Security at ira
The whole product is built on one decision: your customers' voices never leave your network. Everything below follows from it.
Nothing to exfiltrate is the strongest control there is.
Most conversation-intelligence vendors ship your audio to their cloud and then spend a security page explaining how well they guard it. We removed the journey instead of hardening it.
Inside your perimeter
ira installs on your own hardware or your private cloud tenancy. Models, index, transcripts and audit logs all live on infrastructure you control and can physically walk to.
- Bare metal or Kubernetes
- Air-gapped installs supported
- No outbound inference calls
One direction only
Audio arrives from your telephony, is processed in memory, and is written only where your retention policy says. Hints are generated locally and rendered to the agent's browser on your network.
- No third-party translation API
- No cloud LLM call
- No telemetry containing content
You pull, we do not push
Model and software releases are signed artefacts that your team pulls and promotes through your own change process. We have no standing access to a production environment.
- Signed, checksummed builds
- Staged rollout under your control
- Rollback to prior version
What is switched on by default
How we prove it rather than assert it.
An on-prem product can be inspected in ways a SaaS product cannot. We would rather you looked than took our word.
Independent testing
Annual third-party penetration test against a reference deployment, with the summary report available to customers and prospects under NDA. Findings are tracked to closure with severity-based SLAs.
Secure development
Peer-reviewed changes, dependency and container scanning in CI, signed release artefacts, and a documented SDLC. Production access by our own team is limited to our internal systems, not yours.
Your own audit
Because the software runs on your infrastructure, your security team can inspect network behaviour, sniff egress, review logs and run their own tooling against it. We will sit with them while they do.
Compliance posture
Designed against ISO 27001 and SOC 2 control families, and built to support your obligations under IRDAI, the DPDP Act, GDPR and HIPAA. Current certification status is shared on request — we will tell you what we hold today rather than what we intend to hold.
Tell us and we will fix it.
If you believe you have found a security issue in ira software, our website, or a deployment you are authorised to test, we want to hear from you before anyone else does.
Write to security@ira.ai
Include what you found, how to reproduce it, and the impact you think it has. Encrypt with our PGP key if the details are sensitive — request it at the same address.
We acknowledge within 2 business days
You get a named human, not a ticket number. We will tell you whether we can reproduce it and what we think the severity is.
We fix, then we credit
Critical issues are patched and released to customers on an emergency track. We will credit you publicly if you would like, and we will not pursue legal action against good-faith research.
Please do not test against a customer's live environment without their written authorisation, do not access data that is not yours, and give us reasonable time to remediate before publishing.
If something goes wrong
We maintain a documented incident response process with defined roles, severity levels and communication paths. Where we are your processor and become aware of a personal data breach affecting your data, we notify you without undue delay and in any event within 48 hours, with the detail set out in the DPA.
Send it to your security team.
We will complete your vendor questionnaire, join the review call, and give your engineers direct access to test the deployment.