Federal, State and Local Government: Compliance Stated First

What a government buyer needs to know first is whether we hold the certifications. Agencies buy differently and are entitled to a straight answer before they are shown a product, so this page starts with the compliance position rather than ending with it.

Stated First

The Compliance Position, without Hedging

The commercial US SaaS is not FedRAMP authorized. It runs in the IREX private cloud on bare-metal colocation in Dallas and Plano, Texas, which is ISO/IEC 27001:2022 certified through the hosting provider but is not a FedRAMP-authorized cloud. Where a program requires FedRAMP, a dedicated instance on an authorized cloud can be scoped and pursued per project.

IrexAI is aligned with ISO/IEC 27001:2022 and 27002:2022 and holds no certification of its own. There is no SOC 2 report for IrexAI, and no FIPS 140-2 or 140-3 validation. Certification is a stated objective. IREX supports all 13 CJIS policy areas, and that is an alignment and compliance-support claim, not a third-party certification.

For sovereign and federal work the answer to most residency questions is the deployment model: on-premises or fully air-gapped, on infrastructure the agency owns, with data residency, key custody and egress constraints defined during discovery and design.

Where It Applies

Federal, State, and Local

Federal Facilities

Unify legacy sensors and systems into automated workflows and alerts, with verification and escalation of incidents on the existing estate rather than a replacement program.

See Real-Time Alerts & Evidence

State and Local Law Enforcement

Watchlists, weapons, vehicles and investigations, integrated with local law-enforcement databases. In production across Southern California.

See Law Enforcement

Border Security

Face and vehicle recognition across ports of entry and approaches, with interagency collaboration and full audit logs.

See Borders & Customs

Bases and Critical Sites

Perimeter intrusion, restricted zones, fire and smoke, and access control on sites that cannot depend on an internet link.

See Critical Infrastructure

On Camera

Perimeter, on a Site with No Link

The Fence Line After Dark

Perimeter intrusion on approaches with no fiber, no reliable uplink and no tolerance for going dark. The analytics run on an edge server at the site, so detection continues when the link drops and the events synchronize when it returns — the pattern a base, a remote facility and a port of entry all need. What reaches the operator is an event with its frame attached, and a non-erasable record of who looked at it and why.

Deployment Models
Seen from a high mast, a figure in dark clothing stands against a tall steel border fence on a floodlit patrol road that curves away into the desert at night.
Fence line crossing · Nogales · 21:52:16

Procurement

How the Paperwork Can Run

  • Sole source, where your rules allow it: typically two to four times faster than an open tender. We supply the justification material and technical specifications.
  • Open tender or RFP, the most common route. Send us the solicitation and we will say inside a working week whether we can meet it, and where a requirement is written around another vendor.
  • Framework call-off, where a vehicle available to you covers the scope.
  • Public-private partnership, including BOT and BOOT structures for capital-heavy deployments.

Facts

Legal Entity
IrexAI Inc., a Delaware C-Corporation incorporated 21 November 2019, doing business as IREX.
SAM Unique Entity ID
FSS2RHTRJ2W5
CAGE / NCAGE
97LJ6

FAQ

Is IREX FedRAMP authorized?

No. The commercial US SaaS runs on ISO 27001-certified colocation that is not a FedRAMP-authorized cloud, so it holds no FedRAMP authorization and must not be represented as holding one. A dedicated instance on a FedRAMP-authorized cloud can be scoped and pursued per project where a program requires it.

Are you ISO 27001 certified or SOC 2 audited?

Neither, as IrexAI. The ISMS is aligned with ISO/IEC 27001:2022 and 27002:2022 and certification is a stated objective. For IREX-managed instances the colocation layer carries the hosting provider’s own ISO/IEC 27001:2022 certificate, which is on file.

Is IREX CJIS compliant?

IREX supports all 13 CJIS policy areas, with encryption, role-based access and daily signed audit exports built in. That is an alignment and compliance-support claim rather than a certification, and we state it that way deliberately.

Which identifiers do you need for our vendor registration?

Legal name IrexAI Inc., a Delaware C-Corporation incorporated 21 November 2019; SAM Unique Entity ID FSS2RHTRJ2W5; CAGE and NCAGE 97LJ6; DUNS 118281522. NAICS codes are confirmed against our current SAM registration at submission time rather than published here, and tax and insurance documents come on request.

Can it run air-gapped on a secure site?

Yes. Fully air-gapped installation is supported through an auxiliary provisioning server, with no runtime internet dependency, and the whole infrastructure stack is open source and inspectable.

Send Us the Solicitation

We will tell you quickly whether we can meet it, including where we cannot. That is faster for both sides than a discovery call.