Skip to content
AIR4T TRUST CENTER

Compliance & Security

We build for Australian data sovereignty, evidentiary integrity and intellectual property protection. Admissibility is determined by a court, never by a vendor — our role is to preserve the chain of custody that makes the question answerable​‌​​​​‌​.

Legal Privilege

Our network-isolated architectures are designed so that sensitive corporate data and discovery material never leaves your perimeter. Whether privilege attaches is a question of law; our contribution is to remove the disclosure paths that would put it at risk.

WORM Compliance

Intent logs and system telemetry are written under Write-Once-Read-Many protection via AWS S3 Object Lock in Compliance Mode — once written, no user can delete or alter a record before its retention period expires, including the account root.

Australian Hosted

All data processing, model inference, and storage default exclusively to the AWS `ap-southeast-2` region.

The Australian regulatory clock

Last verified 10 Aug 2026

Australia has chosen regulator-led AI governance over an AI Act. That means the obligations arrive as supervisory expectations and existing-law deadlines — and several are already live. Dates below reflect the regulators' own publications; where an item rests on secondary reporting we say so.

Apr 2026APRA letter to industry — every bank, insurer and super trustee is expected to show board AI literacy, a formal governance framework, lifecycle ownership from design to decommissioning, an inventory of all AI tooling and use cases, and human accountability for high-risk decisions.
May 2026ASIC wrote to licensees urging urgent strengthening of cyber resilience as frontier AI intensifies cyber risk.
2026Commonwealth agencies move under mandatory AI requirements — impact assessments, accountable-official appointments and training — phasing in across the year.
Jul 2026Office of AI established within the Department of the Prime Minister and Cabinet, with announced intent to legislate the Australian Standards for AI — legislation expected in early 2027.
Dec 2026Privacy Act ADM disclosure deadline — entities using automated decision-making that significantly affects individuals must disclose it in their privacy policies by 10 December 2026.

None of this requires a new statute to bind. It requires evidence: inventories, reporting lines, human gates and records that survive scrutiny. Producing that evidence is the discipline we practise on our own systems first. For the full translation of APRA's expectations into producible artefacts, read the APRA AI letter, translated.

Compliance across jurisdictions

Last verified 25 Aug 2026

Australia is our primary jurisdiction — where we are incorporated and where your data stays. The frameworks of other regions apply when we serve customers or process data there; we hold those as alignment and forward-looking best practice, never as certifications. We hold no external certification in any jurisdiction, and say so plainly.

AustraliaPrimary — live obligations. Privacy Act 1988 + Australian Privacy Principles, OAIC notifiable-data-breach scheme, Corporations Act / ASIC. Aligned to the ACSC Essential Eight, the Information Security Manual and the Australian Voluntary AI Safety Standard guardrails.
United StatesApplies when serving US customers. Aligned to the SOC 2 Trust Services Criteria (internal readiness, external Type II targeted 2027) and the NIST Cybersecurity, 800-53 and AI Risk Management frameworks.
EuropeAdopted as forward-looking best practice for EU engagements — the EU AI Act (risk-tiering, transparency, logging, human oversight) and the GDPR.
United KingdomApplies for UK data subjects — UK GDPR and the Data Protection Act 2018, with ICO AI-and-data-protection guidance tracked as it evolves.
InternationalJurisdiction-neutral standards we align to — the ISO/IEC 27001 information-security family and the ISO/IEC 42001 AI-management family, and the OWASP Top 10 for LLM applications. ISO/IEC 42001 is our AI north-star certification.

Alignment means our controls are mapped internally to each framework; it is not certification. Where a framework becomes a live obligation for your engagement, we scope it explicitly and evidence it under NDA.

Certifications — where we actually stand

AIR4T currently holds no external management-system certification. We are implementing an integrated information-security and AI-management programme aligned to ISO/IEC 27001:2022 and ISO/IEC 42001:2023. Certification may only be claimed after an accredited independent certification body has completed its audit and issued the applicable certificate. Scoped assurance material is available under NDA.

We state this plainly because our work is telling organisations that a control they cannot evidence is a control they do not have. That standard has to apply to us first.

What we offer instead, today

  • Controls you can inspect. Our governance rules are executable code with tests, not policy documents. We will walk you through them line by line under NDA.
  • Evidence you can reconstruct. Every material claim our systems make carries the measurement behind it, the population it was measured over, and when it expires.
  • Boundaries enforced in routing. Privileged and classified material is refused at the boundary rather than handled carefully — a refusal path, not a guideline.
  • Australian residency by default. Processing, inference and storage default to ap-southeast-2, with egress treated as an exception requiring a documented decision.

Where we are heading, with dates

We publish the plan rather than the aspiration. Dates are targets, not commitments — they depend on certification-body availability and on the evidence being genuinely ready. Nothing below may be presented as held until an accredited body has completed its audit and issued the certificate.

Sep 2026Professional indemnity and cyber liability cover bound; information-security and responsible-AI policy summaries published; Essential Eight self-assessment published with its date, scope and maturity level. Full control documentation, including the Statement of Applicability, is available under NDA rather than publicly.
Oct 2026Independent penetration test. We publish the assessor, scope, date, high-level result and remediation status only — findings and remediation detail are disclosed under NDA, never openly.
Nov 2026First internal audit and management review — the point at which the management system has demonstrably operated rather than merely been written.
Apr 2027ISO/IEC 27001 target — audited by an independent certification body whose accreditation we verify in the live accreditation register, on a scope stated in full on the certificate.
Jul 2027ISO/IEC 42001 — the AI management system standard — integrated into the same programme. This is the one that matters for what we do.

Our standing rule

Admissibility, privilege and accuracy are determined by courts, by law and by measurement. We do not assert them as properties of a product — we build the evidence that lets someone else decide.