The organization behind CanString AI has successfully completed the surveillance audit for its ISO/IEC 27001:2022 Information Security Management System, continuing the certification cycle for the international information security standard.
The surveillance audit reviews whether an organisation continues to operate its Information Security Management System (ISMS) effectively after certification. It examines how information security risks are managed, how controls are implemented and reviewed, and whether the management system continues to meet the requirements of ISO/IEC 27001:2022.
For CanString AI, the review is directly relevant to how the platform is deployed and evaluated by enterprise customers. CanString supports customer interaction workflows across voice and non-voice channels, including AI voice agents, conversation analysis, knowledge assistance and business intelligence. These workflows can involve sensitive customer information, recordings, transcripts and operational data, making information security controls a core part of enterprise deployment.
Why the surveillance audit matters
ISO/IEC 27001:2022 is an internationally recognised standard for establishing and maintaining an Information Security Management System. Certification is not a one time assessment. Surveillance audits take place during the certification cycle to verify continued compliance and the ongoing effectiveness of the management system.
The completed audit provides another independently reviewed checkpoint for customers and partners assessing CanString as part of vendor security, procurement and technology risk processes.
This is particularly relevant for organisations in banking, financial services, insurance and contact centre operations, where customer conversations can include personally identifiable information, financial details and other sensitive data. Security teams in these organisations typically need evidence that information security is managed through documented processes, defined ownership and controls that are reviewed over time.
Continuing the security review cycle
Completing the surveillance audit is part of CanString's ongoing information security management process. The organisation will continue periodic reviews, internal controls and external assessments as its platform and customer deployments evolve.
For enterprise customers, the objective is practical: provide AI capabilities for customer interactions without treating information security as an afterthought. The surveillance audit adds current, independently reviewed evidence to that security posture.



