Trust centre · For procurement and third-party risk
Who we depend on, and what we will not claim on their behalf.
Third-party risk assessment fails when a vendor blurs its own controls into its suppliers'. This page keeps the two apart: our dependencies, our own controls, and where the boundary sits.
How to read the evidence status on this page
- Verified in product
- Implemented in the platform and covered by automated tests or recorded verification evidence.
- Controlled document
- Maintained as a version-controlled internal artefact, issued under agreement rather than published.
- In external assurance
- Scheduled with, or in progress with, an independent party. No external opinion is claimed until the report exists.
- Not claimed
- Deliberately not asserted. Stated openly so a reviewer never has to infer whether it exists.
| Claim | Status | What evidences it |
|---|---|---|
| Named sub-processor register with purpose and location | Controlled document | Maintained as a controlled document issued with the processing agreement, with contractual change notification. |
| Open-source dependency licences reviewed and recorded | Verified in product | A generated licence register records every dependency and its licence, and is refreshed as part of release verification. |
| No known high or critical dependency advisories at release | Verified in product | Dependency advisory scanning runs in the release gate. A high or critical advisory blocks the release rather than generating a ticket. |
| Intellectual property provenance of the platform | Controlled document | Contributor register, provenance statement and development-tooling disclosure are maintained and issued to diligence reviewers under agreement. |
| Third-party attestations obtained from our own suppliers | In external assurance | We rely on the published assurance of the managed platforms we use and are formalising annual review of those attestations. We do not restate another party's certification as our own. |
| Our certifications inherited from suppliers | Not claimed | Running on a certified platform does not certify AIRAS Cloud. We say so explicitly rather than borrowing our suppliers' badges. |
The boundary, stated
Our infrastructure providers hold their own certifications. Those certifications cover their platform, not our application, our configuration or our processes. Any assurance you need about AIRAS Cloud itself must come from our own evidence, which is what this trust centre publishes.
Contracting entity
AIRAS Cloud is a trading name of AFRH Consulting Limited, a company registered in Ireland, company registration number 798243. Contracts, processing terms and liability sit with that entity, and the order documentation names it explicitly so a procurement reviewer is never contracting with a brand.
What a supplier review receives
- Sub-processor register with purpose and processing location
- Data processing agreement and data schedule
- Service description and service level schedule
- Support policy and incident severity model
- Customer responsibility matrix
- Dependency licence and advisory position
- Backup, recovery and continuity documentation
- Completed security questionnaire against your template
Third-party risk assessment to complete?
Send your questionnaire and we will complete it against the current controlled documentation, flagging anything we cannot yet evidence.
No commercial commitment. No confidential information required.