Skip to content
AIRAS Cloud

Trust centre · External assurance

We publish what we can evidence, and name what we cannot.

Most vendor trust pages are written to survive a skim. This one is written to survive a reviewer who reads it properly, so it says exactly where independent assurance stands today.

How to read the evidence status on this page

Verified in product
Implemented in the platform and covered by automated tests or recorded verification evidence.
Controlled document
Maintained as a version-controlled internal artefact, issued under agreement rather than published.
In external assurance
Scheduled with, or in progress with, an independent party. No external opinion is claimed until the report exists.
Not claimed
Deliberately not asserted. Stated openly so a reviewer never has to infer whether it exists.
External assurance — current status
ClaimStatusWhat evidences it
Internal security testing and hardening against a documented threat modelVerified in productAutomated suites, code review and targeted remediation, with the attack surface inventoried and each finding tracked to closure in a version-controlled register.
Penetration-test readiness pack prepared for an accredited providerVerified in productScope, rules of engagement, readiness checklist, attack-surface inventory and threat model are complete and issued to providers unchanged.
Independent penetration test with retest of fixed findingsIn external assuranceProvider selection and a dedicated staging target are in progress. The result will be published as a status here once the test and its retest are complete.
Independent review of the ARIE regulatory logicIn external assurancePlanned as a separate engagement from security testing, because the questions and the competence required are different.
ISO/IEC 27001 certificationNot claimedControls are mapped to the standard's themes to support customer review. No certification is held and none is presented.
ISO/IEC 42001 certificationNot claimedThe platform is built around the management-system themes of the standard. That is a design position, not an accredited certification.
SOC 2 reportNot claimedNo SOC 2 examination has been performed and no report exists.

Our claim discipline

No AIRAS Cloud website page, proposal, data-room document or sales conversation may describe the platform as independently penetration tested, certified or externally audited until the corresponding report exists and, where findings were raised, has been retested. Where a claim is not yet supportable, we mark it as scheduled or not claimed instead of softening the language.

Why it is sequenced this way

Readiness first, then the independent opinion.

Testing an unprepared target wastes the engagement

An accredited test is worth having once the obvious classes of issue are already closed, the attack surface is documented and the tester can reach every role, tenant and gate they need. We have spent that preparation deliberately: throttling on public surfaces, hardened responses, tenant isolation re-checked in the application layer, an upload pipeline that fails closed, and a step-up gate enforced server-side.

The remaining items are environmental and commercial rather than technical: an isolated staging target holding no real data, test identities covering every role including one privileged account with a second factor and one without, and a signed statement of work that includes retesting.

What we will publish afterwards

  • The date and scope of the engagement
  • The provider's accreditation and the fact of retesting
  • Severity counts by category, and closure status
  • Any accepted residual risk, and why it was accepted
  • The date the status on this page was last reviewed

Does your approval require independent assurance now?

Tell us the specific report your process needs and by when. We will tell you honestly whether it exists, when it will, and what interim evidence we can issue under agreement.

No commercial commitment. No confidential information required.