The standard
AIUC-1 is an emerging security, safety, and reliability standard built specifically for AI agents. The full standard organises its requirements across six pillars:
| Pillar | Covers |
|---|---|
| Data & Privacy | PII leakage, cross-customer isolation, retention, training-data disclosure, secrets |
| Security | Prompt injection, jailbreaks, unauthorized actions, tool scoping, adversarial testing |
| Safety | Harmful output prevention, pre-deployment testing, risk taxonomy, human escalation |
| Reliability | Hallucination controls, tool-call restrictions, scope adherence, monitoring |
| Accountability | Incident response, AI disclosure, audit logging, named owner, vendor diligence |
| Society | Cyber misuse, CBRN misuse, fraud and impersonation, fairness |
What Veriflow implements
Veriflow ships a practical 36-control library aligned to those six pillars and scoped for small teams shipping one or a few agents. Controls carry IDs like SEC-01 and DP-02, which is what you see in citation chips.
Why it's underneath, not on top
Most questionnaires you receive today are SOC 2 plus custom AI questions, not "are you AIUC-1 certified?" So Veriflow leads with getting you through review, and uses AIUC-1 as the structure that makes your answers defensible and consistent.
When buyers do start asking for it by name, you're already organised around it.
Readiness, not certification
Veriflow reports readiness against an AIUC-1-aligned control set. It does not certify you, and the trust page says so in its footer. Certification requires an actual auditor — see the Auditors section when you're ready.