What We Can Prove, and What We Cannot

Security pages usually list every acronym a vendor can spell. This one separates what IREX holds from what it is aligned with, because a procurement officer who discovers the difference later stops believing the rest of the page.

Stated Plainly

Aligned, Not Certified

IrexAI operates an information-security management system aligned with ISO/IEC 27001:2022 and 27002:2022. It holds no ISO certification and no SOC 2 report of its own; certification is a stated objective. The scope covers both software platforms and the private cloud that runs them.

For IREX-managed instances, the physical and environmental security of the hosting layer is inherited from the colocation provider’s own ISO/IEC 27001:2022 certification, which is on file. The commercial US SaaS is not FedRAMP authorized: it runs on bare-metal colocation in Dallas and Plano, Texas, which is ISO 27001 certified but is not a FedRAMP-authorized cloud. Where a program requires FedRAMP, a dedicated instance on an authorized cloud can be scoped and pursued per project.

For customer-hosted deployments, on-premises deployment is the data-residency mechanism: data resides entirely on your own infrastructure in your own jurisdiction, and you operate the instance under a documented shared-responsibility matrix.

Controls

What Is in Place

Encryption

AES-256-GCM at rest with keys stored separately; TLS 1.2 minimum with 1.3 in use; camera streams over a mandatory encrypted site-to-site VPN.

Access Control

Hierarchical role-based access with six roles, multi-factor authentication, and a permission-driven interface that scopes cameras, watchlists, and results by role.

Audit and Oversight

Append-only, tamper-evident logging of every high-risk action against a mandatory Case ID, exported daily, readable by supervisors and independent oversight bodies.

Vulnerability Management

Remediation service levels by severity, quarterly automated scanning, and annual third-party penetration testing with critical findings fixed within 48 hours and verified inside a week.

Incident Response

Breach notification on a defined clock: a preliminary notice at four hours, a detailed one at one day, and a final report at five days.

Backup and Recovery

AES-256 encrypted backups with monthly restore tests and quarterly recovery-objective validation.

AI Model Governance

A public policy signed by the CEO and the CTO covers the in-house detector models and the open-weight foundation models behind StreamVLM™ and Ask IREX (beta, selected instances): four permitted training-data sources, human-reviewed labels, evaluation and bias testing before release, artifact integrity, and foundation models pinned and confined inside the instance. Aligned with ISO/IEC 42001:2023 and NIST AI RMF 1.0, not certified.

Read the AI Model Governance Policy

Regulatory

Frameworks the Platform Is Designed to Support

  • GDPR- and CCPA-ready, with the Case ID gate enforcing a lawful basis for biometric processing. Because IREX is user-hosted, each instance is validated separately before compliance is asserted for it.
  • Alignment with the EU AI Act and the NIST AI Risk Management Framework.
  • Support for all 13 FBI CJIS Security Policy areas. These are alignment and compliance-support claims, not third-party certifications.
  • EU and EEA data subjects are served from a local, in-region instance rather than the US instance, with transfers under Standard Contractual Clauses plus supplementary measures.
  • Customers retain 100% ownership and control of their data; IREX holds only a limited license to process it in order to provide the products.
  • Vendor and subcontractor security is governed by a documented vendor security policy.

Facts

What IREX Does Not Claim
Not ISO 27001 certified, and not ISO/IEC 42001 certified either: the AI Model Governance Policy states alignment, not certification. No SOC 2 report. The commercial US SaaS is not FedRAMP authorized. No FIPS 140-2 or 140-3 validation. We would rather you read that here than find it in a bid.
A Disclosed Limitation
The IREX-managed footprint is a single Dallas site with in-cluster redundancy and no secondary site or off-site backup. That is a formally accepted risk, and it is disclosed rather than glossed. Customer-hosted deployments set their own continuity posture.
NDAA Section 889
IREX uses no equipment or services covered by Section 889 (Huawei, ZTE, Hytera, Hikvision, Dahua and their affiliates) in the platform or its hosting, and supplies no cameras, servers or network equipment: the end user owns and procures them, so the Section 889 status of the camera estate is the buyer’s own procurement record.

FAQ

Are you ISO 27001 certified?

No. IrexAI operates an ISMS aligned with ISO/IEC 27001:2022 and 27002:2022 and holds no certification of its own; certification is a stated objective. For IREX-managed instances, the colocation layer is ISO/IEC 27001:2022 certified through the hosting provider, and that certificate is on file.

How are the AI models themselves governed?

By a public policy rather than a promise. The AI Model Governance Policy (DOC-ISMS-POL-014) covers the two classes of model in the platform. In-house detectors are trained only on four permitted data sources, labeled or label-reviewed by people, evaluated on sealed real-imagery test sets against thresholds set before the test, and, where they detect or identify people, assessed for demographic bias across gender, age group and skin tone before release, with known limitations disclosed to customers. The foundation models behind StreamVLM™ and Ask IREX (beta, selected instances) are open-weight models used as published, pinned by version and checksum, served on designated endpoints inside your instance with no outbound network access and no third-party cloud inference, and they inherit the calling operator’s permissions and Case ID on every request. Model identities are disclosed under NDA rather than published, because a named model is an attack surface. The policy is aligned with ISO/IEC 42001:2023 and NIST AI RMF 1.0 and may be supplied to any contracting authority: read it or download the PDF from the Ethical AI page.

Is the platform NDAA Section 889 compliant?

Yes. IREX is software and uses no equipment or services covered by NDAA Section 889, meaning nothing from Huawei, ZTE, Hytera, Hikvision, Dahua or their affiliates, in the platform or in its hosting. IREX also does not supply the cameras, servers or network equipment in a deployment: the end user typically owns and procures them, so the Section 889 status of the camera estate rests with the buyer’s own procurement, and the site survey confirms the fleet before a statement of work is signed. Where a bid asks IREX to propose hardware, it proposes only Section 889-compliant models and never the covered brands, with final models confirmed after the site survey.

Do you have a SOC 2 report?

IrexAI does not. A SOC 2 Type II report exists for the Dallas data-center layer covering a stated historical period, but it has lapsed and we describe it only by that period, never as current.

Is the platform FedRAMP authorized?

The commercial US SaaS is not. It runs on ISO 27001-certified bare-metal colocation that is not a FedRAMP-authorized cloud. Where a program requires FedRAMP, a dedicated instance on an authorized cloud can be scoped and pursued for that project.

Where does our data live?

For customer-hosted deployments, entirely on your own infrastructure in your own jurisdiction: on-premises deployment is the data-residency and data-sovereignty mechanism. For IREX-managed instances, on the IREX private cloud on colocation in Dallas and Plano, Texas, with backups inside the same managed environment. EU and EEA data subjects are served from an in-region instance instead.

What happens to our data if we leave?

You own and retain all right, title, and interest in your data throughout; IREX holds only a limited license to process it in order to provide the products. Termination for uncured breach, insolvency, or a sustained availability failure carries a pro-rata refund of prepaid fees.

Send Us the Security Questionnaire

We answer from a documented ISMS with the gaps marked, which is faster for both sides than discovering them at evaluation.