Security, Governance and Export Control
Written for your CISO, security officer, export-control team and customer auditors: exactly what stays inside your boundary, who can reach it, and how each control maps to the frameworks you work under.
What Leaves Your Account
Never Leaves
- Technical and Export-Controlled DataDrawings, specifications, test data and controlled technical data, including prompts and outputs about them.
- Maintenance and Programme DataWork orders, component histories, contracts, bids and pricing.
- Inspection ImageryBorescope, NDT and camera footage, processed only at your site edge or in your cloud.
- Logs and EvaluationsRequest logs, sources, approvals and expert ratings.
May Leave, Under Your Control
- Operational Health MetricsCPU, GPU and service health so we can operate the platform. You can inspect or switch them off; none in air-gapped deployments.
- Public-Only Managed AI TasksOnly tasks the policy check classes as public, for task types you allow, under a monthly cap. Off by default in air-gapped deployments.
Who Can Reach What
Controls built into the platform, configured by your teams.
Policy Check First
Every request is checked before any model sees it. Controlled data, or anything the check is unsure about, stays private.
Access by Role, Programme and Licence
Attributes from your identity provider decide which workspaces and documents each user can reach.
Audit Trail per Workspace
Every request, source, route and approval is logged in your infrastructure and exportable per customer.
Human Oversight
Read-only connectors. Nothing is released, certified, classified, filed or sent automatically.
Frameworks and How Controls Map to Them
How the platform is designed to support the rules defence and aerospace organisations work under.
| Framework | What it expects | How Aegironix is designed to support it |
|---|---|---|
| ITAR, EAR and EU Dual-Use Regulation (EU) 2021/821 | Controlled technical data is not exported or released to unauthorised persons. | Controlled data processed only on private models in infrastructure you choose; access limited by programme, role, nationality and licence; managed AI never receives it; every access logged. |
| NIST SP 800-171, DFARS 252.204-7012 and CMMC | Controlled unclassified information is protected by defined security requirements. | Runs inside your accredited boundary, with role-based access, encryption, audit logging and documentation to map controls in your system security plan. |
| NIS2 Directive | Essential and important entities manage cybersecurity risk, including suppliers. | Security documentation, logging and incident-support processes that fit your supplier risk management and reporting duties. |
| GDPR | Personal data is processed lawfully, minimally and securely. | Processing inside your infrastructure, no facial recognition in inspection vision, face blurring at source and documentation for your DPIA. |
| EU AI Act | Obligations for AI systems placed on the EU market; military-only use is out of scope. | Human oversight on every output, logging, transparency on routes and models, and documentation for civil and dual-use applications. |
| AS9100 and EN 9100 | Quality management for aviation, space and defence organisations. | Versioned knowledge, evaluated releases with rollback and records that support your document and change control. |
| EASA Part 21 and Part 145 | Design, production and maintenance organisations follow approved data and procedures. | Answers cite your approved data; nothing is released to service or certified by Aegironix; certifying staff decide. |
| ISO/IEC 27001 | An information security management system with risk-based controls. | Documented architecture, access model and operational controls to include in your own ISMS scope. |
| National classified-information rules | Classified work happens only in environments accredited by the national security authority. | Deployable fully on-premise and air-gapped; accreditation remains with your security authority, supported by our documentation. |
Aegironix is designed to support these obligations; it does not make your organisation compliant on its own. Compliance depends on how you configure and use the platform, and on your own processes. This table is general information, not legal advice.
Questions from Security and Export-Control Teams
Can Aegironix operators see our data?
No. We operate the platform from outside your boundary, using infrastructure automation and operational health metrics only. Prompts, outputs, documents and logs stay in your infrastructure. In air-gapped deployments, your own staff apply the updates we deliver.
Can access be restricted by nationality and export licence?
Yes. Access rules can combine role, programme, nationality and licence attributes from your identity system, so users only reach the workspaces and documents they are authorised for. Your export-control officers define and maintain those rules.
Where are logs kept, and for how long?
All request, source, route and approval logs are stored in your own infrastructure, under the retention policy you set. You can export them per workspace for audits.
What happens to our data if we stop using Aegironix?
It stays where it is: in your infrastructure. Your knowledge bases, fine-tuned models, ratings and settings remain yours, with exit and continuity terms set out in the contract.
Request the Security Pack
Architecture, data-flow and control documentation for your security, export-control and compliance review.