Airclerk is certified to ISO/IEC 27001:2022 and supports AI implementation, on Claude, Microsoft Copilot or ChatGPT, in regulated financial and professional services across New Zealand and Australia. Security, governance and auditability are treated as central to implementation - not as a later phase.
The questions a risk team asks first: where the documents go, and who can see them. The short answers are here; the detail sits behind the links.
Your documents and systems stay where they are and remain the systems of record; what information goes to the AI provider, and where it is processed, is documented in the design. The AI platform runs under your own licence with the provider, configured so your data is not used for model training where the provider supports that setting. Airclerk holds the configured evidence record, the workflow state and the expected-versus-actual comparison for each instrumented workflow. Raw workflow data and source documents can stay inside your environment.
The Airclerk MCP and its audit trail are hosted by Airclerk with per-tenant isolation, or deployed single-tenant into your own Azure tenant on request. In the single-tenant case your team administers the tenant, identity and network boundary; Airclerk maintains the software and the evidence store inside it for the support period written into the scope, and beyond that under a separate operations agreement. Material subprocessors are listed and reviewed on a set cadence.
Access is scoped to the engagement and covered by NDA and DPA, on customer paper where you prefer. Our own systems run SSO, MFA, least privilege and periodic access reviews, with joiner, mover and leaver discipline. The design documents what Airclerk can access during and after the build and what stays under your team's control; standing access to your production data is not assumed.
Deeper reading: custody, control and evidence on the AI Process Assurance page, the trust centre for policies and the subprocessor list, our privacy policy and terms, and service status.
Airclerk is certified to ISO/IEC 27001:2022, and is pursuing SOC 2 Type 2, as part of our commitment to supporting regulated financial and professional services customers.
Information security management system, certified 28 July 2026 and valid to 27 July 2029. Certificate 1677-I-1, issued by Global Compliance Certification Pty Ltd under JAS-ANZ accreditation. Certified scope: the provision of Airclerk's advisory, AI and software-engineering services for business process and workflow automation, including the supporting corporate systems and information assets (virtual operations). The certificate is available on request.
Security, availability and confidentiality. Controls implemented; audit window starting.
Source control, code review, dependency scanning and release controls aligned with secure development practice.
Formal subprocessor list and review cadence. Material providers documented and contracted.
Documented incident response and breach notification process with named owners.
SSO, MFA, least privilege, periodic access reviews and joiner/mover/leaver discipline.
The Airclerk MCP and its audit trail can be hosted by Airclerk with per-tenant isolation, or deployed single-tenant into your own Azure tenant on request.
We provide a security and governance pack to assist procurement, risk and security teams during vendor onboarding. It includes policy excerpts, the subprocessor list, an architecture overview and our AI governance principles. Ask for it through the contact form and choose the security option, or email trust@airclerk.ai. Public policies are on the trust centre.
No. Airclerk does not train its own foundation models on customer data, and where available we configure the third-party AI providers we implement to disable the use of customer data for model training or improvement. Data-handling documentation is available on request.
Yes. Airclerk is certified to ISO/IEC 27001:2022 under certificate 1677-I-1, issued by Global Compliance Certification Pty Ltd under JAS-ANZ accreditation on 28 July 2026 and valid to 27 July 2029. The certified scope is the provision of Airclerk's advisory, AI and software-engineering services for business process and workflow automation, including the supporting corporate systems and information assets (virtual operations). SOC 2 Type 2 is still in progress. Secure SDLC, vendor management, incident response and access control are active, and our security and governance pack documents the current status.
The Airclerk MCP and its audit trail can be hosted by Airclerk with per-tenant isolation, or deployed single-tenant into your own Azure tenant on request. We maintain a formal subprocessor list and review cadence.
Yes. We have standard NDA and DPA templates, support DPIAs, and are comfortable working under customer paper.
Request it through the contact form, choosing the security option, or email trust@airclerk.ai. The pack assists procurement, risk and security teams during vendor onboarding and includes policy excerpts, the subprocessor list, an architecture overview and our AI governance principles.
That is what the record is for. Review regimes like the CA ANZ practice review sample engagement files and test them against the firm's quality management standards. Airclerk workflows are built so an AI-assisted file carries what a reviewer expects to find: what the work relied on, what was checked, who reviewed it and who signed it off. Airclerk does not make a file compliant; the firm's own quality management system does that. Our work is making sure AI-assisted output leaves the evidence that system needs.