CultureAI: AI Security platform
CultureAI secures AI interactions wherever they happen, enabling organisations to safely adopt AI by providing 360 degree visibility, control, and guardrails for AI use.
Features
- Run-time visibility of AI interactions
- AI usage control
- AI security controls and policy enforcement
- Multimodal AI protection
- Shadow AI discovery
- AI usage control
Benefits
- Identify shadow AI use
- Monitor and classify data disclosure into AI
- Secure AI interactions, everywhere
- Enforce AI security policies
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 8 9 7 2 6 4 1 3 5 3 3 3 0 3
Contact
CULTUREAI LTD
Kristina Lazurenko
Telephone: +44 (0)800 368 7676
Email: kristina.lazurenko@culture.ai
About the service
- Service categories
-
- Systems Infrastructure Software
- Security
- Endpoint security
- Endpoint security
- Security analytics
- Security analytics
- Data security
- Information protection
- Endpoint security
- Security
- Systems Infrastructure Software
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- None
- System requirements
- Basic ability to centrally deploy software (InTune or equivalent)
User support
- Email or online ticketing support
- Yes
- Support response times
- Same day Mon-Fri
- User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- Yes
- Support levels
- Email and video-conferencing support available as required Mon - Friday 9am UK - 5pm UK. Support requests are typically acknowledged same working day. Technical client success manager provided.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Support is provided by a named client success manager and via our UK support team. Full documentation is also provided, and support can be accessed via both email and video conferencing.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- Documentation accessibility standard
- WCAG 2.2 A
- End-of-contract data extraction
- Data can be exported via API or using the data export functionality in the platform.
- End-of-contract process
- There are no additional off-boarding costs
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- Yes
- Compatible operating systems
-
- Linux or Unix
- MacOS
- Windows
- ChromeOS
- Designed for use on mobile devices
- No
- Service interface
- Yes
- Description of service interface
- The service interface allows visibility and analytics of AI interactions and configuration of AI security policies.
- Accessibility standards
- None or don’t know
- Description of accessibility
-
The platform is built to work with popular screen readers including NVDA, JAWS, and VoiceOver.
Users who cannot use a mouse can navigate the platform using keyboard only.
The platform includes features to support users with visual impairments and those who experience discomfort with animations.
The platform reflows properly on different screen sizes and when zoomed, ensuring content remains accessible without requiring horizontal scrolling. - Accessibility testing
- Basic in-house testing with JAWS.
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
- The service provides a Restful API that provides a wide range of functionality, including access to analytics and data.
- API documentation
- Yes
- API documentation formats
- Open API (also known as Swagger)
- API sandbox or test environment
- Yes
- Customisation available
- No
Scaling
- Independence of resources
- High-availability architecture and auto-scaling of all resources.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Number of employees covered by AI security monitoring
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Data sanitisation type
- Data Erasure
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- Data can be exported using the API or in-platform data export functionality
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- 99.9% availability SLA with service credits for surplus outages.
- Approach to resilience
- Available on request
- Outage reporting
- Email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Access restrictions in management interfaces and support channels
- Access is restricted to named contacts. Additional restrictions such as IP-based restrictions and additional time-based MFA can be enforced over and above those provided by the clients IDP.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Software Security Code of Practice
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Wide range of policies and processes as part of our ISO 27001 certification.
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
All service components are inventoried and tracked throughout their lifecycle. Assets are identified and version-controlled using centralized repositories. Changes are logged, auditable, and linked to ownership and deployment history. Decommissioned components are retired and removed from inventories.
All changes follow a risk-based change management workflow. Changes are reviewed, approved, tested, and validated prior to production deployment, with automation and peer review used.
Changes are assessed for security impact, effects on confidentiality, integrity, availability, and compliance. Higher-risk changes may trigger additional security review or testing.
Configuration changes are logged, with audit trails retained for investigation and compliance. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- We maintain a formal vulnerability management process to identify, assess, and remediate security risks to our services. Potential threats are assessed through continuous vulnerability scanning, dependency analysis, configuration reviews, and risk-based prioritization considering exploitability and business impact. We monitor trusted sources for threat intelligence, including vendor advisories, CVE databases, security research, and third-party scanning tools. Patches and mitigations are deployed according to severity, with critical vulnerabilities addressed on an expedited basis and lower-risk issues remediated within defined service-level timeframes. Remediation actions are tracked, validated, and documented.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- We maintain a documented protective monitoring process aligned with CSA CCM v4.0. Potential compromises are identified through centralized logging, continuous monitoring, alerting, and automated detection of anomalous or suspicious activity across systems and services. Alerts are triaged by trained personnel and investigated using defined incident response procedures. When a potential compromise is identified, containment, eradication, and recovery actions are initiated promptly, with escalation based on severity. Incident response timelines are risk-based, with critical incidents addressed immediately and managed through to resolution, including post-incident review and documentation.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Post-quantum cryptography secure
- No
- Incident management approach
- We maintain a documented incident management process. Pre-defined procedures exist for common incident types, including security events, service disruptions, and data incidents. Users can report incidents through established support channels, such as a service desk or designated contact points, which are monitored continuously. Incidents are logged, tracked, and managed through to resolution. Incident reports are provided to users as appropriate, including status updates, impact assessment, remediation actions, and post-incident summaries when required.
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- There is a free AI assessment service that provides a detailed report quantifying use of AI across the organisation, including shadow AI use and categorisation of the data assets being disclosed into AI applications/agents.
- Link to free trial
- https://www.culture.ai/
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 15%
- Between £2,500,001 and £5,000,000
- 15%
- Over £5,000,001
- 20%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- NQA
- ISO/IEC 27001 accreditation date
- Thursday 23 October 2025
- What the ISO/IEC 27001 doesn’t cover
- Entire organisation and service in scope.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- 2f7b427d-b1c5-4dd3-9a98-4fa16e74cbc9
- Cyber essentials plus
- Yes
- Cyber Essentials Plus Certificate Number
- 95ffaa0a-5516-4ee5-b85e-6457310b4910
- Other security certifications
- No
Social value
- Mission: Kick start economic growth
-
To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Offer a pay and leave entitlement to all eligible staff who become kinship carers, ideally equivalent to statutory adoption pay and leave
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Volunteering opportunities for staff