Security Posture

This page states what IREX holds and what it does not. The formal, counsel-approved policy document is issued on request and the technical detail lives on the platform security page.

Security Policy

What We Hold and What We Do Not

Certification Status, Stated Plainly

IrexAI Inc. operates an information-security management system aligned with ISO/IEC 27001:2022 and ISO/IEC 27002:2022. The scope covers both software platforms and the private cloud that runs them.

  • IrexAI holds no ISO 27001 certification of its own. Certification is a stated objective.
  • IrexAI holds no SOC 2 report.
  • The commercial US SaaS is not FedRAMP authorized and must not be represented as authorized or as holding a formal "FedRAMP Ready" designation.
  • IREX claims no FIPS 140-2 or 140-3 validation.
  • IREX supports all 13 FBI CJIS Security Policy areas. This is an alignment and compliance-support statement, not a third-party certification.

For IREX-managed instances, the physical and environmental security of the hosting layer is inherited from the colocation provider’s own ISO/IEC 27001:2022 certification, which is on file and available under NDA.

Customer Data

Customers retain 100% ownership and control of their data. IREX holds only a limited license to process it in order to provide the products and neither owns nor accesses customer video, events, logs, alarms, watchlists or floor plans. There is no IREX-side data plane for customer media: this is a property of the architecture, not a contractual undertaking.

Hosting and Data Residency

  • Customer-hosted deployments. Data resides entirely on the customer’s own infrastructure in the customer’s chosen jurisdiction. On-premises deployment is the primary data-residency and data-sovereignty mechanism and the customer operates the instance under a documented shared-responsibility matrix.
  • IREX-managed instances. Data is held in the IREX private cloud on bare-metal colocation in Dallas and Plano, Texas, United States. Backups remain within the same managed environment.
  • EU and EEA data subjects are served from a local, in-region instance rather than the US instance. Cross-border transfers from IREX-managed instances rely on Standard Contractual Clauses plus supplementary measures.

A disclosed limitation: the IREX-managed footprint is a single Dallas site with in-cluster redundancy and no secondary site or off-site backup. Total-site loss is a formally accepted risk. Customer-hosted deployments set and operate their own business-continuity posture, with IREX providing guidance and the backup tooling.

Technical Controls

  • Encryption. AES-256-GCM at rest with keys stored separately. TLS 1.2 minimum, with 1.3 in use. Camera streams traverse a mandatory encrypted site-to-site VPN.
  • Access control. Hierarchical role-based access with six roles, multi-factor authentication and a permission-driven interface that scopes cameras, watchlists, alerts and results by role.
  • Logging. Append-only, tamper-evident logging of every high-risk action against a mandatory Case ID, exported daily, with read access designed for supervisors and independent oversight bodies.
  • Vulnerability management. Remediation service levels by CVSS severity, quarterly automated scanning and annual third-party penetration testing with critical findings fixed within 48 hours and verified within a week.
  • Incident response. Breach notification on a defined clock: a preliminary notice at four hours, a detailed notice at one day and a final report at five days.
  • Backup and recovery. AES-256 encrypted backups, monthly restore tests and quarterly recovery-objective validation.
  • Suppliers. Subcontractor and vendor security is governed by a documented vendor security policy.
  • Open stack. The infrastructure is entirely open source and inspectable and IREX-authored components are available for source review or escrow under license.

Regulatory Alignment

The platform is GDPR- and CCPA-ready and aligns with the EU AI Act, the NIST AI Risk Management Framework and the FBI CJIS Security Policy. Ready is not the same as compliant: IREX is user-hosted, so full compliance is established per deployment and each instance is validated separately. Biometric processing is gated on the Case ID mechanism, which is what carries the lawful-basis requirement operationally.

Reporting a Vulnerability

If you believe you have found a security vulnerability in an IREX product or in this website, report it through the contact form with the detail and we will route it to the security team. Please give us a reasonable opportunity to remediate before public disclosure.

Document Status

This page states the security posture and is maintained against the IREX information-security management system. The formal, counsel-approved security policy document, the ISMS certificate pack, the shared-responsibility matrix and the penetration-test summary are issued on request, normally under NDA. Ask through the contact form.

FAQ

Why does this page list what you do not hold?

Because a buyer who discovers a missing certification during evaluation stops believing everything else on the site. Stating it first is cheaper for both of us.

Can we see the ISO certificate and the penetration-test results?

The colocation provider’s ISO/IEC 27001:2022 certificate is on file and available under NDA, along with the shared-responsibility matrix and a penetration-test summary. IrexAI itself holds no certification, so there is none to show.

Do you complete security questionnaires?

Yes. We answer from a documented ISMS with the gaps marked rather than glossed. Send it through the contact form.

Send Your Security Questionnaire

We answer from a documented ISMS and we mark the gaps. That is faster than discovering them at evaluation.