Skip to content
AIRAS Cloud

Trust centre

Security, privacy and operational trust

A governance platform holds the record of how an organisation makes AI decisions. It has to be held to the standard it asks of everyone else.

What are you reviewing?

Start with your discipline. Every claim behind it carries a status: verified, controlled, in external assurance, or not claimed.

How to read the evidence status on this page

Verified in product
Implemented in the platform and covered by automated tests or recorded verification evidence.
Controlled document
Maintained as a version-controlled internal artefact, issued under agreement rather than published.
In external assurance
Scheduled with, or in progress with, an independent party. No external opinion is claimed until the report exists.
Not claimed
Deliberately not asserted. Stated openly so a reviewer never has to infer whether it exists.

Independent assurance status, stated up front

AIRAS Cloud has not yet been penetration tested, certified or audited by an independent party. Security testing to date is internal, and the readiness pack for an accredited engagement is complete.

Read the full external assurance status

Security architecture

  • Enterprise identity with role-based access control
  • Segregation of duties enforced in the workflow, not requested
  • Tenant-scoped data isolation with row-level authorisation
  • Encryption in transit and at rest
  • Least-privilege service access and secret management
  • Hardened transport security headers on every response
  • Append-only audit history that cannot be silently edited
  • Hashed evidence artefacts for integrity verification

Data handling and privacy

Customer data is processed only to deliver the service. AIRAS Cloud does not use customer content to train models. Data residency, retention and deletion positions are agreed contractually before onboarding, and pilots run on synthetic, de-identified or expressly approved data unless a prior privacy and security review says otherwise.

Our privacy notice sets out lawful basis, retention and the rights available to individuals whose data is processed through the service.

Operational controls

Product change moves through governed, versioned release process with review before deployment. Rulesets, policy packs and control libraries are versioned separately from code so a governance change is itself an auditable event.

Incidents are triaged against defined severity, with customer notification commitments set out in the applicable agreement.

Assurance status

We publish only what we can evidence. AIRAS Cloud maps its own operating controls to ISO/IEC 27001 and ISO/IEC 42001 themes and supports customer-led security reviews with a security pack, architecture detail and completed questionnaires. We do not claim certifications we do not hold.

Client test summary sheet

Automated verification of the regulatory engines, the public site and the governance demonstration workspace, executed headlessly against the source tree and a running build. Every figure below is generated from the recorded evidence artefacts. No proprietary scoring logic or ruleset internals are disclosed.

Cases in register
2014
Passed
2014
Failed
0
Pass rate (executed)
100.0%

Engine and platform logic

Deterministic regulatory engines, discovery pipeline, access control and the published scoring illustration, executed against the current source tree.

Automated unit and integration suite · 1287 cases · 0 failed · executed 2 Sept 2026

Engine and platform logic — results by test suite
SuiteCasesResult
AI-system qualification engine24All passed
Demonstration scoring illustration26All passed
Discovery detection and document pipeline143All passed
High-risk classification and impact triggers23All passed
Identity, tenancy and access control39All passed
Operator role assessment30All passed
Other verified modules791All passed
Regulatory framework and pipeline ordering31All passed
Regulatory obligations register15All passed
Regulatory validation corpus132All passed
Ruleset administration and notifications15All passed
Transparency screening (Article 50)18All passed

Website and demonstration workspace

Public website, the gated governance demonstration workspace, the guided tour and the machine-readable surface, executed headlessly against a running build.

Automated end-to-end suite · 727 cases · 0 failed · executed 2 Sept 2026

Website and demonstration workspace — results by test suite
SuiteCasesResult
Route availability53All passed
Metadata integrity318All passed
Structured data53All passed
Accessibility landmarks106All passed
Runtime health53All passed
Navigation5All passed
Machine endpoints5All passed
Security controls7All passed
Access control4All passed
Demonstration screens42All passed
Tool data integrity10All passed
Lead capture4All passed
Readiness assessment1All passed
Responsive layout12All passed
Performance budget53All passed
Session lifecycle1All passed

Summary generated from the verification evidence on 2 Sept 2026 and published for evaluation and procurement purposes. The full case register, including expected and observed outcomes for every case, is available on request.

Responsible disclosure

If you believe you have found a security issue, contact interest@airascloud.com with enough detail to reproduce it. We acknowledge reports, investigate promptly and will not pursue action against good-faith research that respects customer data and service availability.

Integration and onboarding documentation

The AIRAS Cloud Integration and Onboarding Gospel is written, tested and validated: a 45-page controlled technical manual covering procurement gates, contracting instruments, tenant provisioning and isolation, role-based access and SSO, evidence onboarding waves, the regulatory assessment sequence, security controls, environments and recovery, go-live criteria, the 90-day hypercare warranty and per-layer troubleshooting.

It is a confidential document issued under agreement rather than published, and is made available immediately to customers and to organisations in an active procurement or assurance review. Request it and we will issue the current controlled version.

Statement of integration readiness

AIRAS Cloud maintains a signed Statement of Integration Readiness covering tenant isolation, identity and access management, upload content safety, recoverability, service levels and the contractual position. Each line in it names the artefact that evidences it, and any item that is not complete is disclosed rather than implied.

The current version records enforced multi-factor authentication for privileged roles, a full member invitation and offboarding lifecycle with session revocation, SAML single sign-on configurable against your identity provider, a deterministic upload content-safety gate, documented backup and disaster recovery objectives, and a data processing agreement with a named sub-processor register. It is issued confidentially on request to customers and assurance reviewers.

Security or procurement review under way?

Tell us what your assurance process requires and we will respond with the architecture detail, control mapping and documentation your reviewers need.

No commercial commitment. No confidential information required.