Skip to content
Aurexus

Trust Centre

Trust Centre

Security, privacy and responsible intelligence

Security, privacy, compliance, responsible AI and data protection commitments at Aurexus Group Ltd.

Overview

How Aurexus approaches trust

Overview

Trust is Aurexus' greatest asset. It is earned through every design choice, partnership and delivery commitment—not claimed through certifications we have not earned or controls we have not implemented.

This Trust Centre provides an executive overview of how Aurexus approaches security, privacy, compliance and responsible AI. Detailed operational controls, architecture documentation and audit evidence are available to partner organisations under appropriate confidentiality arrangements and will mature as Aurexus scales.


Security

Aurexus treats security as a foundational engineering commitment.

Our commitments:

  • Security integrated into architecture, development and deployment from inception—not added afterward
  • Defence-in-depth across infrastructure, application and data layers
  • Least-privilege access with comprehensive audit trails
  • Regular security assessment and continuous improvement of security posture
  • Secure interoperability between systems and processes

Availability of detail: Detailed security architecture documentation, penetration testing results and security policies are available to partner organisations under NDA. Aurexus does not publish operational security details publicly.


Privacy

Aurexus respects the privacy of the individuals and organisations whose data our platforms process.

Our commitments:

  • Data collected and processed only for defined, legitimate organisational purposes
  • Privacy considerations integrated into platform design from the outset
  • Transparency with partner organisations about what data is collected, how it is used and how it is protected
  • Respect for data subject rights in accordance with applicable legislation
  • Data minimisation—collecting only what is necessary to deliver defined capabilities

Availability of detail: Privacy policies and data processing documentation are provided to partner organisations as part of engagement. Public privacy documentation will be published as platforms reach general availability.


Compliance

Aurexus designs platforms with the governance expectations of regulated environments in mind—particularly healthcare, pharmaceutical and public-sector contexts.

Our commitments:

  • Governance frameworks embedded in platform architecture from design through deployment
  • Awareness of regulatory requirements in the sectors we serve
  • Auditability and transparency built into every process and data flow
  • Continuous monitoring of regulatory developments and adaptation of platform capabilities accordingly

What we do not claim: Aurexus does not claim certifications—such as ISO 27001, SOC 2 or Cyber Essentials—that have not been formally achieved and independently verified. Compliance maturity will be documented honestly as it develops.


Responsible AI

Responsible AI is an engineering requirement at Aurexus, not a marketing position.

Our commitments:

  • AI operates as decision support—professionals retain judgement and organisational accountability
  • AI outputs are subject to professional review before acting upon them
  • Transparency in how AI-assisted insights are generated
  • Governance frameworks applied to AI capabilities with the same rigour as any other system component
  • Continuous evaluation of AI performance against organisational outcomes
  • No deployment of AI capabilities that compromise safety, accountability or trust

Availability of detail: AI governance frameworks and model documentation are available to partner organisations under appropriate confidentiality arrangements.


Availability

Aurexus platforms are engineered for continuous operation in demanding environments.

Our commitments:

  • Architectures designed for resilience and fault tolerance
  • Monitoring and alerting to detect and respond to service degradation
  • Disaster recovery planning aligned with partner organisational requirements
  • Transparent communication with partners during incidents or planned maintenance

Availability of detail: Service level commitments and availability metrics are defined individually with partner organisations based on operational requirements.


Business continuity

Organisations that depend on Aurexus platforms must be able to continue operating through disruption.

Our commitments:

  • Business continuity planning integrated into platform architecture and operational procedures
  • Regular review and testing of continuity arrangements
  • Data backup and recovery capabilities aligned with partner requirements
  • Clear escalation and communication procedures during incidents

Availability of detail: Business continuity documentation is provided to partner organisations as part of engagement.


Data protection

Data protection is a shared responsibility between Aurexus and the organisations we serve.

Our commitments:

  • Encryption of data in transit and at rest using industry-standard protocols
  • Access controls based on least privilege with comprehensive logging
  • Data residency considerations aligned with partner and regulatory requirements
  • Clear data processing agreements defining roles, responsibilities and obligations
  • Incident notification procedures aligned with applicable legal requirements

Encryption

Our commitments:

  • Industry-standard encryption for data in transit (TLS) and at rest
  • Key management practices aligned with security best practices
  • Encryption applied consistently across all Aurexus platforms and infrastructure

Authentication

Our commitments:

  • Strong authentication mechanisms for platform access
  • Role-based access control aligned with organisational governance structures
  • Multi-factor authentication where appropriate for the sensitivity of the environment
  • Session management and access logging for audit purposes

Secure development

Our commitments:

  • Secure development lifecycle practices integrated into engineering workflows
  • Code review, testing and vulnerability assessment as standard practice
  • Dependency management and monitoring for known vulnerabilities
  • Security training for engineering team members
  • Separation of development, testing and production environments

Availability of detail: Secure development policies and practices documentation is available to partner organisations under NDA.


Responsible disclosure

Aurexus welcomes responsible disclosure of security vulnerabilities.

Our commitments:

  • A defined process for receiving, assessing and responding to security vulnerability reports
  • Acknowledgement of good-faith security research
  • Timely remediation of confirmed vulnerabilities
  • Transparent communication with affected partners

Reporting: Security researchers and partners who identify potential vulnerabilities should contact admin@bioaegix.com with the subject line "Security Disclosure."


Incident response

Our commitments:

  • Defined incident response procedures for detecting, assessing and remediating security and operational incidents
  • Escalation pathways with clear roles and responsibilities
  • Partner notification procedures aligned with contractual and legal obligations
  • Post-incident review and continuous improvement of response capabilities

Availability of detail: Incident response procedures are shared with partner organisations as part of engagement.


Questions

For trust, security or compliance enquiries, contact admin@bioaegix.com.

Detailed controls documentation is available to partner organisations under appropriate confidentiality arrangements.

Contact Aurexus

Prefer a full policy index? Browse legal pages

Need a security questionnaire or NDA discussion?

Enterprise and partnership teams can reach us for diligence materials proportionate to engagement scope.