Prodia.dev · Research programme
Certifications Roadmap
Last updated: 29 May 2026
Operator
Prodia.dev is a research programme operated by Prodia Systems Ltd, an Irish private company limited by shares (patents pending). Corporate information is published at prodiasystems.com.Prodia publishes its certification posture transparently. We distinguish between controls and frameworks we already operate against, and certifications we are actively pursuing. We do not claim certifications we do not hold.
1. Current
- GDPR-aligned — Records of processing, DPIA process, controller/processor terms (DPA), data subject rights workflow, breach notification process, and international transfer governance in place.
- AI Governance Framework — Public statements aligned with the EU AI Act, NIST AI RMF, ISO/IEC 42001, and equivalent regimes covered in the Legal Pack.
- Security Programme — Encryption in transit and at rest, MFA, least-privilege access, vulnerability management, change management, secure development lifecycle, incident response, and responsible disclosure programme, as described in the Security Policies and Security & Responsible Disclosure pages.
- Governance & Ethics — Conflict of Interest, Whistleblower, Anti-Bribery & Anti-Corruption, Code of Ethics, Code of Conduct, Inclusion and Accessibility statements operationalised.
2. Planned
- SOC 2 Type I — Readiness in progress; report targeted within the next 12 months of the date of this statement.
- SOC 2 Type II — Following Type I, an observation window will run prior to Type II issuance.
- ISO/IEC 27001 — ISMS scope, statement of applicability and Annex A controls in development for certification.
- ISO/IEC 42001 — AI Management System aligned with the existing AI Governance framework; certification pursued in step with ISO 27001.
- EU AI Act conformity — Where the platform or specific deployments fall within scope obligations of high-risk or general-purpose AI provisions, Prodia will operate the required technical and organisational measures and engage notified bodies as applicable.
3. Under consideration
- ISO/IEC 27701 (privacy information management).
- HIPAA-aligned posture for customers handling protected health information.
- Cloud Security Alliance STAR self-assessment.
4. Reporting and evidence
On execution of a mutual non-disclosure agreement, current customers and qualified prospects may request the current security questionnaire, sub-processor register, SBOM excerpts, penetration-test attestation summaries and policy bundle through trust@prodia.dev.
5. No misrepresentation
Prodia will not represent any planned certification as held until the certificate or report has been formally issued by the relevant accredited body or audit firm.
Prodia Systems Ltd
Irish private company limited by shares · Patents pending
Operator of the Prodia.dev research programme · prodiasystems.com
Contact: legal@prodia.dev
