Trust centre
Security, privacy and operational trust
A governance platform holds the record of how an organisation makes AI decisions. It has to be held to the standard it asks of everyone else.
Security architecture
- Enterprise identity with role-based access control
- Segregation of duties enforced in the workflow, not requested
- Tenant-scoped data isolation with row-level authorisation
- Encryption in transit and at rest
- Least-privilege service access and secret management
- Hardened transport security headers on every response
- Append-only audit history that cannot be silently edited
- Hashed evidence artefacts for integrity verification
Data handling and privacy
Customer data is processed only to deliver the service. AIRAS Cloud does not use customer content to train models. Data residency, retention and deletion positions are agreed contractually before onboarding, and pilots run on synthetic, de-identified or expressly approved data unless a prior privacy and security review says otherwise.
Our privacy notice sets out lawful basis, retention and the rights available to individuals whose data is processed through the service.
Operational controls
Product change moves through governed, versioned release process with review before deployment. Rulesets, policy packs and control libraries are versioned separately from code so a governance change is itself an auditable event.
Incidents are triaged against defined severity, with customer notification commitments set out in the applicable agreement.
Assurance status
We publish only what we can evidence. AIRAS Cloud maps its own operating controls to ISO/IEC 27001 and ISO/IEC 42001 themes and supports customer-led security reviews with a security pack, architecture detail and completed questionnaires. We do not claim certifications we do not hold.
Responsible disclosure
If you believe you have found a security issue, contact interest@airascloud.com with enough detail to reproduce it. We acknowledge reports, investigate promptly and will not pursue action against good-faith research that respects customer data and service availability.
Security or procurement review under way?
Tell us what your assurance process requires and we will respond with the architecture detail, control mapping and documentation your reviewers need.
No pricing commitment. No confidential information required.