Skip to content
AIRAS Cloud

Enterprise · For procurement, security and risk reviewers

Built to withstand scrutiny.

Enterprise AI governance cannot credibly be sold from an organisation that has not governed itself. AIRAS Cloud operates against a controlled internal assurance estate spanning product, security, privacy, AI governance, impact assessment, resilience, testing, release, operations, intellectual property and supplier risk.

How to read the evidence status on this page

Verified in product
Implemented in the platform and covered by automated tests or recorded verification evidence.
Controlled document
Maintained as a version-controlled internal artefact, issued under agreement rather than published.
In external assurance
Scheduled with, or in progress with, an independent party. No external opinion is claimed until the report exists.
Not claimed
Deliberately not asserted. Stated openly so a reviewer never has to infer whether it exists.

How to read this page

Each domain below names its purpose, its current evidence status, the accountable role and the basis on which material can be released. Confidential artefacts are not published here. Where a domain is marked restricted, it is available only inside a formal process such as executed diligence or a signed agreement.

Assurance estate

Nineteen governed domains, each with a named owner.

Integrated management system

01

The single register that binds policy, control ownership, review cadence and internal audit across every other domain below.

Controlled document
Owner
Chief Executive
Release
On request under agreement

Information security

02

Threat model, control register, hardening standards, key handling, logging and vulnerability management for the platform and its build chain.

Verified in product
Owner
Chief Executive, security accountable
Release
Public summary

Privacy and data protection

03

Processing records, lawful basis, controller and processor roles, retention, deletion, data-subject handling and transfer position.

Verified in product
Owner
Data protection lead
Release
Public summary

Operational resilience and BCDR

04

Recovery objectives, encrypted backup and scripted restore, rebuild from source control, continuity scenarios and concentration risk.

Verified in product
Owner
Chief Product Officer
Release
Public summary

AI management system

05

Our own governance of AI used inside the business and inside the product, including where a model may and may not influence a decision.

Controlled document
Owner
Chief Product Officer
Release
On request under agreement

AI system impact assessment

06

Impact-assessment method applied to our own product features, aligned to recognised impact-assessment guidance rather than certified against it.

Controlled document
Owner
Chief Product Officer
Release
On request under agreement

Product governance

07

How scope, regulatory interpretation and ruleset change are proposed, reviewed, approved and versioned before release.

Controlled document
Owner
Chief Product Officer
Release
On request under agreement

Architecture and data

08

Tenant isolation model, data model, authorisation boundaries, storage separation and audit-event design.

Verified in product
Owner
Chief Executive
Release
On request under agreement

API and integration

09

Interface contracts, authentication, scope limits, rate control and the governed interoperability surface for external systems.

Verified in product
Owner
Chief Executive
Release
On request under agreement

Test and validation

10

Automated unit, integration and end-to-end coverage, authorisation verification and regression evidence produced on every release.

Verified in product
Owner
Chief Executive
Release
Public summary

Configuration, change and release

11

Version control, review before deployment, separate versioning for rulesets and policy packs, and traceable release records.

Verified in product
Owner
Chief Executive
Release
On request under agreement

Platform operations

12

Monitoring, availability handling, incident classification and the operational runbooks used when something goes wrong.

Controlled document
Owner
Chief Executive
Release
On request under agreement

Customer support

13

Support model, response expectations, escalation route and how support access to tenant data is limited and recorded.

Controlled document
Owner
Chief Product Officer
Release
On request under agreement

Customer implementation

14

Onboarding method, configuration decisions, role design, evidence migration and the definition of a completed implementation.

Controlled document
Owner
Chief Product Officer
Release
On request under agreement

Intellectual property, source and trade secrets

15

Ownership and provenance of source, asset register, trade-secret register and the controls protecting engine logic.

Controlled document
Owner
Chief Executive
Release
Restricted

People and contributor governance

16

Contributor onboarding, confidentiality obligations, access provisioning and removal, and separation of duties.

Controlled document
Owner
Chief Executive
Release
On request under agreement

Supplier and third-party risk

17

Sub-processor register, dependency assurance, licence and advisory scanning, and review of platform providers we rely on.

Verified in product
Owner
Chief Executive
Release
Public summary

Commercial, procurement and transaction governance

18

Contracting position, order-form control, pricing governance and the diligence pack maintained for corporate processes.

Controlled document
Owner
Chief Executive
Release
Restricted

External assurance

19

Independent penetration testing, certification readiness and third-party review: scoped and prepared, not yet completed.

In external assurance
Owner
Chief Executive
Release
Public summary

Send us your review, not a questionnaire template.

Tell us which domain you need to satisfy and the form your organisation expects it in. We will reply with the available material, or with the terms under which it can be released.

Do not submit credentials, customer data or sensitive evidence in a web form.