Enterprise trust

Security for the
data behind the deal.

AERRIS is built for confidential legal and transaction information. Customer segregation, controlled access, encryption, responsible AI data handling and transparent data-use rules are designed into how the platform operates — from document ingestion to source-linked output.

  • Application layer

    Source-linked outputs with human control

  • Data & logic layer

    Access controls, AI orchestration, governance

  • Data layer

    Encrypted data stores and key management

  • Infrastructure layer

    Isolated environments and secure operations

Platform architecture model

Trust at a glance

  • Separate client environments

    Your data is isolated in logically separate environments with no co-mingling between customers.

  • Encryption in transit and at rest

    All data is protected with industry-standard encryption in transit and at rest, with managed keys.

  • Granular access controls

    Role-based permissions, least privilege by default, and just-in-time access where appropriate.

  • Source-linked auditability

    Comprehensive audit logs and source-linked outputs provide transparency and traceability.

  • Australian data residency available

    Store your data in Australia with region-specific controls and residency options.

  • SOC 2 and ISO/IEC 27001

    AERRIS has commenced its SOC 2 and ISO/IEC 27001 compliance programs with Vanta and is implementing the required controls and processes as we work towards SOC 2 attestation and ISO/IEC 27001 certification.

Certifications are not complete. Readiness reflects our ongoing program of work.

Protection through the transaction lifecycle

  1. 01

    Ingest

    Authenticated intake of documents and data into AERRIS.

  2. 02

    Segregate

    Data is placed in a separate, single-tenant environment.

  3. 03

    Analyse

    Orchestrated analysis and processing of data within permissions using controlled models and guardrails.

  4. 04

    Review

    Outputs are traceable and source-linked with human oversight.

  5. 05

    Retain or delete

    Data is returned or deleted under the agreed lifecycle and obligations.

AI does not bypass your access controls.

AERRIS enforces graph-based and semantic access controls across every layer.

  • Least privilege by design (users, systems and applications receive only the minimum access needed to perform their function — and no more)
  • No data leakage across matters or clients
  • Named users only — always

Governed by permissions at every layer

From AI output
to source material

Every output is traceable to the exact source, so you can verify with confidence.

  1. 01

    Finding

    AI-identified insight

  2. 02

    Source document

    Original document in repository

  3. 03

    Clause

    Specific clause or section

  4. 04

    Review status

    Under review, approved, or needs follow-up

  5. 05

    Reviewer

    Named reviewer with timestamp

Built on trust.
Backed by security.

AERRIS is designed for confidential legal, transaction and professional information. Security, privacy and responsible AI controls are embedded across the platform.

Pillar 01

Security

Industry-leading controls protect your data, your way.

  • Single-tenant environments
  • Encryption in transit and at rest
  • Granular access control
  • Incident response and recovery

Pillar 02

Data Use

Your data is your data. We use it only to serve you better.

  • Customer-specific learning stays customer-specific
  • De-identified data for structural improvement
  • Customer choice and controls
  • We do not sell your data

Pillar 03

Responsible AI

AI that supports professionals—built with guardrails.

  • Source traceability and citations
  • Human review and control
  • No autonomous legal decision-making
  • Issue escalation when appropriate

Separate by design

Every client operates in a logically and operationally separate environment. Your data, configurations and AI learning are isolated—by design.

Single-tenant environments
Your data lives in your environment.
Optional client-specific VPC / VPN
Additional isolation to meet your requirements.

Client A

Environment

  • Applications
  • Data & AI
  • Infrastructure

Client B

Environment

  • Applications
  • Data & AI
  • Infrastructure

Client C

Environment

  • Applications
  • Data & AI
  • Infrastructure

Additional client environments follow the same pattern.

Network isolation · Access controls · Encryption · Monitoring

Your data. Your choices.

01

Operate and secure the platform

We use your data to operate, secure and improve the core functionality of the AERRIS platform for your organisation.

02

Learn privately for your organisation

You can allow AERRIS to use your data privately to improve models and experiences for your organisation only.

03

Improve AERRIS from de-identified structural signals

We may use de-identified, aggregated structural signals to improve AERRIS for all customers — never your content or confidential information.

What AERRIS does not do

  • No sale of personal information
  • No advertising use of Customer Content
  • No cross-customer sharing of confidential content
  • No shared-model or third-party AI provider training on Customer Content

Confidentiality is not an afterthought.

We understand the obligations of legal and professional work—and we build for them.

  • Legal professional privilege awareness

    Designed to support the protection of privileged information.

  • Confidentiality obligations

    Built to help you meet your duties of confidentiality and care.

  • Continuing confidentiality after engagement

    Your data remains protected even after a matter or transaction ends.

  • Suitable for commercially sensitive materials

    Built for the highest standards of business confidentiality.

Human control by design

AI assists; your team decides. Review, validate and finalise with confidence.

Responsible AI at AERRIS

  • Source-grounded

    All outputs are grounded in your documents and linked to verifiable sources.

  • Human-reviewed

    AI augments experts. Humans make the calls that matter.

  • Permission-aware

    AI respects your access controls and data boundaries.

  • Purpose-limited

    Used only for agreed purposes within the transaction lifecycle.

  • Escalatable

    Controls and guardrails scale with complexity and risk.

Data lifecycle

  1. 01

    Minimise

    Collect only what is necessary.

  2. 02

    Use for agreed purpose

    Use data only for the transaction and objectives we agree.

  3. 03

    Retain only as required

    Retain for the minimum period required by law or agreement.

  4. 04

    Return or delete

    Return data to you or delete upon completion or request.

  5. 05

    Secure disposal

    When deletion applies, data is securely and irrevocably destroyed.

Security controls today.
Independent assurance next.

Controls operating today

  • Separate client environments (single-tenant by default)
  • AES-256-GCM application-level encryption (at rest)
  • Encryption in transit
  • Named users
  • Granular role-based permissions
  • Logging and audit trails
  • Configurable retention and secure deletion
  • Incident-response processes
  • Source-linked auditability
  • Human review and control

Assurance roadmap

  • SOC 2 readinessIn Progress
  • ISO/IEC 27001 readinessIn Progress
  • Independent security testingPlanned
  • Security governance and
    risk management procedures
    Available

Certification and assurance claims will only be published once the applicable assessment has been completed and the relevant report or certificate has been issued.

Roadmap items are subject to change. We share updates as milestones are achieved.

Trust resources

Explore our policies, practices and answers.

Security Policy

Our security principles and controls are summarised on this page — customer segregation, encryption in transit and at rest, granular role-based access, logging and audit trails, configurable retention and secure deletion, and incident-response processes. The full Security Policy document is provided as part of an enterprise security review.

Request the full policy

Frequently asked questions

  • No. As part of our standard Services, AERRIS does not use Customer Content to train or improve shared AI models for other customers or the public. We also do not permit our third-party AI providers to use Customer Content to train or improve their public or shared models.

    Customer Content may be used to provide, configure and improve AERRIS for that customer, including through customer-specific configurations, corrections, thresholds, playbooks and institutional learning.

    AERRIS may use de-identified, non-content usage and structural signals to improve the platform generally. This does not include underlying contract or clause text, customer-specific financial information, legal advice, conclusions or other Customer Content.

    Customer Content and customer-specific intelligence remain segregated from other customers.

Doing a security or AI-governance review of AERRIS?

Questions about security,
privacy or AI governance?

Our team is here to help. Request security information or speak with a member of our team.