Vorim AI Has Signed the Cloud Security Alliance's AI Trustworthy Pledge
Vorim AI has signed the Cloud Security Alliance's AI Trustworthy Pledge.
CSA launched the pledge in June 2025 as a public commitment for organisations that build, offer or use AI. Signatories affirm four principles. Their AI systems should be safe and comply with the law, they are open about the AI they build and use, they take responsibility for its outcomes, and they protect personal data.
Be clear about what it is. A pledge is a promise, not an audit or a certification, and CSA does not present it as one. That is exactly why we wanted to sign it and then say how we keep it, because for a company whose whole product is evidence, a promise on its own is not enough.
How Vorim keeps each principle
| The pledge asks for | What Vorim does today |
|---|---|
| Safe and compliant AI | Every gated agent action is checked before it runs, against permissions, limits and policy. Suspend stops an agent on its next check and is reversible; revoke is permanent. |
| Transparency | Every action is signed by the agent and verifiable offline with open-source tools. Our protocol, VAIP, is an IETF Internet-Draft, and we implement open standards including MCP, OCSF, Shared Signals and RFC 9421. |
| Ethical accountability | Each action traces to a registered agent with a named owner. When a human approves something, that approval is signed into the record, and delegation between agents is capped at the intersection of their authority. |
| Privacy | Customers can log a keyed hash of a prompt or output instead of the content itself, and the SDK can refuse to send agent content at all. Zero data retention is available on every plan, including free. |
Those are features we can show you in the product, not intentions.
Why it matters for agents
Most responsible AI commitments were written with models and chatbots in mind. Agents are harder. They act on their own, often after the person who delegated to them has logged off, and they call real systems with real consequences.
The pledge's principles still hold, but keeping them for an agent means answering specific questions. Which agent did this? Was it allowed to? Who approved it? Can you prove it to someone who does not trust you? Vorim exists to answer those questions with evidence, and signing the pledge puts that on the public record.
For organisations that want to go further than a pledge, CSA also publishes the AI Controls Matrix, a structured set of controls for assessing AI systems. We would recommend it to any team moving agents into production.
Where to go next
See how Vorim maps to the Blueprint Alliance architecture →
Questions, we read every email at team@vorim.ai.
