Compliance & Security
We build for Australian data sovereignty, evidentiary integrity and intellectual property protection. Admissibility is determined by a court, never by a vendor — our role is to preserve the chain of custody that makes the question answerable.
Legal Privilege
Our network-isolated architectures are designed so that sensitive corporate data and discovery material never leaves your perimeter. Whether privilege attaches is a question of law; our contribution is to remove the disclosure paths that would put it at risk.
WORM Compliance
Intent logs and system telemetry are written under Write-Once-Read-Many protection via AWS S3 Object Lock in Compliance Mode — once written, no user can delete or alter a record before its retention period expires, including the account root.
Australian Hosted
All data processing, model inference, and storage default exclusively to the AWS `ap-southeast-2` region.
The Australian regulatory clock
Last verified 10 Aug 2026Australia has chosen regulator-led AI governance over an AI Act. That means the obligations arrive as supervisory expectations and existing-law deadlines — and several are already live. Dates below reflect the regulators' own publications; where an item rests on secondary reporting we say so.
None of this requires a new statute to bind. It requires evidence: inventories, reporting lines, human gates and records that survive scrutiny. Producing that evidence is the discipline we practise on our own systems first. For the full translation of APRA's expectations into producible artefacts, read the APRA AI letter, translated.
Compliance across jurisdictions
Last verified 25 Aug 2026Australia is our primary jurisdiction — where we are incorporated and where your data stays. The frameworks of other regions apply when we serve customers or process data there; we hold those as alignment and forward-looking best practice, never as certifications. We hold no external certification in any jurisdiction, and say so plainly.
Alignment means our controls are mapped internally to each framework; it is not certification. Where a framework becomes a live obligation for your engagement, we scope it explicitly and evidence it under NDA.
Certifications — where we actually stand
AIR4T currently holds no external management-system certification. We are implementing an integrated information-security and AI-management programme aligned to ISO/IEC 27001:2022 and ISO/IEC 42001:2023. Certification may only be claimed after an accredited independent certification body has completed its audit and issued the applicable certificate. Scoped assurance material is available under NDA.
We state this plainly because our work is telling organisations that a control they cannot evidence is a control they do not have. That standard has to apply to us first.
What we offer instead, today
- —Controls you can inspect. Our governance rules are executable code with tests, not policy documents. We will walk you through them line by line under NDA.
- —Evidence you can reconstruct. Every material claim our systems make carries the measurement behind it, the population it was measured over, and when it expires.
- —Boundaries enforced in routing. Privileged and classified material is refused at the boundary rather than handled carefully — a refusal path, not a guideline.
- —Australian residency by default. Processing, inference and storage default to ap-southeast-2, with egress treated as an exception requiring a documented decision.
Where we are heading, with dates
We publish the plan rather than the aspiration. Dates are targets, not commitments — they depend on certification-body availability and on the evidence being genuinely ready. Nothing below may be presented as held until an accredited body has completed its audit and issued the certificate.
Our standing rule
Admissibility, privilege and accuracy are determined by courts, by law and by measurement. We do not assert them as properties of a product — we build the evidence that lets someone else decide.