Secnora Becomes a Founding Signatory of the CREST AI Charter

Secnora has become a founding signatory of the CREST AI Charter, supporting responsible AI use in cybersecurity and the CREST AI Principles. By joining this founding group of around 60 signatories across 15 countries, Secnora is supporting an industry-wide effort to promote trust, transparency, accountability and assurance in AI-enabled cybersecurity services. Created by CREST, the global not-for-profit that accredits providers and sets professional standards across the cybersecurity industry, the Charter helps organisations adopt AI responsibly. Built around CREST’s nine AI Principles, it provides a framework for ensuring AI-enabled activities remain secure, accountable and subject to appropriate human oversight.

Why the CREST AI Charter Matters Now
AI is no longer optional in security testing, it is already standard practice. A CREST survey of 62 providers across 19 countries found that 69% are using AI somewhere in their penetration testing workflows and 76% increased that use in the past year alone, mostly for reconnaissance, analysis and report drafting. That shift cuts both ways. AI lets a lean testing team cover more ground and faster but assurance work runs on trust, and trust breaks the moment a client cannot tell what a tool decided from what a tester actually verified.

The real question for buyers is no longer whether a provider uses AI. It is whether someone competent is still checking its output before it reaches them, and 85% of providers surveyed already expect clients to ask exactly that. The CREST AI Charter exists to answer that question before it gets asked. Built around CREST’s nine AI Principles, it gives providers a shared standard for keeping a qualified person accountable for AI-assisted work, instead of leaving every client to take a vendor’s claims on faith.

Our Commitment to the CREST AI Principles
CREST built the Charter around nine principles, each covering a different layer of AI governance, from initial scope and oversight through to long-term resilience. By signing the Charter, Secnora publicly supports all nine principles:

  • Accountability and governance: Defining the scope of AI use and applying oversight appropriate to its risk.
  • Transparency of use: Being clear about where AI is used, including its benefits and limitations.
  • Documentation and auditability: Ensuring AI-enabled activities remain traceable, reviewable and auditable.
  • Boundaries and control: Maintaining qualified human oversight of AI-assisted decisions and outputs.
  • Data handling, sovereignty and client control: Protecting client data and maintaining transparency around its use.
  • Security and confidentiality: Applying appropriate safeguards to data, prompts and AI-generated outputs.
  • Secure development of AI tooling: Building and maintaining AI-enabled tools with security by design.
  • Supply chain assurance: Assessing third-party AI providers against appropriate security and governance standards.
  • Resilience and business continuity: Maintaining continuity plans should AI systems or dependencies become unavailable.

These principles reinforce a simple but important objective: ensuring AI enhances cybersecurity services without compromising trust, professional judgment or accountability. While AI can improve efficiency and support decision-making, ultimate responsibility for outcomes must always remain with qualified security professionals.

Our Approach to Responsible AI
The CREST AI Principles align closely with Secnora’s existing approach to the use of AI in cybersecurity services. Signing the Charter formalises these commitments and demonstrates them publicly to clients, partners and the wider cybersecurity community. In practice, that means:

  • Accountability: AI can assist with analysis, automation and efficiency, but responsibility for decisions, findings and recommendations remains with experienced security professionals. Every AI-assisted output is subject to appropriate human review and oversight.
  • Transparency: Where AI plays a material role in the delivery of a service, we believe clients should understand how it is being used, what value it provides and any limitations that may apply.
  • Data Protection and Client Control: Data handling, confidentiality and client control remain fundamental. Information is managed in accordance with agreed requirements, with clear governance around how data is processed and used.

These commitments help ensure that AI enhances cybersecurity services without compromising trust, accountability or professional judgment.

What This Means for Our Clients
For organizations that rely on Secnora for security assessments, penetration testing, advisory engagements and broader cybersecurity programs, the CREST AI Charter provides additional assurance around how AI is used within the delivery of cybersecurity services.

Where AI supports our work, we remain committed to transparency, accountability and human oversight. AI can help improve efficiency, accelerate analysis and support decision-making but responsibility for findings, recommendations and outcomes remains with qualified security professionals.

By signing the CREST AI Charter, Secnora is reinforcing its commitment to responsible AI adoption through a recognised industry framework. For our clients, that means greater confidence that AI-enabled activities are governed appropriately, supported by clear standards and aligned with the professional practices expected across the cybersecurity industry.

To learn more about the CREST AI Charter and CREST’s AI Principles, visit the CREST website.

To Learn More About SECNORA AI Security AI Security