AttestloopNorthwind AI
Interactive demo

Northwind AI uses sample controls. No customer data is shown.

Scan your code
Compliance / Policies / Information Security Policy
⌘K
Y
← All policies
POLICY
Northwind AI — Information Security Policy
PublishedSOC 2ISO 27001
Purpose

This policy establishes how Northwind AI governs the controls described below. It exists to protect Northwind AI's systems, data, and customers, and to satisfy the obligations of SOC 2 and ISO 27001.

Scope

This policy applies to all Northwind AI personnel, contractors, systems, and third parties that process Northwind AI data. It maps to the requirements of SOC 2 and ISO 27001 and is reviewed at least annually or on material change.

Policy

Northwind AI maintains documented, enforced controls for the area covered by this policy. Each control is monitored continuously, evidence is collected automatically where possible, and exceptions are tracked, justified, and time-bound. Where a control carries regulatory or contractual liability, a credentialed reviewer co-signs it before it is treated as met.

Roles and responsibilities

The security owner maintains this policy and the underlying controls. System owners implement and evidence the controls in their area. All personnel are responsible for adhering to this policy. A credentialed reviewer (e.g. CISSP, CIPP/E, or lead auditor) co-signs high-judgment controls.

Enforcement and review

Violations are handled under Northwind AI's disciplinary process. This policy is owned by the security function, approved by management, and reviewed at least annually. The current readiness of the controls it governs is visible in the Attestloop console and on the published Trust Page.