No certification claims
PDICON does not claim SOC 2, ISO 27001, HIPAA or comparable accreditation at this stage.
What is implemented, and what is not yet certified
PDICON Intelligence is designed around tenant isolation, permission-aware retrieval, explicit training consent, encryption and auditable actions. The company does not currently hold SOC 2, ISO 27001 or comparable third-party certifications, and states that openly rather than implying accreditation it has not completed.
Design boundary
Credibility begins where automation stops and accountable professional judgment starts.
PDICON does not claim SOC 2, ISO 27001, HIPAA or comparable accreditation at this stage.
The platform does not replace statutory approval, certification or professional liability.
Data captured for one declared purpose is not repurposed without a new agreement.
A young company can implement isolation, least privilege, encryption and audit logging properly while not yet holding an external certificate. Conflating the two misleads buyers, so PDICON separates them explicitly.
Whether captured project evidence may contribute to model training is a written decision with a defined purpose, revocation path and retention term, not a setting buried in defaults.
Where a control is implemented, PDICON says so and describes it. Where accreditation is absent or a capability is planned, that is stated in the same document rather than omitted.
Operating matrix
The matrix separates source evidence, intelligence work, governing authority and the resulting artifact.
| Subject | Input | Intelligence operation | Human / policy control | Output |
|---|---|---|---|---|
| Isolation | Customer workflow data | Tenant separation | Access policy | Contained data |
| Access | Documents and projects | Permission-aware retrieval | Role and document rules | No privilege leakage |
| Consent | Training eligibility | Recorded purpose | Written agreement | Revocable use |
| Audit | Human and model actions | Immutable logging | Customer visibility | Reviewable trail |
Questions answered
Open a question to inspect the operating position, not a marketing promise.
No. Those certifications are not held at this stage. The controls the standards describe — isolation, least privilege, encryption, audit logging and consent records — are part of the design, and the distinction is stated openly.
Only under an explicit written agreement that defines purpose, retention and revocation. It is never the silent default.
Get started
Bring a workflow your team already repeats. We define the evidence, the approver and the outcome to measure, then instrument it end to end.
We are working with a small number of design partners across engineering and procurement workflows.