All Products
Search
Document Center

Platform For AI:Security compliance qualifications

Last Updated:Feb 28, 2026

To ensure data security and regulatory compliance, Alibaba Cloud adheres to stringent security compliance standards. This topic describes the security compliance qualifications that Platform for AI (PAI) has acquired and their significance for protecting your business and data.

Qualification Name

Scope

Description

ISO 27018

Global

Cloud service provider standard for personal data protection, reflecting privacy and security management maturity.

ISO 27701

Global

Extension of information security management standards addressing privacy information management for all organizations, demonstrating privacy protection capabilities.

ISO 27799

Global

Guidelines for healthcare providers on protecting personal health information.

ISO 29151

Global

Guidelines for protecting personally identifiable information (PII).

ISO 9001

Global

Quality management system requirements for organizations of all types and sizes to ensure continuous improvement of product or service quality.

ISO 20000

Global

IT Service Management (ITSM) standard enabling organizations to optimize IT services for business requirements and processes.

ISO 22301

Global

Business continuity management requirements to help organizations recover from disruptive incidents.

ISO 27001

Global

Information security management requirements for securing information assets.

ISO 27017

Global

Information security guidelines specific to cloud services.

BS 10012

Global

Requirements for data protection and processing in personal information management systems.

CSA STAR

Global

Cloud Security Trust Assurance Standard assessing security practices and privacy measures of cloud service providers.

MLPS Level 3

China

Multi-Level Protection Scheme (MLPS) Level 3 mandating stringent security measures for systems where data breaches may harm societal order.

SOC

International

Controls and reporting demonstrating that service organizations (e.g., data centers) can manage and protect data.

PCI DSS

International

Payment Card Industry Data Security Standard (PCI DSS) ensuring all entities that accept, process, store, or transmit credit card information maintain a secure environment.