Ethical AI · Transparency by Design

The standard for ethical AI in public safety

For every IREX engagement, the highest priority is optimizing safety and life-enhancing technology within the privacy and ethical norms of free societies. We don't promise ethics in a policy document — we engineer it into the architecture, where it cannot be switched off.

Book a Demo
  • 250,000+cameras held to this standard
  • 8countries in production
  • NIST FRVTindependently evaluated
  • World firstCase ID mandate in video analytics

Why it matters

Ethics as architecture, not afterthought

Public safety agencies face an urgent challenge: how to use the power of artificial intelligence while upholding the rights and trust of the communities they serve. Surveillance technology without ethical guardrails erodes public confidence, invites regulatory risk, and undermines the very safety it aims to provide.

IREX was built from the ground up to solve this problem. Rather than treating ethics as a compliance checkbox bolted on at the end, accountability is embedded in every layer of the platform — the architecture, the access controls, the audit trails, and the limits on what the AI is permitted to do at all. The result: every high-risk AI action is justified, logged and auditable.

The framework

Six pillars of trust

Transparency by Design is a doctrine, and these six pillars are how it governs the way the platform creates, accesses, stores and shares data — six commitments enforced by the system itself, not six promises.

01

Full Transparency

Every action — database additions, search queries, alert configurations, video exports, permission changes — is written to a detailed, non-erasable audit log that supervisors and oversight bodies can search in full. Who did what, when, and why is a matter of record, not reconstruction.

02

Cybersecurity and Privacy Protection

TLS 1.3 end to end, multilayer WAF, IDS/IPS and network filtering, JWT with asymmetric signatures and rotating keys, MFA, and penetration testing against the OWASP Testing Guide on every major release. Customer data is owned exclusively by the customer.

03

Narrow Constraints for Law Enforcement

Detection is limited to pre-identified people — wanted suspects, missing children, trafficking victims. Real-time biometric database size is capped, and recognition of random individuals is not possible. These limits are architectural, not policy: misuse is structurally prevented, not merely prohibited.

04

Permission-Driven Interface

Hierarchical role-based access control decides which cameras, recordings, analytics modules, databases and results each operator can reach. Configuration changes are restricted to top-level roles and logged in full detail.

05

Bias Awareness and Mitigation

Our face-recognition engine is trained on a proprietary 40-million-image dataset optimized for real CCTV conditions and evaluated independently in the NIST Face Recognition Vendor Test. Where systematic bias exists, our policy is to disclose it and its estimated impact to the customer.

06

Ethics Best Practices and Compliance

User guidelines, audit processes and compliance checklists built with privacy, civil-liberties and law-enforcement experts — supporting GDPR and CCPA, and aligned with the EU AI Act, the NIST AI RMF and the FBI CJIS Security Policy.

Case ID — a world first

Every high-risk AI action carries the reason it was allowed

Case ID is a mandatory justification mechanism built into the platform. Before performing any privacy-sensitive AI action, the operator enters a Case ID — a reference to the legal document that grants the lawful basis for it: a police case file, a court order, a missing-person report. The reference is recorded permanently alongside the action it authorizes, and no operator can proceed without it.

IREX is the world's only video management and analytics platform to offer comprehensive logging of all high-risk AI operations, with every action tied to a legitimate case reference — a platform-level mandate, not a setting an administrator can switch off.

When Case ID is required

  • People searches — photo, name, appearance
  • Vehicle searches — plate, make, model
  • Event searches — weapons, intrusion, unattended items
  • Watchlist management — adding or modifying entries
  • Alarm monitor management — real-time alert streams
  • Media management — upload, analysis, export of evidence
  • Live video access — live feeds and archived recordings

Every Logbook entry answers four questions

Who

The operator’s identity and role, on every entry.

What

The action taken — search type, database operation, export.

When

A precise timestamp, in an append-only sequence.

Why

The Case ID — the legal justification, bound permanently.

Tamper-proof by export. Signed log files are automatically exported daily to a secure archive — digitally signed to detect tampering, available even after a disaster or breach, and reviewable by ethics committees, inspectors general and court-appointed auditors without platform access.

Case ID logging turns AI accountability from a policy aspiration into a technical reality. It protects communities from misuse, protects officers by documenting their lawful actions, and gives oversight bodies the evidence to verify that AI is being used responsibly.

Regulatory alignment

Built for the world's toughest standards

The regulatory landscape for AI in law enforcement is evolving fast. IREX is engineered to meet these requirements today, so agencies can deploy with confidence and avoid costly retrofits as regulations take effect.

EU Artificial Intelligence Act

The Act classifies real-time biometric identification in public spaces as high-risk. IREX’s architecture already satisfies its core obligations: built-in risk constraints, customer-owned data governance, human oversight through RBAC, non-erasable transparency logs, and continuous accuracy testing.

NIST AI Risk Management Framework

The Ethical AI framework aligns with the four core functions of the NIST AI RMF — Govern, Map, Measure and Manage — giving U.S. agencies a structured, evidence-based approach to responsible AI deployment.

FBI CJIS Security Policy

Access control, authentication, encryption and audit capabilities designed to support compliance with the Criminal Justice Information Services Security Policy that governs U.S. law-enforcement data.

GDPR and CCPA

The platform supports all seven GDPR principles — lawfulness, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability — with logging, access control and retention features that help customers demonstrate compliance.

The next frontier

Ethical Agentic AI: responsible autonomy

IREX is pioneering autonomous investigation agents that operate within strict ethical boundaries. Natural-language investigations, multi-step search orchestration and automated cross-referencing — shipping in beta on selected instances — are governed by the same Transparency by Design principles as every other platform feature. Autonomy and accountability are not in conflict; they are complementary.

Logged and attributed

Every agent action is attributed to the operator who initiated it and the Case ID that authorizes it.

No self-escalation

Agents operate within the same permission boundaries as the human operator, with no ability to escalate their own access.

Fully auditable

All agent-initiated searches, watchlist queries and alert configurations flow through the same Logbook and signed daily exports as manual operations.

Our commitment

Hold us to this standard

IREX exists to make communities safer without compromising the values that make them worth protecting. Through our partnership with the National Child Protection Task Force, we actively combat human and child trafficking — and those cases are the sharpest test of this framework: the capability that finds a trafficking victim is the same capability that could be misused against an ordinary person. The Case ID mandate, the pre-registration constraint and the audit trail exist so that the first is possible and the second is not.

We invite law enforcement agencies, governments and oversight bodies to hold us to this standard. Our logs are open to audit. Our constraints are verifiable. Our commitment is permanent.

Our ethics program is advised by David K. Bain — former Executive Director of INCITS, the US secretariat for international IT standards under ISO/IEC JTC 1, and founding Executive Director of the Technology Integrity Council.

See the audit trail on your own cameras

Tell us about your camera environment and compliance requirements, and we'll walk you through the Logbook, Case ID and the six pillars on your footage — not a canned demo.