Trust and technical assurance

Trust should be inspectable.

Decide quickly whether AI Fabrix belongs inside your enterprise boundary—and what your Architecture, Security, Risk and Legal teams should validate next.

AI Fabrix provides technical and operational controls that support trustworthy enterprise AI. It does not make a customer, deployment or AI use case compliant merely by being installed.

Customer Azure tenant
Entra ID
Customer Azure tenant
Operational Trust
Customer Azure tenant
Enterprise Runtime
Customer Azure tenant
Evidence
The 30-second trust assessment

Seven questions. Verifiable answers.

Each answer links to the detailed architecture responsibility behind it. This page is the assurance index, not a replacement for technical review.

Deployment
Runs in your Azure tenant as an Azure Marketplace managed application.
Validate the boundary
Identity
Uses the customer identity environment, including Entra ID where configured.
Validate the boundary
Authority
AI cannot grant itself authority. Governed operations remain attributable to verified human authority.
Validate the boundary
Secrets
Credentials and connection details remain behind the governed boundary and use Key Vault where established.
Validate the boundary
Systems of record
Enterprise applications remain authoritative for their records and transactions.
Validate the boundary
Evidence
Validated results preserve what happened—including denial, waiting, failure and safe stop.
Validate the boundary
Independence
Models and interfaces can change without becoming the enterprise authority or Runtime control plane.
Validate the boundary
Suitability

Operational trust—not governance theatre.

AI Fabrix is designed for organisations that want AI to participate in real business work without creating a separate identity, authority model, integration estate or source of business truth for AI.

Strong fit when you need to
Work across multiple enterprise systems without exposing unrestricted APIs
Attribute AI-assisted operations to an identified person
Keep existing permissions, business scope and approvals in force
Move beyond read-only copilots into governed work
Provide inspectable outcomes to Audit, Risk and Legal
Reuse business meaning and authority across use cases
Validate one bounded process before production release

Not designed for

Public-information chatbots, autonomous AI that bypasses human authority, or deployments without defined ownership, permissions and approval boundaries.

The governed execution boundary

AI can request. It cannot authorise itself.

A Role Assistant defines the validated business purpose and operating boundary. Enterprise Runtime owns execution and each continuation decision. Operational Trust evaluates the current person, role, business scope, permissions, policies and approval state.

Verified identity and role
Current governed context
Runtime decision
Authority and capability verification
Execute, wait, complete or stop safely
Validated result

A prompt cannot expand the permitted boundary. Missing authority or insufficient information produces denial, waiting or safe stop—not guessed continuation.

Evidence and accountability

More than a chat transcript.

Execution result

The validated result of one run, including failure, rejection, waiting, incomplete work or safe stop.

Evidence

Validated, business-significant facts, controls, decisions and outcomes.

Operational records

Technical traceability, security and platform operations—kept separate from business Evidence.

Usage proves that AI was used. It does not prove that governed work was completed correctly.

Standards and regulation
ISO/IEC 27001
Aligned implementation practices.

AI Fabrix is designed and implemented using security and governance practices aligned with ISO/IEC 27001 principles: customer-controlled deployment, identity and role separation, Key Vault secret handling, explicit network profiles, controlled readiness, inspectable outcomes and defined responsibilities.

Scope matters. ISO-aligned implementation is not the same as certification of every customer deployment or AI use case. The public certification statement must identify the certified legal entity, certificate scope, issuer and validity.

EU AI Act
Supports accountable human oversight.

AI Fabrix supports an organisation’s governance programme through identified human authority, defined operating boundaries, permission and approval enforcement, traceable sources and outcomes, safe-stop behaviour and governed change.

AI Fabrix supports compliance readiness. The organisation must still classify each use case, determine its obligations, perform risk management, define retention and oversight, and obtain legal or independent assurance where required.

Ownership and operations

Your tenant. Explicit responsibilities.

The customer selects the Azure subscription, region and approved deployment parameters, owns enterprise identity and organisational authority, and controls customer Azure RBAC according to the selected edition and Marketplace model.

AI Fabrix workloads use scoped managed identities. Publisher or support access must not be assumed to be universally absent or present; it exists only where the selected operating model and support agreement explicitly define it.

Customer Azure authority, workload identity and publisher support access are different responsibilities. They must be reviewed separately.

What your assurance review should request

Trust marketing claims only after they become evidence.

A qualified technical evaluation should make these materials inspectable rather than replace missing proof with broader promises.

Marketplace identity
Current listing, publisher and offer identity
Deployment
Resource inventory, supported topology and readiness checks
Identity and secrets
Entra ID model, managed identities, Key Vault and credential boundaries
Network
Selected profile, ingress, egress, DNS and external dependencies
Authority
Roles, business scope, approvals and capability verification
Evidence
Schema-backed example, lifecycle, honest outcomes and retention/export model
Publisher and support access
Access conditions, auditability and emergency procedure
Security management
ISO/IEC 27001 certificate or approved scope statement when published
Regulatory support
Use-case-specific EU AI Act control mapping and customer responsibilities
Exit
Retained resources, export formats, licence dependencies and removal responsibilities

Validate one process with measurable value, authoritative information and clear human authority.

Prove usefulness and control together.