Enterprise trust
Security for the
data behind the deal.
AERRIS is built for confidential legal and transaction information. Customer segregation, controlled access, encryption, responsible AI data handling and transparent data-use rules are designed into how the platform operates — from document ingestion to source-linked output.
Platform architecture model
Trust at a glance
Separate client environments
Your data is isolated in logically separate environments with no co-mingling between customers.
Encryption in transit and at rest
All data is protected with industry-standard encryption in transit and at rest, with managed keys.
Granular access controls
Role-based permissions, least privilege by default, and just-in-time access where appropriate.
Source-linked auditability
Comprehensive audit logs and source-linked outputs provide transparency and traceability.
Australian data residency available
Store your data in Australia with region-specific controls and residency options.
SOC 2 and ISO/IEC 27001
AERRIS has commenced its SOC 2 and ISO/IEC 27001 compliance programs with Vanta and is implementing the required controls and processes as we work towards SOC 2 attestation and ISO/IEC 27001 certification.
Certifications are not complete. Readiness reflects our ongoing program of work.
Protection through the transaction lifecycle
01
Ingest
Authenticated intake of documents and data into AERRIS.
02
Segregate
Data is placed in a separate, single-tenant environment.
03
Analyse
Orchestrated analysis and processing of data within permissions using controlled models and guardrails.
04
Review
Outputs are traceable and source-linked with human oversight.
05
Retain or delete
Data is returned or deleted under the agreed lifecycle and obligations.
AI does not bypass your access controls.
AERRIS enforces graph-based and semantic access controls across every layer.
- Least privilege by design (users, systems and applications receive only the minimum access needed to perform their function — and no more)
- No data leakage across matters or clients
- Named users only — always
Governed by permissions at every layer
From AI output
to source material
Every output is traceable to the exact source, so you can verify with confidence.
01
Finding
AI-identified insight
02
Source document
Original document in repository
03
Clause
Specific clause or section
04
Review status
Under review, approved, or needs follow-up
05
Reviewer
Named reviewer with timestamp
Built on trust.
Backed by security.
AERRIS is designed for confidential legal, transaction and professional information. Security, privacy and responsible AI controls are embedded across the platform.
Pillar 01
Security
Industry-leading controls protect your data, your way.
- Single-tenant environments
- Encryption in transit and at rest
- Granular access control
- Incident response and recovery
Pillar 02
Data Use
Your data is your data. We use it only to serve you better.
- Customer-specific learning stays customer-specific
- De-identified data for structural improvement
- Customer choice and controls
- We do not sell your data
Pillar 03
Responsible AI
AI that supports professionals—built with guardrails.
- Source traceability and citations
- Human review and control
- No autonomous legal decision-making
- Issue escalation when appropriate
Separate by design
Every client operates in a logically and operationally separate environment. Your data, configurations and AI learning are isolated—by design.
- Single-tenant environments
- Your data lives in your environment.
- Optional client-specific VPC / VPN
- Additional isolation to meet your requirements.
Client A
Environment
- Applications
- Data & AI
- Infrastructure
Client B
Environment
- Applications
- Data & AI
- Infrastructure
Client C
Environment
- Applications
- Data & AI
- Infrastructure
Additional client environments follow the same pattern.
Network isolation · Access controls · Encryption · Monitoring
Your data. Your choices.
01
Operate and secure the platform
We use your data to operate, secure and improve the core functionality of the AERRIS platform for your organisation.
02
Learn privately for your organisation
You can allow AERRIS to use your data privately to improve models and experiences for your organisation only.
03
Improve AERRIS from de-identified structural signals
We may use de-identified, aggregated structural signals to improve AERRIS for all customers — never your content or confidential information.
What AERRIS does not do
- No sale of personal information
- No advertising use of Customer Content
- No cross-customer sharing of confidential content
- No shared-model or third-party AI provider training on Customer Content
Confidentiality is not an afterthought.
We understand the obligations of legal and professional work—and we build for them.
Legal professional privilege awareness
Designed to support the protection of privileged information.
Confidentiality obligations
Built to help you meet your duties of confidentiality and care.
Continuing confidentiality after engagement
Your data remains protected even after a matter or transaction ends.
Suitable for commercially sensitive materials
Built for the highest standards of business confidentiality.
Human control by design
AI assists; your team decides. Review, validate and finalise with confidence.
Responsible AI at AERRIS
Source-grounded
All outputs are grounded in your documents and linked to verifiable sources.
Human-reviewed
AI augments experts. Humans make the calls that matter.
Permission-aware
AI respects your access controls and data boundaries.
Purpose-limited
Used only for agreed purposes within the transaction lifecycle.
Escalatable
Controls and guardrails scale with complexity and risk.
Data lifecycle
01
Minimise
Collect only what is necessary.
02
Use for agreed purpose
Use data only for the transaction and objectives we agree.
03
Retain only as required
Retain for the minimum period required by law or agreement.
04
Return or delete
Return data to you or delete upon completion or request.
05
Secure disposal
When deletion applies, data is securely and irrevocably destroyed.
Security controls today.
Independent assurance next.
Controls operating today
- Separate client environments (single-tenant by default)
- AES-256-GCM application-level encryption (at rest)
- Encryption in transit
- Named users
- Granular role-based permissions
- Logging and audit trails
- Configurable retention and secure deletion
- Incident-response processes
- Source-linked auditability
- Human review and control
Assurance roadmap
- SOC 2 readinessIn Progress
- ISO/IEC 27001 readinessIn Progress
- Independent security testingPlanned
- Security governance and
risk management proceduresAvailable
Certification and assurance claims will only be published once the applicable assessment has been completed and the relevant report or certificate has been issued.
Roadmap items are subject to change. We share updates as milestones are achieved.
Trust resources
Explore our policies, practices and answers.
Security Policy
Our security principles and controls.
Privacy Policy & Data Use Terms
How we collect, use and protect personal data, and how customer data is used within AERRIS.
FAQ
Answers to common security questions.
Security Policy
Our security principles and controls are summarised on this page — customer segregation, encryption in transit and at rest, granular role-based access, logging and audit trails, configurable retention and secure deletion, and incident-response processes. The full Security Policy document is provided as part of an enterprise security review.
Request the full policyFrequently asked questions
No. As part of our standard Services, AERRIS does not use Customer Content to train or improve shared AI models for other customers or the public. We also do not permit our third-party AI providers to use Customer Content to train or improve their public or shared models.
Customer Content may be used to provide, configure and improve AERRIS for that customer, including through customer-specific configurations, corrections, thresholds, playbooks and institutional learning.
AERRIS may use de-identified, non-content usage and structural signals to improve the platform generally. This does not include underlying contract or clause text, customer-specific financial information, legal advice, conclusions or other Customer Content.
Customer Content and customer-specific intelligence remain segregated from other customers.
No. Customer Content and Customer-Specific Intelligence are segregated from other customer environments and are not made available to another customer merely because both organisations use AERRIS.
Access is limited to authorised customer users and, where required to provide, support or secure the Services, appropriately authorised AERRIS personnel and service providers subject to applicable confidentiality, privacy and security controls.
AERRIS applies technical and organisational measures including access controls, customer segregation, encryption, logging and monitoring, backup and recovery measures and incident-response processes.
Retention, return and deletion of Customer Content are governed by the applicable customer agreement, customer instructions and legal requirements.
Limited information may remain temporarily in protected backup systems until it is overwritten or deleted through the applicable backup cycle.
AERRIS is designed for confidential legal and professional information and applies security and access controls designed to protect Customer Content.
Whether legal professional privilege applies or is preserved depends on the relevant circumstances, the customer's use of the platform and applicable law.
AERRIS is progressing its SOC 2 and ISO 27001 readiness programme.
Formal certification or independent-assurance claims will be published once the relevant assessment has been completed and the applicable report or certificate has been issued.
Client data is hosted in secure cloud infrastructure. For Australian clients, AERRIS can support Australian data residency, subject to the agreed deployment model and hosting configuration.
Doing a security or AI-governance review of AERRIS?
Questions about security,
privacy or AI governance?
Our team is here to help. Request security information or speak with a member of our team.
- Platform architecture
- Hosting and deployment model
- Data residency
- Encryption and access controls
- AI model and provider arrangements
- Retention and deletion
- Logging and auditability
- Human oversight and responsible-AI controls
- Incident response
- Subprocessors
- Change management
- Security and certification roadmap