This page is maintained by IRES AI to answer common security and privacy questions about the IRES AI product. It describes the controls we operate today and how responsibility is split between IRES AI, our platform providers and our customers. It is not an independent certification.
Shared responsibility
- IRES AI operates the application, the AI orchestration layer and the customer-facing controls listed below.
- Platform providers (managed database & hosting, model providers) operate the underlying infrastructure and its certifications.
- Customers (committees, owners, managers) control who they invite, what documents they upload and how they act on IRIS drafts.
Access & authentication
- Email/password and Google sign-in for end users.
- Role-based access inside each community (owner, committee, manager, auditor).
- Row-level security in the database — every query is scoped to the caller.
- Admin/service credentials are never exposed to browser code.
Data residency & hosting
- Application and database hosted in the EU (Frankfurt region).
- No customer data is stored on servers outside the EU by IRES AI.
- Certain AI model calls may be routed through providers with multi-region infrastructure — see subprocessors below.
Encryption
- TLS in transit for all traffic to and from the application.
- Encryption at rest for the managed database and file storage.
- Session cookies are httpOnly, secure and SameSite=Lax.
Data collection & use
- We collect the data communities need to operate: members, units, meetings, messages, ledger entries, documents.
- We do not sell personal data.
- We do not use customer content to train third-party foundation models.
Anonymous insights
IRES AI may transform platform data into anonymous, aggregated statistics and anonymised datasets, and share or license those with public authorities, research institutions or commercial partners. Anonymisation follows EDPB Opinion 05/2014 with minimum aggregation thresholds and suppression of any household- or community-identifying combinations. Personal data is never included. Details are in the Privacy Policy and the Data Processing Agreement.
Subprocessors
A current list of subprocessors (hosting, database, email, AI model providers) is maintained in the Data Processing Agreement. Material changes are communicated to customers via email before they take effect.
Retention & deletion
- Customer data is retained while the community is active.
- On account closure, data is deleted or anonymised within 30 days, except where retention is legally required (e.g. tax records).
- Owners can request export or deletion of their personal data at any time — see Privacy Policy.
Incident response & security contact
Suspected security issues should be reported to security@iresai.app. We acknowledge reports within one working day and coordinate disclosure with the reporter.
Compliance posture
- GDPR-aware product design; DPA available on request.
- IRES AI is a private beta operated by a small team. We do not currently claim SOC 2, ISO 27001 or HIPAA certification.
