PDICONIntelligence
Contact

What is implemented, and what is not yet certified

Compliance Posture

PDICON Intelligence is designed around tenant isolation, permission-aware retrieval, explicit training consent, encryption and auditable actions. The company does not currently hold SOC 2, ISO 27001 or comparable third-party certifications, and states that openly rather than implying accreditation it has not completed.

Controls by design; certifications not yet held

Design boundary

What the system will not pretend to be.

Credibility begins where automation stops and accountable professional judgment starts.

01

No certification claims

PDICON does not claim SOC 2, ISO 27001, HIPAA or comparable accreditation at this stage.

02

No regulatory sign-off substitution

The platform does not replace statutory approval, certification or professional liability.

03

No silent scope creep

Data captured for one declared purpose is not repurposed without a new agreement.

Controls and certificates are different things

Implementing a control is not the same as being audited against it.

A young company can implement isolation, least privilege, encryption and audit logging properly while not yet holding an external certificate. Conflating the two misleads buyers, so PDICON separates them explicitly.

Consent is contractual, not implied

Training use is agreed in writing.

Whether captured project evidence may contribute to model training is a written decision with a defined purpose, revocation path and retention term, not a setting buried in defaults.

Procurement diligence gets a straight answer

Security questionnaires deserve accuracy.

Where a control is implemented, PDICON says so and describes it. Where accreditation is absent or a capability is planned, that is stated in the same document rather than omitted.

Operating matrix

Evidence moves through explicit controls.

The matrix separates source evidence, intelligence work, governing authority and the resulting artifact.

Control surface Reviewable lineage
SubjectInputIntelligence operationHuman / policy controlOutput
IsolationCustomer workflow dataTenant separationAccess policyContained data
AccessDocuments and projectsPermission-aware retrievalRole and document rulesNo privilege leakage
ConsentTraining eligibilityRecorded purposeWritten agreementRevocable use
AuditHuman and model actionsImmutable loggingCustomer visibilityReviewable trail

Questions answered

Precise answers for technical evaluation.

Open a question to inspect the operating position, not a marketing promise.

01Is PDICON SOC 2 or ISO 27001 certified?

No. Those certifications are not held at this stage. The controls the standards describe — isolation, least privilege, encryption, audit logging and consent records — are part of the design, and the distinction is stated openly.

02Can our project data be used to train shared models?

Only under an explicit written agreement that defines purpose, retention and revocation. It is never the silent default.

Get started

Start with one real decision.

Bring a workflow your team already repeats. We define the evidence, the approver and the outcome to measure, then instrument it end to end.

Talk to the team How engagements work

We are working with a small number of design partners across engineering and procurement workflows.