Skip to main content

Regis — How We Deliver on Security

An overview of how The Regis Company delivers on security: our ISO/IEC 27001 and ISO/IEC 42001 attestations and the framework that governs how we protect client data and use AI responsibly.

Enterprise-grade security, independently verified.

Protecting your data is foundational to how we build and operate SimGate — and we don't ask you to take our word for it. Our security and AI governance programs are independently audited, with current attestations published on this page for your team to verify directly. And when you need a formal InfoSec review, we turn those around in days, not weeks.

We'll add new attestations and reports here as they become available.


Certifications & Attestations

The Regis Company has completed independent certification audits, conducted by A-LIGN Compliance and Security Inc., against two international standards. In both cases we have successfully completed the certification audit and been recommended for certification; A-LIGN is finalizing the audit reports and official certificates. The attestation letters below are available for your security, procurement, and vendor-risk teams to download and share.

ISO/IEC 27001:2022 — Information Security Management

ISO/IEC 27001 is the leading international standard for information security. Our Information Security Management System (ISMS) covers the development, deployment, and support of the cloud-based simulation learning solution, SimGate — including all associated IT systems, data assets, infrastructure, physical office locations, and personnel involved.

ISO/IEC 42001:2023 — AI Management

ISO/IEC 42001 is the first international standard for responsible AI management. Our AI Management System (AIMS) applies to all AI systems developed, integrated, or used by The Regis Company — including generative AI services, machine learning models in SimGate, and AI-enabled development and content workflows, as well as third-party integrations and partnerships where AI components influence business operations, client products, or decision-making.

SOC 2 — In Progress

🚧 A SOC 2 examination is underway. The report will be shared here as soon as it is available.


Our Security & AI Governance Framework

The Regis Company maintains a formal Information Security Management System (ISMS) and AI Management System (AIMS) governing how we protect client data and how we develop, deploy, and operate AI capabilities within our learning simulation platform. The framework is mapped to ISO/IEC 27001:2022 and ISO/IEC 42001:2023, with each policy referencing its applicable controls and clauses.

  • Review cadence: All policies are formally reviewed at least annually, and out-of-cycle upon significant change, incidents, or audit findings.

  • Enforcement: Compliance is mandatory for all employees, contractors, and relevant third parties, with defined consequences for non-compliance.

  • Continuous improvement: Policies are supported by measurable success criteria, internal audit, and management review.

  • Resilience: A Business Continuity Plan, Disaster Recovery Plan, and Security Incident Response Plan translate policy into tested response capability.

Our ISMS spans twelve information security policies — covering risk management, HR security, asset management, access control, physical security, incident management, systems security, application security, cryptographic controls, off-premises assets, and credentials. Full policy documents are classified as internal; a client-facing Security & AI Governance Policy Overview is available on request.


Responsible AI, By Design

The Regis Company operates a dedicated AI Management System aligned with ISO/IEC 42001:2023. We do not train or fine-tune AI models on your data; our AI systems combine established third-party foundation models with Regis-built orchestration, guardrails, and human oversight. Key elements of the AI governance framework include:

  • AI Ethics & Responsible AI Policy: fairness, transparency, accountability, privacy, and human oversight, governing all third-party AI services.

  • AI System Impact Assessments: performed before deployment, at least annually, and upon significant change.

  • Multi-tenant data separation and human review of AI-generated content.

  • AI engineering standards: data governance and quality, secure design (including defenses against AI-specific threats such as prompt injection), independent evaluation before deployment, and operational monitoring.


Related Resources

Available on request (email [email protected]): Security & AI Governance Policy Overview, SimGate Architecture & Security Overview, latest penetration test summary, CAIQ v4 assessment, VPAT / Accessibility Conformance Report, and full policy documents under an appropriate confidentiality agreement.


Need a Formal InfoSec Review?

If your organization requires a security review or formal documentation for procurement or IT assessment, email [email protected] to request an InfoSec Review. Estimated turnaround is 3–5 business days for completion of initial security forms.

Did this answer your question?