CyberSentien assesses once against your real evidence and reports everywhere — deterministic verdicts, honest coverage, tamper-evident lineage on every report. Controls without evidence read “manual assessment required”, never a fabricated pass. Built for assessors, practices, banks and AI providers.
A control with no evidence renders “manual assessment required”. A signal that stops reporting renders lost visibility. Evidence past its freshness window renders stale. The engine has no path from nothing to compliant — so the collapse that happens when an assessor asks for the artefact simply cannot start here.
The full ISM at IRAP depth, current with ASD’s quarterly releases. Essential Eight assessed per strategy across ML1–ML3. APRA CPS 230, CPS 234 and CPS 220 together, because that is how you are supervised. These are the spine of the engine, not entries on a list.
SOC 1, SOC 2, SOC 3, ISO 27001, ISO 42001, PCI DSS, NIST 800-53, NIST CSF 2.0, CIS v8, FedRAMP, the EU AI Act and more — on one evidence spine. Collect an artefact once and it is credited everywhere it applies, through a crosswalk validated so a mapping can never score a control that does not exist.
Every artefact is timestamped and SHA-256-lineaged; every issued report carries an integrity anchor a regulator, auditor or client can verify independently — no account, no call to us. Assurance you cannot check is just a claim.
An Australian company (ACN 688 655 334) on Australian-sovereign infrastructure, with the AI inside that boundary rather than a third-party API. When procurement asks who owns and controls the stack holding your posture, that is a one-sentence answer.
Our pricing is on the website so you can budget before you speak to anyone, and the demo is the real engine — not a scripted tour. Open it and try to make it show you a pass it cannot prove.
Start on the real engine now. Pricing is published so you can budget before you talk to us. Australian-sovereign, no lock-in.
Open the gated demo and run the REAL engine on a synthetic sample library spanning strong evidence through to poor — so you can watch it stay honest no matter what it's fed. Instant sample reports open immediately from cached scenarios — pre-run assessments over the same library — then a live run takes a couple of minutes, because it's real work, not a scripted animation. Output stays watermarked until you subscribe; the trial itself is never gated.
CPS 230 operational resilience and CPS 234 information security posture from live evidence — board and regulator packs, material-supplier registers, no false green. The engine is the evidence layer; it does not replace an APRA-appointed tripartite reviewer.
Tier-A breadthGeneral, life and private health insurers assess CPS 230 operational resilience and CPS 234 information security from one evidence base — claims, policy administration and payments as critical operations, with regulator-ready packs. Never a false green.
Tier-A breadthRSE licensees meet CPS 230 and CPS 234 from one evidence base, with the register and fourth-party transparency that heavy outsourcing — administration, custody, investment — demands: evidenced contract clauses, board packs, no false green.
IRAP-grade on Essential EightGet cyber-compliant on real evidence, not a checklist: Essential Eight maturity and an evidence pack that satisfies a customer, a tender or a cyber insurer — in a sub-$5k SMB lane. Readiness, never a fake pass.
Consultant-grade depthISM/IRAP assessment at the depth an IRAP assessor documents — the full ISM catalogue with SAR generation, Essential Eight across ML1–ML3, evidence mapped control by control. Australia's real moat.
Depth badged per laneEvery framework live on the engine, one book of work: per-engagement scoping, evidence freshness measured — not asserted — and reports carrying an Evidence Freshness Statement. IRAP-grade on ISM/E8, Tier-A breadth elsewhere.
Tier-A breadthMulti-jurisdiction AI governance from one evidence base — EU AI Act, ISO/IEC 42001, NIST AI RMF, plus every national instrument live on the catalogue, enumerated on the solutions page rather than promised. The one axis where our reach is already genuinely global.
Served via security lensOAIC breach duties and buyer security clauses served through ISO 27001, SOC 2, Essential Eight and third-party risk. Honest position: no dedicated health-sector catalogue on the engine today — we say that plainly rather than badge it green.
Served via existing lanesSOCI risk-management-program obligations served through Essential Eight maturity, ISM depth and third-party risk registers. Honest position: no dedicated SOCI catalogue yet — where an obligation is not covered, the posture says so.
Tier-A breadthA standalone third-party risk register: criticality tiering, honest 0–100 exposure scoring (an unassessed supplier is never green), service concentration and fourth-party contagion, due-diligence questionnaires and a board / auditor portfolio report.
Tier-A breadthA curated, source-cited obligation set for Australian schools — student privacy, cyber controls, notifiable breaches, child safety and EdTech vendor risk — with every obligation stating the sector and jurisdiction it actually binds.
Tier-A breadthA curated, source-cited obligation set for Australian early childhood services — the Education and Care Services National Law, notification clocks, records and retention, the February 2026 device and image provisions, privacy and child safety — with every obligation stating not just who it binds but which states it is actually in force in.
Tier-A breadthA standalone CPS 230 / CPS 234 console: the entity self-assesses the curated obligation set with evidence, and — for the obligations that flow down to material providers — sees which providers already evidence them (prove-once). Never a false green.
Not a bank, not an agency, not a hospital? The engine is framework-driven, not industry-templated. If your obligations map to the frameworks live on the catalogue, the same machinery serves you — and if they don't, we say so and it goes on the roadmap, not on your report.
Locked founder pricing, a direct line to the founder, and real roadmap input. We build the case studies together — that's the deal.
Every report carries a validation run id and a SHA-256 integrity anchor chained into a tamper-evident ledger — auditors, regulators and your clients can verify a CyberSentien report is genuine and unmodified. No logo proves that.
Coverage is measured against full catalogues; controls without evidence say “manual assessment required”, never a fabricated pass. The same rule governs this website: every framework, control and obligation count here was read from the engine when the site was built.
Approved provider or centre director
National Law obligations gated to your state, notification clocks, records and retention.
Principal, business manager or board
195 source-cited school obligations, each stating the sector and jurisdiction it binds.
Owner, office manager or MSP
Essential Eight maturity and an SMB readiness ladder from real evidence.
Practice running multiple clients
The multi-client practice view — assess, evidence and report across your book.
CRO, risk or compliance
CPS 230 and CPS 234 obligations, critical operations and material service providers.
CyberSentien is an Australian-owned compliance assurance platform that assesses an organisation once against its real evidence and reports across many frameworks — Essential Eight, ISM (IRAP-aligned depth), APRA CPS 230 and CPS 234, and AI governance — and maps that same evidence to ISO 27001, SOC 2 and ISO 42001 readiness. It produces deterministic verdicts with per-control evidence chains and tamper-evident report lineage.
No. CyberSentien (CyberSentien Pty Ltd, ACN 688 655 334, New South Wales) is a separate Australian compliance-assurance software company. It is not affiliated with CyberSentience, a New Zealand threat-intelligence firm, or with CyberSentriq. The correct spelling is “CyberSentien” and the website is cybersentien.com.
Essential Eight (with ML1–ML3 maturity), the ISM at IRAP-aligned depth, and APRA CPS 230 and CPS 234, plus AI-governance frameworks including the NSW AI Assessment Framework, QLD FAIRA, NIST AI RMF and the EU AI Act. For ISO/IEC 27001, SOC 2 and ISO 42001 it maps your evidence to a readiness/crosswalk view — not an independent certification: CyberSentien gets you audit-ready, and an accredited certifier issues the certificate.
For licensed engagements: on Australian-sovereign infrastructure, with no third-party AI API. The public evaluation demo is the one exception, and the engine says so itself: demo answers are generated OUTSIDE Australia on third-party GPU infrastructure (the specific country varies with provider capacity), and every one of them carries an on-screen disclosure saying so. No customer evidence is processed there — licensed engagements run exclusively on Australian-sovereign compute. Evidence stays inside the boundary. Retention follows the engagement policy; tenant owners can obtain an integrity-manifested export before deletion, and legal holds fail closed — the reason sovereignty is the platform's first design principle.
Four platform tiers, plus per-school and per-service sector lanes. Billed annually or monthly in AUD (annual is the cheaper way to buy): Core from $6,000, Professional from $18,000, Enterprise from $48,000 and Sovereign from $85,000. All subscriptions are prepaid — cancel any time and you keep access to the end of the period you have paid for. Pricing scales with framework breadth and deployment model; the gated demo is free and requires no documents of your own.
It never shows a false green. Controls without evidence read “manual assessment required” rather than a fabricated pass, coverage is measured against full catalogues, and every report carries a validation run id and a SHA-256 integrity anchor an auditor or regulator can verify independently.
A working demo on live machinery — not slides. Tell us where you sit and we'll send a gated, revocable demo link.