Skip to content
AIRAS Cloud

Security and trust

Governance software has to be governable itself.

This page describes the target security and trust model for AIRAS Cloud. It is maintained by the AIRAS Cloud team and does not represent independent certification.

Security controls

Identity and access

Enterprise identity, role-based access and segregation of duties so submitters cannot approve their own records.

Tenant-scoped data

Customer data is scoped to the tenant, with access decisions applied at the record and evidence level.

Encryption

Data is encrypted in transit and at rest, with managed secrets and controlled key handling.

Evidence integrity

Attachments are versioned and hashed, linked to the control they satisfy and retained in append-only history.

Audit logging

Material actions, decisions and exports are recorded so the decision trail can be reconstructed reliably.

Backup and release control

Backup, restore and controlled release practices support continuity and change discipline.

Framework alignment

  • EU AI Act
  • NIST AI RMF
  • ISO/IEC 42001
  • GDPR / DPIA
  • EU GMP Annex 11
  • SOC 2 / ISO 27001
  • OWASP GenAI guidance

Framework references describe design alignment and evidence support. They do not represent certification, legal advice or a guarantee of compliance.

Responsible disclosure: please report suspected security issues to interest@airascloud.com.

Frequently asked questions

What is AIRAS Cloud?
AIRAS Cloud is an operational AI governance and risk assurance platform. It helps organisations register AI use, assess risk, route reviewers, manage controls and evidence, record decisions and monitor the lifecycle.
Is AIRAS Cloud only for generative AI?
No. It is designed for AI systems, models, agents, embedded vendor features, analytics, decision support, automation and other material AI-enabled capabilities.
Does AIRAS Cloud make the final approval decision?
No. AIRAS Cloud supports structured assessment and decision workflow. Authorised people and governance bodies retain accountability.
Does AIRAS Cloud guarantee EU AI Act or regulatory compliance?
No. AIRAS Cloud supports structured readiness, mapping, evidence and operational governance. It does not replace legal or regulatory advice and does not guarantee compliance.
Can AIRAS Cloud support pharmaceutical and GxP environments?
It is designed with regulated-industry concerns such as GxP screening, supplier assessment, data integrity, validation route, evidence, audit trail, change control and periodic review in mind. Customer intended use and validation requirements remain customer decisions.
How is customer information protected?
The target architecture uses enterprise identity, role-based access, tenant-scoped data controls, encryption, secure evidence storage, audit logging, managed secrets, backup and controlled release practices.
Can AIRAS Cloud integrate with existing systems?
The platform is designed with REST APIs, signed webhooks and selective connectors so it can coexist with GRC, ITSM, CMDB, document, identity, model and security platforms.
How can my organisation learn more?
Use the Register your interest form. The AIRAS Cloud team will review your organisation, governance needs and preferred next step.

Security or procurement questions?

Register your interest and select Security and procurement so the right information reaches your team.

No pricing commitment. No confidential information required.