AI Governance
Last updated: July 17, 2026
Aurysia Labs builds AI systems for finance, defense, security, and enterprise customers — contexts where an AI system's behavior can carry real financial, security, or operational consequences. This page describes how we govern that responsibility: the policies, roles, and controls that make up our AI Management System (AIMS), operated in conformance with ISO/IEC 42001, the international standard for AI management systems.
Certification Status
- Standard
- ISO/IEC 42001:2023
- Certification body
- Schellman Compliance, LLC (ANAB-accredited)
- Certificate number
- 1698444-1
- Valid
- July 17, 2026 – July 17, 2028
- Certified scope
- The artificial intelligence management system (AIMS) supporting Aurysia Labs AI Data Cloud Services, in the role of an AI producer, AI developer, and AI product and service provider, per Statement of Applicability v2025.1 (January 29, 2025). In-scope location: 1209 Mountain Road PL NE, STE R, Albuquerque, NM 87110, United States.
Certificate available on request at contact@aurysialabs.com. Certification covers our AI management system, not an endorsement or labelling of any individual product or service.
1. Governance
Our AI Policy is approved and signed by Aurysia Labs' Founder & CEO and governs every AI system we build or operate. It is owned day to day by our AI Governance Lead and overseen by the AI Governance Committee (AIGC), a standing body that meets quarterly — and within days of any serious incident — to review our AI systems, open risks, and supplier posture.
- —A documented AI Policy, reviewed at least annually
- —Named roles and responsibilities for every stage of the AI lifecycle, from a product engineering lead accountable per product to a company-wide reporting channel every employee can use
- —A quarterly AI Governance Committee with authority to block a production launch pending unresolved risk
2. Inventory & Risk Management
Every AI system we operate is registered before it reaches production, classified by risk (Low, Medium, or High) based on the severity of potential harm and how autonomously it acts, and — for anything Medium risk or above — put through a formal AI Impact Assessment before launch.
- —A maintained inventory of every AI system across Terminal, Spectra, Sentinel, Shield, Quant, and Warden
- —AI Impact Assessments covering purpose, affected stakeholders, data, autonomy, bias testing, and mitigations
- —Continuous post-launch monitoring — performance drift, override rates, and anomalous activity — reviewed weekly for our highest-risk systems and escalated through a defined incident-severity process
3. Lifecycle of Our AI Systems
We apply documented controls at every stage of an AI system's life — design, development, evaluation, staged rollout, production, and eventual decommissioning — so risk is assessed before exposure grows, not after.
- —Traceability: every model version, its training/grounding data, and its evaluation results are logged, so any output can be traced back to the exact model version and data that produced it
- —Staged rollout: material changes to a higher-risk system go through canary deployment and monitoring before general availability, with a tested rollback plan
- —Bias & fairness testing: systems are tested against a fairness definition specific to their function — for example, consistent policy enforcement across customers in Warden, or subgroup detection accuracy in Spectra — on a fixed cadence, not only at launch
- —Decommissioning: retired systems have a documented data-disposition decision and customer notice period
4. Suppliers & Third Parties
Our own AI systems depend in part on third-party model, cloud, and data providers. We evaluate those suppliers before use and monitor them for as long as we rely on them.
- —Pre-engagement review of data handling, security posture, model transparency, and sub-processor disclosure for every AI/ML supplier
- —Annual re-review, plus immediate re-review on any supplier security incident or material model change
- —Standard AI-related contract terms — data-use limitation, disclosure, and human-oversight clauses — in both our supplier agreements and our customer contracts
5. Transparency, Human Oversight & Ethics
No output a user reasonably relies on for a decision leaves an Aurysia Labs product without being identifiable as AI-generated or AI-assisted, and no high-consequence system acts without a way for a human to intervene.
- —Disclosure: AI-generated or AI-assisted output is labeled in-product — for example, Warden logs the specific policy rule behind every allow/deny decision, and Terminal links summaries back to source documents
- —Human oversight: our highest-risk, autonomous-capable products — Warden and Quant — ship with a customer-reachable kill switch that suspends autonomous action and reverts to human confirmation, and a fail-closed default so uncertainty is escalated rather than silently allowed
- —Contestation: anyone affected by an Aurysia Labs AI decision can dispute it through an in-product mechanism or our support channel; disputes are investigated against the system's own decision log, and no one is penalized for raising one in good faith
- —Explainability: higher-risk decisions come with a stated reason — the rule, threshold, or signal that drove them — matched to the depth a user actually needs to act, documented per product
Related policies
- —Privacy Policy — how we collect, use, and protect personal data, including data processed by our AI systems
- —Terms of Service — the terms governing use of our products
Questions about our AI governance, a specific AI decision, or our ISO/IEC 42001 certification? Contact us at contact@aurysialabs.com
Aurysia Labs LLC — 1209 Mountain Road PL NE, STE R, Albuquerque, NM 87110, USA