Skip to content
SECURITY FAQ

Straight answers

The questions security and risk teams actually ask, answered the way we'd want them answered — including the ones where the honest answer is "not yet".

What certifications does AIR4T hold?

None yet, and we won't pretend otherwise. We are implementing an integrated information-security and AI-management programme aligned to ISO/IEC 27001:2022 and ISO/IEC 42001:2023, with a dated roadmap published on our Trust page. You will not find the words “aligned” or “compliant” doing the work of a certificate anywhere on this site. Certification may only be claimed after an accredited body has completed its audit and issued the certificate.

Is customer data used to train AI models?

Never. Customer prompts, responses, documents and personal information are never used to train any AI model — ours or anyone else's. External model providers are used via enterprise APIs with training disabled; local models run on sovereign infrastructure only. This is a permanent governance rule (our rule G-18), not a settings default.

Can your AI agents act autonomously?

Not in any way that reaches the outside world or changes governance state. Our agents cannot send emails or external communications, approve or deploy changes, or activate anything without explicit human approval — draft-first, human-approved-second, no exceptions (rules G-19 and G-03). Every agent has a named human owner, a permission boundary, and a documented kill-switch path.

Where is data processed and stored?

Australian region (AWS Sydney, ap-southeast-2) by default, with any egress treated as an exception requiring a documented decision. For material that must never be exposed to foreign legal reach, we run inference locally on sovereign hardware — because storage residency alone does not decide which law can compel disclosure. The full argument is on our Sovereign AI page.

What are the privacy defaults?

Private by default. Recordings, transcripts, summaries and AI analysis in our systems are visible only to their owner; sharing requires the owner's explicit action (rule G-20). Meeting and session material is never used for anything beyond the purpose it was created for.

How do you handle security evidence?

Our systems sign their own work: completed operations produce evidence bundles with a cryptographic hash and keyed signature over the canonical record, verified by re-reading from storage before the operation may report success. Audit records are written to tamper-evident storage (AWS S3 Object Lock in Compliance Mode) where applicable. We show real, redacted bundles under NDA rather than mock-ups.

What about security testing?

An independent penetration test is scheduled for October 2026 (target, not commitment — see the dated roadmap on the Trust page). We will publish the assessor, scope, date, high-level result and remediation status; findings detail is disclosed under NDA only. Internal security checks run daily on our own infrastructure.

How do I report a security issue?

Email anthonyautore@airevolution4technologies.com.au with “Security report” in the subject. A machine-readable contact is published at /.well-known/security.txt. We acknowledge reports and do not pursue good-faith researchers.

How does AIR4T compare with the big compliance platforms?

We don't compete with them on breadth and we don't publish comparison tables. The honest difference is narrow: our work-product is regulator-grade evidence produced by governed agents on sovereign Australian infrastructure, and we practise every control on ourselves first. If breadth of integrations is what you need, a large platform will serve you better — and we'll say so.