Privacy policies need an automated decision-making section by 10 December 2026.
Draft yours free

Certified businesses

Block8.ai

Active

Cyber Security Penetration Testing · 1-2 employees · ABN 42682456140

Responsible AI Certified · Govern tierCertified since 6 Oct 2026 · Valid until 6 Oct 2027

Certification ID: RAIA-2026-0012

block8.ai

Trust seal

Verified live against the certification register

Responsible AI Australia Govern certification markVerifying against the register…
TierGovern
Certification IDRAIA-2026-0012
Expires6 Oct 2027

For AI agents

This certification is machine-verifiable. Any AI agent, search engine or procurement system can confirm it in milliseconds, no account required.

RAIA-2026-0012

Responsible AI profile

Self-declared AI practices, submitted as part of this business's certification.

AI usage

How they use AI

Block8.ai uses AI-powered automation to accelerate penetration testing of client websites, applications, portals and external attack surfaces, helping organisations identify, validate and remediate security risks faster and at lower cost. AI-generated findings are validated by CREST-certified human security professionals, so AI supports rather than replaces expert judgement and accountability for results. All testing is delivered within Block8.ai's ISO/IEC 27001:2022-certified information security management system, which governs how client data and testing activities are handled.

AI tools in use

Chatbots or virtual assistants (e.g., customer service)Automation or robotic process automation (RPA) (e.g., workflow efficiency)Natural language processing (e.g., content generation or sentiment analysis)Other (specify briefly)

Pre-built models & their purpose

Cyber Penetration testing for vulnerability assessment

AI use & risk profile

Low-risk (e.g., internal automation or content generation)Medium-risk (e.g., customer recommendations or marketing)

Risk & safety

How they identify and mitigate AI risk

Block8 manages AI risk through its ISO/IEC 27001 risk management process. AI-specific risks are recorded in our risk register alongside other information security risks. Each has an owner, existing controls and treatment actions, and the register is reviewed through our Information Security Working Group. Key mitigations include: Use of AI Policy, approved by our CEO: staff must not enter client or organisation names, individuals' names, locations, system names or IP addresses into third-party AI tools. They use placeholder details instead. Isolated model access: our platform uses Anthropic's Claude only through AWS Bedrock over a private network connection. There is no direct model access, no data is kept in the AI layer, and no client data is used to train models. Authorisation guardrails that restrict our AI testing agent to targets the client has authorised. Code review and change approval before changes to the platform are deployed.

Fairness audits & human-in-the-loop review

Yes

Frequency & method

We provide human in the loop AI assisted cyber penetration testing.

Ability to contest or override AI decisions

Yes

Example

The human in the loop is always in control at every step of the process and validates AI agent work.

Ethics & governance

Follows ethical AI frameworks

Yes

Frameworks followed

Internal company policyAustralian AI Ethics PrinciplesInternational standards (e.g., EU AI Act guidelines)

Maintains AI documentation & oversight

Yes

Responsible for oversight

CEO

Privacy & fairness

Privacy & data security (Privacy Act 1988)

Yes

Methods

Data encryption and anonymizationRegular security auditsCompliance with Privacy Act via data impact assessmentsThird-party tools (e.g., secure cloud providers)

Prevents AI bias & discrimination

Yes

Methods

Other (specify)

Other methods

This is not really applicable to our company size and model of providing cyber penetration testing services

Sustainability & society

Societal benefit & responsible scaling

Block8.ai's use of AI benefits society by making professional-grade penetration testing affordable and fast enough for small and growing businesses that have traditionally gone untested. This strengthens the security of Australian organisations overall. As AI use in testing scales, Block8.ai will keep human oversight central: qualified testers remain accountable for every finding delivered to clients, and AI will not act on client systems outside an agreed scope.