Ethics, privacy, and compliance
What is the IREX Ethical AI framework?
IREX is built on a doctrine of Transparency by Design: accountability is embedded in the platform's architecture, access controls, audit trails, and AI constraints rather than added as a compliance step at the end. The framework rests on six pillars that govern how the platform creates, accesses, stores, and shares data:
- Full Transparency — every action on the platform (searches, database additions, alert configurations, video exports, permission changes) is recorded in a detailed, non-erasable, fully searchable audit log.
- Cybersecurity and Privacy Protection — a secure private cloud architecture, HTTPS/TLS 1.3 encryption end to end, layered WAF/IDS/IPS defenses, JWT authentication with regularly rotated keys, multi-factor authentication, and penetration testing for each major release.
- Narrow Constraints for Law Enforcement — the platform detects only pre-identified persons relevant to active cases, and the database size for real-time biometric identification is restricted.
- Permission-Driven User Interface — hierarchical role-based access control, so each user sees and does only what their role requires; configuration changes are limited to designated top-level roles and are logged in full.
- Bias Awareness and Mitigation — continuous work to reduce demographic bias, a proprietary 40-million-image training dataset optimized for real-world CCTV conditions, participation in the NIST Face Recognition Vendor Test (FRVT), and proactive disclosure of any systematic bias to the customer.
- Ethics Best Practices and Compliance Checklists — user guidelines, audit processes, and compliance checklists developed with privacy, civil-liberties, and law-enforcement experts.
Every high-risk AI action is additionally bound to a mandatory Case ID. For how these pillars appear in the product, see Engineered for ethics.
What is Case ID, and why does the platform require it?
Case ID is a mandatory justification mechanism built into the platform: before performing a privacy-sensitive AI action, the operator must enter a Case ID — a reference, in a standardized format, to the legal document that provides the lawful grounds for that action, such as a police case file, a court order, or a missing person report. Case ID is required for people searches, vehicle searches, event searches, watchlist management, alarm-monitor management, media management, and live video access; an operator cannot perform these actions without one. Every Case ID action is recorded in the platform's consolidated Logbook with who performed it, what was done, when, and why — the Case ID and its legal justification. Signed log files are exported daily to a secure archive, digitally signed so tampering can be detected, and can be reviewed by independent third parties such as ethics committees, inspectors general, and court-appointed auditors without access to the platform itself. In data-protection terms, Case ID operationally enforces the lawful-basis requirement for biometric processing: a court order or equivalent lawful authorization must be entered before a facial-recognition search can run. Step-by-step instructions are in Provide Case ID.
Can the platform identify or track random people in public spaces?
No. The platform identifies only pre-registered persons — missing people, criminals, suspects, trafficking victims, and other individuals relevant to active cases. It does not identify or track random individuals in public spaces, and its neural networks are trained specifically to recognize scenes and subjects that threaten public safety. These limits are enforced in the platform architecture, not by policy alone:
- The database size for real-time biometric identification is restricted, which prevents mass-surveillance use.
- A Case ID is mandatory before any facial-recognition search, so a court order or equivalent lawful authorization must be entered first. This establishes the lawful basis and creates an audit trail, in line with the EU AI Act's Article 5 provisions on prohibited AI practices.
- Facial biometric identifiers are classified at the highest sensitivity level and treated as special-category data under GDPR Article 9, with access limited to essential personnel under role-based access control and every access logged.
- A Data Protection Impact Assessment is required before face recognition is enabled on any IrexAI-managed deployment; on-premises customers are advised to conduct their own.
- Audit logging is non-erasable, with daily signed exports that independent oversight bodies can review.
How does the platform keep humans in control of AI alerts and decisions?
Human control is maintained through several mechanisms that reinforce each other:
- Permission-driven interface. Platform features, people databases, match alerts, and search results are visible only to users whose role carries sufficient permissions under hierarchical role-based access control. User groups define which cameras, recordings, analytics modules, and search capabilities each operator can reach, and configuration changes are restricted to designated top-level roles. This permission-driven design is how the platform supports the EU AI Act's human-oversight obligation.
- Supervisory audit. Authorized supervisors can search the Logbook by Case ID, user ID, event type, or date and time range to trace a sequence of actions, audit compliance, or investigate suspected misuse.
- Bounded AI agents. The platform's autonomous investigation agents are logged and attributed to the operator who initiated them and to the authorizing Case ID. Agents work within the same permission boundaries as that operator and cannot escalate their own access, and every agent-initiated action is auditable through the same Logbook and export mechanisms as manual work.
- Reviewable detections. Automated detections are governed by the six-pillar framework — transparency, proportionality, human oversight, and Case ID auditability — so they remain reviewable and attributable.
IrexAI also applies human-in-the-loop requirements to its own internal use of AI tools: agentic actions with side effects require human approval, and no customer-facing automated decision with a legal or similarly significant effect is made by an AI system without a human reviewer.
Which privacy and AI regulations is the platform aligned with?
The platform is engineered to support compliance with the major AI and privacy frameworks that apply to public-safety deployments. These are alignment and compliance-support positions, not third-party certifications.
- EU AI Act. The architecture addresses the core obligations for high-risk law-enforcement AI: risk management through narrow constraints and Case ID, data governance through customer-owned data with defined retention and minimization, human oversight through permission-driven role-based access control, transparency through non-erasable logs with daily signed exports, and accuracy through continuous bias testing and NIST FRVT participation.
- GDPR. The platform supports all seven GDPR principles. Data-subject rights, Data Protection Impact Assessments for biometric processing, 72-hour breach notification, and Standard Contractual Clauses for cross-border transfers are documented in the IrexAI Data Protection Policy.
- CCPA / CPRA. Consumer rights to know, delete, correct, and opt out are honored within statutory timeframes, and biometric information is treated as sensitive personal information. IrexAI also commits to meeting applicable US state privacy and biometric-privacy laws in the jurisdictions where the platform is deployed, applying the more protective standard where regimes overlap.
- NIST AI Risk Management Framework. The Ethical AI framework maps to the four core functions — Govern, Map, Measure, and Manage.
- FBI CJIS Security Policy. The platform supports all 13 CJIS policy areas, including access control, auditing and accountability, incident response, encryption, multi-factor authentication, and formal audit readiness, and can be deployed in US data centers at county, state, or federal level.
IrexAI's information security management system is aligned with ISO/IEC 27001:2022; IrexAI does not hold an ISO 27001 certificate of its own.
Who owns the data processed by the platform, and how long is video retained?
Customer data — video, events, logs, and floor plans — is owned exclusively by the customer. IREX neither owns customer data nor has access to it, and customer data is not sold to third parties, shared with competitors, or used to train IrexAI's models.
Retention is configurable for each deployment and is set by the customer, who acts as the data controller. For IrexAI-managed instances the defaults are:
- Raw video archive — 30 days by default, configurable up to 90 days.
- Critical alert images and associated logs — 12 months or longer, configured per instance.
- Biometric identifiers — configurable, retained no longer than necessary for the controller's purpose.
- Detection and event metadata and Case ID records — configurable, and typically longer than raw footage where an investigation justifies it.
Data may be held beyond these periods where an investigation or dispute is under way, a legal hold applies, or a lawful authority has requested retention. When a retention period ends, data is disposed of by cryptographic erasure or secure overwrite, and deletion is verified for the most sensitive categories, including biometric data. On customer-hosted, on-premises deployments the customer operates the instance and sets retention directly.