Independently certified responsible AI
GuruLink is ISO/IEC 42001 certified (the international standard for AI management systems), making PathPilot Canada's first certified responsible-AI career companion.

Certificate available on request for security reviews.
- Standard
- ISO/IEC 42001:2023, Artificial Intelligence Management System (AIMS)
- Status
- Certified, independently audited
- Certified organization
- Guru-Link, Inc. (the company behind PathPilot)
- Certification body
- Prescient Security LLC (accredited per ISO/IEC 17021-1)
- Certificate number
- PS42001-02
- Certified since
- November 18, 2024
- Valid until
- November 17, 2027, maintained through annual surveillance audits
- Scope
- The AI management system supporting PathPilot, including the PathPilot product team
ISO 27001 & SOC 2: in progress
We are actively pursuing ISO 27001 and SOC 2 for information security management, and we report their status honestly, never as achieved before certification is complete.
How your data is protected
The answers procurement and IT teams ask for first, in one place.
Hosting & data residency
- Data is hosted in North America
Encryption
- Encrypted at rest and in transit using industry-standard protocols
Access control
- Role-based access limited to authorized personnel
- Multi-factor authentication for all staff
- Audit logging, regular access reviews, and automated deprovisioning
- Single Sign-On (SSO) support for enterprise deployments
Security testing
- Regular security audits and penetration tests
Data lifecycle & user control
- Data minimization by design
- Users can access, modify, or delete their data and opt out of specific uses
- Secure deletion on a defined timeline after a program ends
- Explicit consent at onboarding
AI-specific commitments
- Third-party AI providers never train on participant data
- Institutional reporting is aggregate-only. Clients see cohort-level outcomes, never individual activity
Independent oversight, not self-attestation
NIST AI RMF 1.0
Adopted as our AI risk management framework: Govern, Map, Measure, Manage.
Independent bias audits
Regular audits examine recommendation patterns across demographic groups.
Third-party incident reporting
Independent AI Incident Reporting Center: [email protected]
Privacy contact
Named privacy officer at [email protected]. GDPR/CCPA-aligned practices.
We don't ask you to sign on faith
Bring your security review. Here's how it usually runs.
Share requirements
Tell us what your security and procurement review needs, and we map to it from day one.
Review our documentation
We put our technical and compliance documentation in front of your IT/security team.
DPA in parallel
A data processing agreement runs alongside the review so your timeline never slips.
Questions about privacy? Reach our privacy officer at [email protected]
Looking for our AI ethics practices? Fairness, bias mitigation, transparency, and human oversight live on our Responsible AI page.
Responsible AI