Skip to main content

Help us improve the Digital Marketplace - send your feedback

CULTUREAI LTD

CultureAI: AI Security platform

CultureAI secures AI interactions wherever they happen, enabling organisations to safely adopt AI by providing 360 degree visibility, control, and guardrails for AI use.

Features

  • Run-time visibility of AI interactions
  • AI usage control
  • AI security controls and policy enforcement
  • Multimodal AI protection
  • Shadow AI discovery
  • AI usage control

Benefits

  • Identify shadow AI use
  • Monitor and classify data disclosure into AI
  • Secure AI interactions, everywhere
  • Enforce AI security policies

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at kristina.lazurenko@culture.ai. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

7 8 9 7 2 6 4 1 3 5 3 3 3 0 3

Contact

CULTUREAI LTD Kristina Lazurenko
Telephone: +44 (0)800 368 7676
Email: kristina.lazurenko@culture.ai

About the service

Service categories
  • Systems Infrastructure Software
    • Security
      • Endpoint security
        • Endpoint security
      • Security analytics
        • Security analytics
      • Data security
        • Information protection
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
None
System requirements
Basic ability to centrally deploy software (InTune or equivalent)

User support

Email or online ticketing support
Yes
Support response times
Same day Mon-Fri
User can manage status and priority of support tickets
No
Phone support
No
Web chat support
No
Onsite support
Yes
Support levels
Email and video-conferencing support available as required Mon - Friday 9am UK - 5pm UK. Support requests are typically acknowledged same working day. Technical client success manager provided.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Support is provided by a named client success manager and via our UK support team. Full documentation is also provided, and support can be accessed via both email and video conferencing.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
Documentation accessibility standard
WCAG 2.2 A
End-of-contract data extraction
Data can be exported via API or using the data export functionality in the platform.
End-of-contract process
There are no additional off-boarding costs

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
Yes
Compatible operating systems
  • Linux or Unix
  • MacOS
  • Windows
  • ChromeOS
Designed for use on mobile devices
No
Service interface
Yes
Description of service interface
The service interface allows visibility and analytics of AI interactions and configuration of AI security policies.
Accessibility standards
None or don’t know
Description of accessibility
The platform is built to work with popular screen readers including NVDA, JAWS, and VoiceOver.

Users who cannot use a mouse can navigate the platform using keyboard only.

The platform includes features to support users with visual impairments and those who experience discomfort with animations.

The platform reflows properly on different screen sizes and when zoomed, ensuring content remains accessible without requiring horizontal scrolling.
Accessibility testing
Basic in-house testing with JAWS.
User support accessibility
None or don’t know
API
Yes
What users can and can't do using the API
The service provides a Restful API that provides a wide range of functionality, including access to analytics and data.
API documentation
Yes
API documentation formats
Open API (also known as Swagger)
API sandbox or test environment
Yes
Customisation available
No

Scaling

Independence of resources
High-availability architecture and auto-scaling of all resources.

Analytics

Service usage metrics
Yes
Metrics types
Number of employees covered by AI security monitoring
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Supplier type

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
Yes
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
NCSC approved service provider
Protecting data at rest
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Data sanitisation type
Data Erasure
Equipment disposal approach
A third-party destruction service

Data importing and exporting

Data export approach
Data can be exported using the API or in-platform data export functionality
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
99.9% availability SLA with service credits for surplus outages.
Approach to resilience
Available on request
Outage reporting
Email alerts

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
Access restrictions in management interfaces and support channels
Access is restricted to named contacts. Additional restrictions such as IP-based restrictions and additional time-based MFA can be enforced over and above those provided by the clients IDP.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Software Security Code of Practice
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Wide range of policies and processes as part of our ISO 27001 certification.

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
All service components are inventoried and tracked throughout their lifecycle. Assets are identified and version-controlled using centralized repositories. Changes are logged, auditable, and linked to ownership and deployment history. Decommissioned components are retired and removed from inventories.

All changes follow a risk-based change management workflow. Changes are reviewed, approved, tested, and validated prior to production deployment, with automation and peer review used.

Changes are assessed for security impact, effects on confidentiality, integrity, availability, and compliance. Higher-risk changes may trigger additional security review or testing.

Configuration changes are logged, with audit trails retained for investigation and compliance.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
We maintain a formal vulnerability management process to identify, assess, and remediate security risks to our services. Potential threats are assessed through continuous vulnerability scanning, dependency analysis, configuration reviews, and risk-based prioritization considering exploitability and business impact. We monitor trusted sources for threat intelligence, including vendor advisories, CVE databases, security research, and third-party scanning tools. Patches and mitigations are deployed according to severity, with critical vulnerabilities addressed on an expedited basis and lower-risk issues remediated within defined service-level timeframes. Remediation actions are tracked, validated, and documented.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
We maintain a documented protective monitoring process aligned with CSA CCM v4.0. Potential compromises are identified through centralized logging, continuous monitoring, alerting, and automated detection of anomalous or suspicious activity across systems and services. Alerts are triaged by trained personnel and investigated using defined incident response procedures. When a potential compromise is identified, containment, eradication, and recovery actions are initiated promptly, with escalation based on severity. Incident response timelines are risk-based, with critical incidents addressed immediately and managed through to resolution, including post-incident review and documentation.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Post-quantum cryptography secure
No
Incident management approach
We maintain a documented incident management process. Pre-defined procedures exist for common incident types, including security events, service disruptions, and data incidents. Users can report incidents through established support channels, such as a service desk or designated contact points, which are monitored continuously. Incidents are logged, tracked, and managed through to resolution. Incident reports are provided to users as appropriate, including status updates, impact assessment, remediation actions, and post-incident summaries when required.

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
Yes
Description of free trial
There is a free AI assessment service that provides a detailed report quantifying use of AI across the organisation, including shadow AI use and categorisation of the data assets being disclosed into AI applications/agents.
Link to free trial
https://www.culture.ai/

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
15%
Over £5,000,001
20%

Standards and certifications

ISO/IEC 27001 certification
Yes
ISO/IEC 27001 accredited by
NQA
ISO/IEC 27001 accreditation date
Thursday 23 October 2025
What the ISO/IEC 27001 doesn’t cover
Entire organisation and service in scope.
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Cyber Essentials Certificate Number
2f7b427d-b1c5-4dd3-9a98-4fa16e74cbc9
Cyber essentials plus
Yes
Cyber Essentials Plus Certificate Number
95ffaa0a-5516-4ee5-b85e-6457310b4910
Other security certifications
No

Social value

Mission: Kick start economic growth

To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

  • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
  • Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
  • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
  • Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
  • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
  • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
  • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
  • Volunteering opportunities for staff

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at kristina.lazurenko@culture.ai. Tell them what format you need. It will help if you say what assistive technology you use.