Trust centre
Security, privacy and operational trust
A governance platform holds the record of how an organisation makes AI decisions. It has to be held to the standard it asks of everyone else.
What are you reviewing?
Start with your discipline. Every claim behind it carries a status: verified, controlled, in external assurance, or not claimed.
CISO, security engineer, CTO
OpenEngineering assurance
Implemented controls, automated verification, response hardening, upload safety and step-up authentication — each with its evidence status.
Data protection officer, privacy counsel
OpenData protection and privacy
Processing purpose, controller and processor roles, tenant isolation, encryption, retention, deletion and individual rights.
Operational resilience, DORA and NIS2 reviewers
OpenResilience and continuity
Backup and recovery objectives, scripted restore, rebuild from source control, incident handling and concentration risk.
Programme director, QA lead, audit reviewer
OpenDelivery governance and traceability
The engineering management system behind the platform: GitHub as authoritative source, Jira delivery blocks, generated Confluence records and native Xray test evidence.
Procurement and third-party risk
OpenSupplier and dependency assurance
Sub-processors, managed platform dependencies, licence and advisory position, contracting entity and IP provenance.
How to read the evidence status on this page
- Verified in product
- Implemented in the platform and covered by automated tests or recorded verification evidence.
- Controlled document
- Maintained as a version-controlled internal artefact, issued under agreement rather than published.
- In external assurance
- Scheduled with, or in progress with, an independent party. No external opinion is claimed until the report exists.
- Not claimed
- Deliberately not asserted. Stated openly so a reviewer never has to infer whether it exists.
Independent assurance status, stated up front
AIRAS Cloud has not yet been penetration tested, certified or audited by an independent party. Security testing to date is internal, and the readiness pack for an accredited engagement is complete.
Security architecture
- Enterprise identity with role-based access control
- Segregation of duties enforced in the workflow, not requested
- Tenant-scoped data isolation with row-level authorisation
- Encryption in transit and at rest
- Least-privilege service access and secret management
- Hardened transport security headers on every response
- Append-only audit history that cannot be silently edited
- Hashed evidence artefacts for integrity verification
Data handling and privacy
Customer data is processed only to deliver the service. AIRAS Cloud does not use customer content to train models. Data residency, retention and deletion positions are agreed contractually before onboarding, and pilots run on synthetic, de-identified or expressly approved data unless a prior privacy and security review says otherwise.
Our privacy notice sets out lawful basis, retention and the rights available to individuals whose data is processed through the service.
Operational controls
Product change moves through governed, versioned release process with review before deployment. Rulesets, policy packs and control libraries are versioned separately from code so a governance change is itself an auditable event.
Incidents are triaged against defined severity, with customer notification commitments set out in the applicable agreement.
Assurance status
We publish only what we can evidence. AIRAS Cloud maps its own operating controls to ISO/IEC 27001 and ISO/IEC 42001 themes and supports customer-led security reviews with a security pack, architecture detail and completed questionnaires. We do not claim certifications we do not hold.
Client test summary sheet
Automated verification of the regulatory engines, the public site and the governance demonstration workspace, executed headlessly against the source tree and a running build. Every figure below is generated from the recorded evidence artefacts. No proprietary scoring logic or ruleset internals are disclosed.
- Cases in register
- 2014
- Passed
- 2014
- Failed
- 0
- Pass rate (executed)
- 100.0%
Engine and platform logic
Deterministic regulatory engines, discovery pipeline, access control and the published scoring illustration, executed against the current source tree.
Automated unit and integration suite · 1287 cases · 0 failed · executed 2 Sept 2026
| Suite | Cases | Result |
|---|---|---|
| AI-system qualification engine | 24 | All passed |
| Demonstration scoring illustration | 26 | All passed |
| Discovery detection and document pipeline | 143 | All passed |
| High-risk classification and impact triggers | 23 | All passed |
| Identity, tenancy and access control | 39 | All passed |
| Operator role assessment | 30 | All passed |
| Other verified modules | 791 | All passed |
| Regulatory framework and pipeline ordering | 31 | All passed |
| Regulatory obligations register | 15 | All passed |
| Regulatory validation corpus | 132 | All passed |
| Ruleset administration and notifications | 15 | All passed |
| Transparency screening (Article 50) | 18 | All passed |
Website and demonstration workspace
Public website, the gated governance demonstration workspace, the guided tour and the machine-readable surface, executed headlessly against a running build.
Automated end-to-end suite · 727 cases · 0 failed · executed 2 Sept 2026
| Suite | Cases | Result |
|---|---|---|
| Route availability | 53 | All passed |
| Metadata integrity | 318 | All passed |
| Structured data | 53 | All passed |
| Accessibility landmarks | 106 | All passed |
| Runtime health | 53 | All passed |
| Navigation | 5 | All passed |
| Machine endpoints | 5 | All passed |
| Security controls | 7 | All passed |
| Access control | 4 | All passed |
| Demonstration screens | 42 | All passed |
| Tool data integrity | 10 | All passed |
| Lead capture | 4 | All passed |
| Readiness assessment | 1 | All passed |
| Responsive layout | 12 | All passed |
| Performance budget | 53 | All passed |
| Session lifecycle | 1 | All passed |
Summary generated from the verification evidence on 2 Sept 2026 and published for evaluation and procurement purposes. The full case register, including expected and observed outcomes for every case, is available on request.
Responsible disclosure
If you believe you have found a security issue, contact interest@airascloud.com with enough detail to reproduce it. We acknowledge reports, investigate promptly and will not pursue action against good-faith research that respects customer data and service availability.
Integration and onboarding documentation
The AIRAS Cloud Integration and Onboarding Gospel is written, tested and validated: a 45-page controlled technical manual covering procurement gates, contracting instruments, tenant provisioning and isolation, role-based access and SSO, evidence onboarding waves, the regulatory assessment sequence, security controls, environments and recovery, go-live criteria, the 90-day hypercare warranty and per-layer troubleshooting.
It is a confidential document issued under agreement rather than published, and is made available immediately to customers and to organisations in an active procurement or assurance review. Request it and we will issue the current controlled version.
Statement of integration readiness
AIRAS Cloud maintains a signed Statement of Integration Readiness covering tenant isolation, identity and access management, upload content safety, recoverability, service levels and the contractual position. Each line in it names the artefact that evidences it, and any item that is not complete is disclosed rather than implied.
The current version records enforced multi-factor authentication for privileged roles, a full member invitation and offboarding lifecycle with session revocation, SAML single sign-on configurable against your identity provider, a deterministic upload content-safety gate, documented backup and disaster recovery objectives, and a data processing agreement with a named sub-processor register. It is issued confidentially on request to customers and assurance reviewers.
Security or procurement review under way?
Tell us what your assurance process requires and we will respond with the architecture detail, control mapping and documentation your reviewers need.
No commercial commitment. No confidential information required.