Trust & Compliance

Security & Compliance

AiRK systems are built with security and data minimisation in mind at the architecture level this page outlines our posture, not a substitute for your own assessment.

Every regulatory claim on this page is intentionally scoped to "designed around" not "certified" or "legally guaranteed." Confirm your organization's specific compliance status with your own counsel; this page is not a substitute for that assessment.

Edge-first data processing

AiRK systems are built to process data on-device call audio, drone imagery, sensor streams so less sensitive data has to leave your environment. The calling agent's speech recognition and synthesis run locally on the Jetson platform. Drone imagery is analysed on-board. AMR navigation decisions happen on the robot.

This is an architectural choice, not a marketing claim: keeping data on-device reduces exposure surface, simplifies compliance in sensitive industries, and eliminates cloud round-trip latency.

Encryption in transit & at rest

Data in transit is protected with modern TLS (1.2 minimum, 1.3 preferred). Data at rest is encrypted on-device and in any upstream storage.

Specific cipher suites and key-management architecture are shared under NDA during technical due diligence.

Data protection across markets

AiRK operates across the UAE, India, and the USA three markets with distinct data-protection frameworks. Our systems are designed around the requirements of each:

  • UAE PDPL (Personal Data Protection Law): Designed around consent, data minimisation, and cross-border transfer obligations under the UAE PDPL.
  • India DPDP Act (Digital Personal Data Protection Act): Designed around consent-based processing, purpose limitation, and Data Fiduciary obligations under the DPDP Act, 2023.
  • US frameworks: Designed with awareness of applicable state and federal data-protection frameworks, including CCPA where relevant.

Compliance status is deployment- and jurisdiction-specific confirm your organization's requirements with your own legal counsel.

Telecom compliance AI Calling Agent

The calling agent is designed to operate within the telemarketing and outbound communication rules of the markets we serve:

  • UAE (TDRA): Designed around UAE Telecommunications and Digital Government Regulatory Authority requirements, including the Do Not Call Registry and consent obligations for outbound communication.
  • India: Designed with awareness of TRAI DND (Do Not Disturb) regulations and consent requirements for commercial communication.
  • USA: Designed with awareness of TCPA requirements and FTC/FCC rules for automated outbound calls.

Regulatory status is confirmed per deployment, jurisdiction, and use case, and remains the customer's responsibility to verify with legal and compliance counsel.

Aerial & robotics operational compliance

Drone operations are regulated by civil-aviation authorities in each market. AiRK supports customers in understanding and meeting applicable requirements but regulatory approval is the customer's responsibility.

  • US FAA: UAS operations under Part 107 and applicable waivers.
  • India DGCA: UAS regulations under the Drone Rules, 2021, and applicable approvals.
  • UAE GCAA: UAS operations under GCAA/CAAN regulations and applicable NOTAM procedures.

AMRs are deployed with operational-safety practices: zone demarcation, personnel awareness protocols, and speed governance. Specifics depend on the facility and jurisdiction.

This is not a substitute for regulatory approval. AiRK does not provide regulatory approvals requirements are verified per deployment before any flight operation begins.

Access control & audit logging

Role-based access control governs who can configure, monitor, and report on AiRK systems. Audit logging records system actions for accountability and incident investigation.

The specific RBAC model and log-retention period are confirmed per implementation during deployment scoping.

Vulnerability disclosure

If you discover a security vulnerability in an AiRK system or this website, please report it responsibly:

We aim to acknowledge security reports within 2 business days and to provide a substantive response within 10 business days. We do not pursue legal action against good-faith reporters.

Security questions about an AiRK deployment?

Talk to us. We're happy to discuss our architecture and security posture in detail.