AI governance resources
Everything you need to start your review process.
The questions governance committees typically ask about Edwin AI (e.g. data handling, models, and controls) answered in one place.
Download a deep-dive into our security controls.
Review an independent, third-party security audit.
ISO/IEC 27001:2013, ISO/IEC 27017:2015, ISO/IEC 27018:2019.
SOC 2 Type 2 standards.
What your governance review needs to see
An AI governance review examines the same core areas, whatever the vendor: how data is handled, what’s independently certified, whether outputs can be explained, who stays in control, where it sits under emerging law, and how it’s monitored over time. Here’s the basics on how LogicMonitor approaches these important questions.
Your data is never used to train our models
Data handling is the first thing a committee scrutinizes. Edwin AI is built to minimize sensitive-data exposure and to keep your data out of model training, with clear answers on residency, retention, and sub-processors.
-
Works primarily on operational IT telemetry, not sensitive customer records, and fields containing PII can be excluded from what’s sent to Edwin AI
-
Customer data is not used to train third-party LLMs, and is not shared between customers
-
Encrypted in transit and at rest, with each customer’s data isolated and no co-mingling
-
Zero Data Retention available on request
Independently validated controls you can verify
The certifications that are table stakes in any AI review are current and public, so your security team can confirm them directly rather than take our word for it.
-
SOC 2 Type 2 and ISO/IEC 27001, 27017, and 27018 certifications
-
Annual third-party penetration testing and a publicly available SOC 3 report
-
Full control detail in the Trust Center and security whitepaper
Every recommendation is traceable
Legal and risk teams need to see how a conclusion was reached. Edwin AI grounds its outputs in your own data and records what it did, so any decision can be reviewed after the fact.
-
Retrieval-augmented generation grounds responses in trusted sources, with reference links so users can verify them
-
Trace-level logging captures agent conversations and interactions for QA and review, with regional residency for log data
-
Outputs are presented as recommendations, complete with source citations
You stay in control of every action
Agentic AI is the frontier of governance precisely because agents take action. LogicMonitor keeps a human in the loop and tightly scopes what any agent is allowed to do.
-
Every output is a recommendation, and people review, validate, and decide whether to permit autonomous action and remediation.
-
Agents are limited to a defined toolset built and controlled by LogicMonitor
-
Many capabilities are opt-in and require explicit customer authorization
-
Guardrails keep agent activity scoped to the ITOps domain
Aligned with the EU AI Act’s principles
Committees need to know where a platform falls under emerging AI law. Edwin AI supports low risk use cases and is not designed to do things that would be higher risk, such as making consequential decisions about individuals.
-
Not designed as a safety-system component, and not used for decisions about individuals such as employment
-
Practices aligned to the EU AI Act’s principles of safety, accountability, and transparency
-
Privacy Impact Assessments and AI compliance reviews run for new AI use cases
Model changes are governed, and behavior is monitored
Governance doesn’t end at approval. Model updates are evaluated before they reach you, and AI behavior stays observable once it’s in production.
-
Candidate model upgrades go through structured offline evaluation against a benchmark suite before promotion
-
A staged rollout through a sandbox lets you validate behavior before production
-
Production AI activity is observable through trace-level logging for ongoing QA and assurance
Learn more about Autonomous IT
Approve AI with confidence.
Adopt it with proof.
Adopt it with proof.