The Standard for Ethical AI in Public Safety

For every IREX engagement, the highest priority is optimizing safety and life-enhancing technology within the privacy and ethical norms of free societies. We don't promise ethics in a policy document. We engineer it into the architecture, where it cannot be switched off.

Book a Demo
  • 250,000+cameras held to this standard
  • 8countries in production
  • NIST FRVTindependently evaluated
  • World firstCase ID mandate in video analytics

Why It Matters

Ethics as Architecture, Not Afterthought

Public safety agencies face an urgent challenge: how to use the power of artificial intelligence while upholding the rights and trust of the communities they serve. Surveillance technology without ethical guardrails erodes public confidence, invites regulatory risk, and undermines the very safety it aims to provide.

IREX was built from the ground up to solve this problem. Rather than treating ethics as a compliance checkbox bolted on at the end, accountability is embedded in every layer of the platform: the architecture, the access controls, the audit trails, and the limits on what the AI is permitted to do at all. The result: every high-risk AI action is justified, logged and auditable.

The Framework

Six Pillars of Trust

Transparency by Design is a doctrine, and these six pillars are how it governs the way the platform creates, accesses, stores and shares data. They are six commitments enforced by the system itself, not six promises.

01

Full Transparency

Every action is written to a detailed, non-erasable audit log that supervisors and oversight bodies can search in full: database additions, search queries, alert configurations, video exports, permission changes. Who did what, when, and why is a matter of record, not reconstruction.

Security & Compliance
02

Cybersecurity and Privacy Protection

TLS 1.3 end to end, multilayer WAF, IDS/IPS and network filtering, JWT with asymmetric signatures and rotating keys, MFA, and penetration testing against the OWASP Testing Guide on every major release. Customer data is owned exclusively by the customer.

Security Policy
03

Narrow Constraints for Law Enforcement

Detection is limited to pre-identified people: wanted suspects, missing children, trafficking victims. Real-time biometric database size is capped, and recognition of random individuals is not possible. These limits are architectural, not policy: misuse is structurally prevented, not merely prohibited.

Video Search & Investigations
04

Permission-Driven Interface

Hierarchical role-based access control decides which cameras, recordings, analytics modules, databases and results each operator can reach. Configuration changes are restricted to top-level roles and logged in full detail.

Security & Compliance
05

Bias Awareness and Mitigation

Our face-recognition engine is trained on a proprietary 40-million-image dataset optimized for real CCTV conditions and evaluated independently in the NIST Face Recognition Vendor Test. Where systematic bias exists, our policy is to disclose it and its estimated impact to the customer.

Face Recognition & Bias Testing
06

Ethics Best Practices and Compliance

User guidelines, audit processes and compliance checklists built with privacy, civil-liberties and law-enforcement experts. They support GDPR and CCPA, and align with the EU AI Act, the NIST AI RMF and the FBI CJIS Security Policy.

Privacy Policy

Case ID: A World First

Every High-Risk AI Action Carries the Reason It Was Allowed

Case ID is a mandatory justification mechanism built into the platform. Before performing any privacy-sensitive AI action, the operator enters a Case ID. That is a reference to the legal document granting the lawful basis for the action: a police case file, a court order, a missing-person report. The reference is recorded permanently alongside the action it authorizes, and no operator can proceed without it.

IREX is the world's only video management and analytics platform to offer comprehensive logging of all high-risk AI operations, with every action tied to a legitimate case reference. It is a platform-level mandate, not a setting an administrator can switch off.

When Case ID Is Required

  • People searches: photo, name, appearance
  • Vehicle searches: plate, make, model
  • Event searches: weapons, intrusion, unattended items
  • Watchlist management: adding or modifying entries
  • Alarm monitor management: real-time alert streams
  • Media management: upload, analysis, export of evidence
  • Live video access: live feeds and archived recordings
  • Logbook access: opening and searching the audit log (since 4.40)

Every Logbook Entry Answers Four Questions

Who

The operator’s identity and role, on every entry.

What

The action taken: search type, database operation, export.

When

A precise timestamp, in an append-only sequence.

Why

The Case ID: the legal justification, bound permanently.

Tamper-proof by export. Signed log files are automatically exported daily to a secure archive. They are digitally signed to detect tampering, available even after a disaster or breach, and reviewable by ethics committees, inspectors general and court-appointed auditors without platform access.

Docs: View the Logbook

Case ID logging turns AI accountability from a policy aspiration into a technical reality. It protects communities from misuse, protects officers by documenting their lawful actions, and gives oversight bodies the evidence to verify that AI is being used responsibly.

Accountability, Audited

The Audit Trail Audits Itself

Every high-risk action already carries a Case ID and lands in the Logbook. The question an oversight body asks next is who reads that record, and whether reading it leaves a trace of its own. Releases 4.37 to 4.40 answer it: the audit trail is now governed by the same rules as the actions it captures, so IREX’s commitment that 100% of user actions are auditable covers the act of auditing.

What an inspector general, an ethics committee or a civilian review board can do with the record is set out below, with the release each mechanism shipped in.

Open the Log Only with a Case ID

Reading the audit trail is itself a justified, recorded act. A Case ID is required to open the Logbook page and for every search run on it, and the value entered is stored in the “Search in logbook” entry that the search creates.

Since version 4.40.

See Who Read the Audit Log

The audit log logs the actions taken inside it. Filtering, searching and exporting from the audit-log interface are captured as first-class events, so reviewing the record leaves a record, and the chain of custody covers the reviewer too.

Since version 4.37.

Search the Log by a Complainant’s Photo

On the Persons tab of the Logbook’s additional filters, upload a photo or a descriptor file and set a similarity range. The Logbook returns the entries for actions that used a similar photo or descriptor, which turns a complaint into a query: was this person searched for, and by whom.

Since version 4.39.

See Who Watched Which Video, and for How Long

Entries for live and archived playback record when playback ended, written when it ends or every three hours during a long session. The “Played back video date/time” filter then searches by interval, returning every playback that overlaps the range under review.

Since version 4.38.

Export to CSV and See the Export Logged

The Logbook compiles a CSV report of the entries matching the current search criteria. It stays available to view and download for 24 hours, to the user who requested it, and every download is written back to the Logbook as a “Logbook report downloaded” event.

Since version 4.38.

Receive the Log as JSON on a Schedule the Agency Sets

Automatic export writes user-action records as JSON files into cluster storage, for an external monitoring system to collect. The cluster configuration sets who may read the files, whose actions are included, which event types are exported, how often the export runs, and how long each file is kept.

Since version 4.39.

Keep the Record When the Frames Expire

Event video frames carry their own retention period, separate from the events themselves and never longer. Once frames expire the event card shows the default system image and the event record stays available until event retention ends: data minimization on the agency’s schedule, without losing the entry.

Since version 4.38.

Bias is disclosed, not discovered. All face-recognition systems vary in accuracy across demographic groups, IREX’s included. Where systematic bias exists, IREX policy is to disclose its existence and its estimated impact to the customer, rather than leave an agency to find it in the field. That duty sits alongside continuous bias-reduction work and independent evaluation in the NIST Face Recognition Vendor Test, and it applies whether or not the customer thinks to ask.

Regulatory Alignment

Built for the World's Toughest Standards

The regulatory landscape for AI in law enforcement is evolving fast. IREX is engineered to meet these requirements today, so agencies can deploy with confidence and avoid costly retrofits as regulations take effect.

EU Artificial Intelligence Act

The Act classifies real-time biometric identification in public spaces as high-risk. IREX’s architecture already satisfies its core obligations: built-in risk constraints, customer-owned data governance, human oversight through RBAC, non-erasable transparency logs, and continuous accuracy testing.

NIST AI Risk Management Framework

The Ethical AI framework aligns with the four core functions of the NIST AI RMF (Govern, Map, Measure and Manage), giving U.S. agencies a structured, evidence-based approach to responsible AI deployment.

FBI CJIS Security Policy

Access control, authentication, encryption and audit capabilities designed to support compliance with the Criminal Justice Information Services Security Policy that governs U.S. law-enforcement data.

GDPR and CCPA

The platform is GDPR- and CCPA-ready, and supports all seven GDPR principles: lawfulness, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability. Logging, access control and retention features are what let a customer demonstrate compliance for their own instance, which is validated separately.

AI Model Governance Policy

The Policy behind the Models

Frameworks say what good looks like; a policy says what IREX does. The AI Model Governance Policy states in public, signed by the CEO and the CTO, how IREX trains and tests its own detectors and how it confines the open-weight foundation models behind StreamVLM™ and Ask IREX, both shipping in beta on selected instances. It is written for the procurement officer and the auditor as much as for our engineers, and any customer, partner or contracting authority may have it.

  • Four Permitted Data Sources

    Public open-source datasets, synthetic imagery made by IREX, customer Data Sets provided under a signed agreement, and IREX development cameras that are never installed in public spaces. Customer production video is never training data.

  • A Person Reviews Every Label

    Labels are written by IREX staff or contracted annotators inside IREX’s own labeling platform, and every label a machine proposes is checked by a person before it enters training.

  • Evaluated Before Release, Disclosed After

    Every model is measured on sealed real imagery before release; models that detect or identify people pass a demographic bias assessment; known limitations are disclosed to the customer.

  • Foundation Models Confined

    The open-weight models behind StreamVLM™ and Ask IREX run only inside the instance, unmodified, with no tools beyond their designed function and no access beyond the operator’s own permissions and Case ID.

The Next Frontier

Ethical Agentic AI: Responsible Autonomy

IREX is pioneering autonomous investigation agents that operate within strict ethical boundaries. Natural-language investigations, multi-step search orchestration and automated cross-referencing are governed by the same Transparency by Design principles as every other platform feature. All three are shipping in beta on selected instances. Autonomy and accountability are not in conflict; they are complementary.

Logged and Attributed

Every agent action is attributed to the operator who initiated it and the Case ID that authorizes it.

No Self-Escalation

Agents operate within the same permission boundaries as the human operator, with no ability to escalate their own access.

Fully Auditable

All agent-initiated searches, watchlist queries and alert configurations flow through the same Logbook and signed daily exports as manual operations.

Our Commitment

Hold Us to This Standard

IREX exists to make communities safer without compromising the values that make them worth protecting. Through our partnership with the National Child Protection Task Force, we actively combat human and child trafficking. Those cases are the sharpest test of this framework: the capability that finds a trafficking victim is the same capability that could be misused against an ordinary person. The Case ID mandate, the pre-registration constraint and the audit trail exist so that the first is possible and the second is not.

We invite law enforcement agencies, governments and oversight bodies to hold us to this standard. Our logs are open to audit. Our constraints are verifiable. Our commitment is permanent.

Our ethics program is advised by David K. Bain, former Executive Director of INCITS, the US secretariat for international IT standards under ISO/IEC JTC 1, and founding Executive Director of the Technology Integrity Council.

See the Audit Trail on Your Own Cameras

Tell us about your camera environment and compliance requirements, and we'll walk you through the Logbook, Case ID and the six pillars on your own footage. Not a canned demo.