Commitment
World AI Governance (WAIG) Foundation implements defense-in-depth security across public websites, admin consoles, Academy Studio, and programme operations.
Controls in practice
- Transport encryption (TLS) for public endpoints
- Web Application Firewall (WAF) and DDoS protections where deployed
- Content Security Policy (CSP) and hardened HTTP headers
- Multi-factor and phishing-resistant options (OTP, passkeys, Microsoft Entra SSO)
- Role-based access for staff, trainers, partners, and learners
- Secure development practices and dependency awareness
- Centralised logging / SIEM-oriented audit trails for privileged actions
- Cryptographic evidence patterns for assurance exports where applicable
Data protection alignment
Security practices support privacy commitments in our Privacy Policy and programme agreements, including least-privilege access and segregation of environments.
Supplier & hosting
Infrastructure and SaaS processors are selected with security and availability requirements; access is limited to operational need.
Incident awareness
Suspected security incidents affecting our properties should be reported to security@waigfoundation.org. Researchers should follow our Vulnerability Disclosure policy.
Assurance programmes
WAIG Foundation assurance and Academy offerings help organisations improve their own AI and security governance maturity; they do not replace customer legal obligations.
Contact
Security questionnaires and disclosures: security@waigfoundation.org