Security, Governance and Export Control

Written for your CISO, security officer, export-control team and customer auditors: exactly what stays inside your boundary, who can reach it, and how each control maps to the frameworks you work under.

What Leaves Your Account

Never Leaves

  • Technical and Export-Controlled DataDrawings, specifications, test data and controlled technical data, including prompts and outputs about them.
  • Maintenance and Programme DataWork orders, component histories, contracts, bids and pricing.
  • Inspection ImageryBorescope, NDT and camera footage, processed only at your site edge or in your cloud.
  • Logs and EvaluationsRequest logs, sources, approvals and expert ratings.

May Leave, Under Your Control

  • Operational Health MetricsCPU, GPU and service health so we can operate the platform. You can inspect or switch them off; none in air-gapped deployments.
  • Public-Only Managed AI TasksOnly tasks the policy check classes as public, for task types you allow, under a monthly cap. Off by default in air-gapped deployments.

Who Can Reach What

Controls built into the platform, configured by your teams.

Policy Check First

Every request is checked before any model sees it. Controlled data, or anything the check is unsure about, stays private.

Access by Role, Programme and Licence

Attributes from your identity provider decide which workspaces and documents each user can reach.

Audit Trail per Workspace

Every request, source, route and approval is logged in your infrastructure and exportable per customer.

Human Oversight

Read-only connectors. Nothing is released, certified, classified, filed or sent automatically.

Frameworks and How Controls Map to Them

How the platform is designed to support the rules defence and aerospace organisations work under.

FrameworkWhat it expectsHow Aegironix is designed to support it
ITAR, EAR and EU Dual-Use Regulation (EU) 2021/821Controlled technical data is not exported or released to unauthorised persons.Controlled data processed only on private models in infrastructure you choose; access limited by programme, role, nationality and licence; managed AI never receives it; every access logged.
NIST SP 800-171, DFARS 252.204-7012 and CMMCControlled unclassified information is protected by defined security requirements.Runs inside your accredited boundary, with role-based access, encryption, audit logging and documentation to map controls in your system security plan.
NIS2 DirectiveEssential and important entities manage cybersecurity risk, including suppliers.Security documentation, logging and incident-support processes that fit your supplier risk management and reporting duties.
GDPRPersonal data is processed lawfully, minimally and securely.Processing inside your infrastructure, no facial recognition in inspection vision, face blurring at source and documentation for your DPIA.
EU AI ActObligations for AI systems placed on the EU market; military-only use is out of scope.Human oversight on every output, logging, transparency on routes and models, and documentation for civil and dual-use applications.
AS9100 and EN 9100Quality management for aviation, space and defence organisations.Versioned knowledge, evaluated releases with rollback and records that support your document and change control.
EASA Part 21 and Part 145Design, production and maintenance organisations follow approved data and procedures.Answers cite your approved data; nothing is released to service or certified by Aegironix; certifying staff decide.
ISO/IEC 27001An information security management system with risk-based controls.Documented architecture, access model and operational controls to include in your own ISMS scope.
National classified-information rulesClassified work happens only in environments accredited by the national security authority.Deployable fully on-premise and air-gapped; accreditation remains with your security authority, supported by our documentation.

Aegironix is designed to support these obligations; it does not make your organisation compliant on its own. Compliance depends on how you configure and use the platform, and on your own processes. This table is general information, not legal advice.

Questions from Security and Export-Control Teams

Can Aegironix operators see our data?

No. We operate the platform from outside your boundary, using infrastructure automation and operational health metrics only. Prompts, outputs, documents and logs stay in your infrastructure. In air-gapped deployments, your own staff apply the updates we deliver.

Can access be restricted by nationality and export licence?

Yes. Access rules can combine role, programme, nationality and licence attributes from your identity system, so users only reach the workspaces and documents they are authorised for. Your export-control officers define and maintain those rules.

Where are logs kept, and for how long?

All request, source, route and approval logs are stored in your own infrastructure, under the retention policy you set. You can export them per workspace for audits.

What happens to our data if we stop using Aegironix?

It stays where it is: in your infrastructure. Your knowledge bases, fine-tuned models, ratings and settings remain yours, with exit and continuity terms set out in the contract.

Request the Security Pack

Architecture, data-flow and control documentation for your security, export-control and compliance review.