Elith日本語版
Menu
Corporate

Elith Inc. obtains ISO/IEC 27001 and ISO/IEC 42001 certification simultaneously for its enterprise AI SaaS platform GENFLUX

Elith Inc. (head office: Bunkyo-ku, Tokyo; Representative Director, CEO & CTO: Koki Inoue; hereinafter "Elith") is pleased to announce that, with the provision of its enterprise AI SaaS platform GENFLUX as the scope, it obtained certification to the international standard for information security management systems (ISMS), ISO/IEC 27001:2022, and the international standard for AI management systems (AIMS), ISO/IEC 42001:2023, effective August 21, 2026. ■ Background to the certification As enterprise use of generative AI expands from the trial stage into production environments that support daily operations and critical decision-making, AI products are required to have, in addition to conventional information secu

Elith Inc.
Elith Inc. obtains ISO/IEC 27001 and ISO/IEC 42001 certification simultaneously for its enterprise AI SaaS platform GENFLUX

Elith Inc. (head office: Bunkyo-ku, Tokyo; Representative Director, CEO & CTO: Koki Inoue; hereinafter “Elith”) is pleased to announce that, with the provision of its enterprise AI SaaS platform GENFLUX as the certification scope, it has obtained certification to the international standard for information security management systems (ISMS), ISO/IEC 27001:2022, and the international standard for AI management systems (AIMS), ISO/IEC 42001:2023, effective August 21, 2026.

■ Background to the certification

As enterprise use of generative AI expands from the trial stage into production environments that support daily operations and critical decision-making, AI products are now required to have, in addition to conventional information security, mechanisms for continuously managing AI-specific risks and impacts.

For enterprise SaaS, it is essential to continuously operate the management of information handled by the product, access to the development environment, change history, incident response, and similar processes. For AI systems, meanwhile, as the tasks, data, models, regulations, and societal expectations involved keep changing, it is necessary to continually revisit the intended use and risks and keep updating evaluations and countermeasures.

In providing GENFLUX, Elith has built these not as separate, individual efforts, but as a management system that is continuously improved.

From an information security standpoint, Elith carries out management of information assets and risk, access control, training, incident response, internal audits, and management review, among other activities.

From an AI management standpoint, Elith has also established a set of processes covering AI risk assessment, assessment of the impact of AI systems, management of data and AI resources, clarification of roles and responsibilities, training, incident response, and internal audits.

This certification confirms, through a third-party certification body, that Elith's information security management system and AI management system for the provision of GENFLUX conform to the requirements of ISO/IEC 27001:2022 and ISO/IEC 42001:2023, respectively.

■ About the certifications obtained

The certifications Elith obtained this time cover two international standards relating to information security and AI management.

ISMS

AIMS

About ISO/IEC 27001

ISO/IEC 27001 is an international standard for information security management systems that enables organizations to appropriately manage risks to the information assets they hold and to maintain the confidentiality, integrity, and availability of information.

Elith has put in place a mechanism to continuously review and improve the information management system that supports the planning, development, and operation of GENFLUX.

About ISO/IEC 42001

ISO/IEC 42001 is an international standard for AI management systems that enables organizations that develop, provide, or use AI to manage the risks and impacts associated with AI in an organized and continuous manner.

Elith has put in place a mechanism to continuously review the intended use, risks, impacts, data, and locus of responsibility for its AI, and to revise its management methods in response to changes in technology and the environment in which it is used.

■ Why two management systems are needed

For enterprises to use AI in production environments with confidence, it is not enough to handle information securely alone, nor is it enough to evaluate AI quality and risk alone.

For example, even where robust access control and information security measures are in place, AI may still be used for unintended purposes or have an inappropriate impact on particular users or tasks.

Conversely, even if AI quality and risk are properly evaluated, a service cannot be considered one that enterprises can use with confidence unless access control for the underlying data and systems, incident response, and similar measures are also properly carried out.

Elith believes that viewing information security and AI-specific risk management as mutually complementary, and continuously improving both, forms the foundation that supports enterprises' production use of AI.

■ About the enterprise AI SaaS platform GENFLUX

GENFLUX is a SaaS platform that supports quality evaluation, security, and operational management to help enterprises continuously use generative AI in production environments.

Through evaluation of the response quality and safety of generative AI, visualization and control of the risks associated with AI use and output, and the provision of information for improvement, GENFLUX gives enterprises an environment in which they can continuously review their operations even after adopting AI.

Rather than treating the promotion of AI use and risk management as separate efforts, GENFLUX supports enterprises' production use of AI by enabling both to be handled within the same operation.

■ Comment from Representative Director & CEO Koki Inoue

“As enterprise use of AI expands from proof-of-concept trials into production environments, model performance alone is not enough. Organizations need to continuously operate everything from how they manage the information entrusted to them and how they evaluate the impact and risks of AI, to how they respond when problems occur and how they feed the results into the next round of improvement.

With this certification to ISO/IEC 27001 and ISO/IEC 42001, the criteria for continuously reviewing and improving both the information security and AI management that underpin the provision of GENFLUX have become clearer.

We do not see obtaining this certification as an endpoint. We will keep refining our product foundation, reflecting it in our day-to-day development and operations, so that our customers can keep using AI in production with confidence.”

■ Future outlook

Based on ISO/IEC 27001:2022 and ISO/IEC 42001:2023, Elith will continue to assess information security risks and the risks and impacts associated with AI, and to carry out employee training, internal audits, and management review.

Elith will also reflect the operational knowledge it has accumulated in information security, AI safety, and AI governance in the quality evaluation, security, and governance features of GENFLUX.

We will continuously update our management methods themselves in response to changes in technology, the environment in which AI is used, and the requirements society places on AI, and will keep building a foundation that lets enterprises run AI in production with confidence.