Trust Centre
Evidence that moves with the work.
Kuulo helps organisations turn difficult operational problems into dependable systems. Security, privacy, AI governance and sector assurance are part of that work from the beginning.
Understand
Map the people, data, risks and obligations around the work.
Build
Put the controls, approvals and boundaries into the working system.
Evidence
Leave the client with records a reviewer can actually follow.
Frameworks and registrations
Choose the question you need to answer.
Each page explains what the framework covers, what it changes in delivery, and where the current project and case-study evidence is strong—or still needs confirmation.
Information security

Information security
ISO 27001
ISO/IEC 27001 is the international standard for an information security management system. It gives an organisation a structured way to identify information risks, choose controls, assign responsibility and keep evidence that the controls are operated.
Read the framework page →
Information security
Cyber Essentials
Cyber Essentials is a government-backed baseline for protecting organisations against common internet-borne threats. It focuses on practical controls such as secure configuration, access control, malware protection, software updates and firewalls.
Read the framework page →Data protection

Data protection
Data protection
Data protection requirements, supplemented by the Data Protection Act 2018, govern how organisations use personal data. They cover lawful processing, transparency, security, individual rights, accountability and the relationship between controllers and processors.
Read the framework page →
Data protection
EU GDPR
The EU General Data Protection Regulation is the European framework for protecting personal data. It sets requirements around lawful processing, data-subject rights, security, accountability, international transfers and controller or processor responsibilities.
Read the framework page →
Data protection
CCPA / CPRA
The CCPA, as amended by the California Privacy Rights Act, gives California residents rights over personal information and places obligations on businesses around notice, access, deletion, correction, opting out and the handling of sensitive information.
Read the framework page →Health assurance

Health assurance
HIPAA
HIPAA is a US framework that includes privacy, security and breach-notification requirements for covered entities and business associates handling protected health information. The Security Rule focuses on appropriate administrative, physical and technical safeguards for electronic protected health information.
Read the framework page →
Health assurance
NHS DSPT
The NHS Data Security and Protection Toolkit is an online self-assessment and assurance framework for organisations that access NHS patient data and systems. It tests how data security and information governance are understood, controlled and evidenced.
Read the framework page →
Health assurance
DTAC
DTAC is an NHS assessment framework for digital health technologies. Its review areas include clinical safety, data protection, technical security, interoperability, usability and accessibility.
Read the framework page →Client evidence
The controls are part of the delivery story.
On a regulated health platform, we delivered the working patient and clinician service alongside security, privacy and clinical-safety evidence. The platform began serving patients in four months; the remaining compliance work followed inside the next two.
Case study
A stalled health platform starts serving patients
Cyber Essentials, NHS DSPT, DCB 0129, DCB 0160, ISO 27001, HIPAA requirements, a DPIA and client security questionnaires.
Read the delivery story →Case study
Compliance moves with the product
A working patient and clinician service with the evidence tied to the data, approval and operating paths.
Read the delivery story →Questions people ask
A practical assurance conversation.
Does Kuulo provide legal or regulatory certification?
No. We help teams understand the requirements that apply to their system, build the relevant controls and produce reviewable evidence. The client's role, data, contract and intended use determine the final legal or regulatory position.
Which frameworks can you help us work through?
The Trust Centre covers ISO 27001, Cyber Essentials, data protection, CCPA / CPRA, the EU AI Act, HIPAA, NHS DSPT, DTAC and ICO registration. We can also connect related clinical-safety work such as DCB 0129 and DCB 0160 where the engagement requires it.
When does compliance work begin?
At the start of delivery. We map the data, users, systems, risks and evidence needed before the build sequence is fixed, then keep those questions connected to the working service.
Can we request the supporting documentation?
Yes. Email support@kuulo.ai with the framework, your organisation and the purpose of the request. We will confirm what can be shared and what needs to be scoped to your system.
Need a framework mapped to your work?

