Compliance you can put your name to

CyberSentien is an Australian governance, risk and compliance platform for organisations that have to prove something to somebody — a regulator, a board, an insurer, a client. We turn the evidence you already hold into a defensible position against the obligations that actually bind you, and we say so plainly when the evidence is not there.

Why we exist

Compliance tooling has a credibility problem: it is very good at producing green. Dashboards fill in, percentages climb, and nobody can tell you which numbers are backed by anything. Then a regulator, an auditor or an incident asks the only question that matters — show me — and the position collapses.

We built CyberSentien the other way round. Every conclusion starts from a piece of evidence with a date and a hash. A control with nothing behind it says so. It makes for a less flattering first screen and a much better second meeting.

What we do

Assess against what binds you

Curated, source-cited obligation sets — the ASD Essential Eight, the ISM at IRAP depth, APRA CPS 230 and CPS 234, and sector packs for Australian schools and early childhood services. Every obligation states the sector and jurisdiction it applies to, because in Australia those differ and a duty shown to the wrong organisation is worse than no duty at all.

Collect the evidence, not the questionnaire

Read-only connectors pull real signals from the systems you already run. Microsoft 365 is the deep, live connection today; every other connector in the registered fleet carries its real lifecycle status, and nothing is badged live until data has actually been pulled — alongside the documents you upload. Evidence is dated on its own currency date, so nothing counts as fresh because it was uploaded today.

Produce something defensible

Board packs, regulator-facing reports and evidence bundles, each carrying a validation run id and a SHA-256 integrity anchor chained into a tamper-evident ledger. A recipient can verify a CyberSentien report is genuine and unmodified without taking our word for it.

How we work

We assess, at depth

Essential Eight ML1–ML3, the ISM at IRAP-aligned depth, CPS 230/234, and our curated sector packs. How we assess →

We map to readiness — we don't certify

For ISO/IEC 27001, SOC 2 and ISO 42001 we map your evidence to a readiness view and get you audit-ready. An accredited certifier issues the certificate. We are not that, and we don't imply we are.

We never fake a pass

A control without evidence reads “manual assessment required”. An obligation that has not commenced in your state is shown as not binding, not as a gap. A compliance vendor that overstates its own compliance can't be trusted to grade yours.

Sovereignty

Built in Australia and hosted on Australian-sovereign infrastructure. For a licensed engagement your evidence stays onshore under Australian jurisdiction, and the AI that assists assessment runs inside that boundary — there is no third-party AI API in the loop. Every deployment, including the public demo, generates its answers on its own box — Australian-hosted, inside the deployment boundary, with no third-party AI API in the loop. The engine states its own processing location on request, and you can check it: /api/ai-statement reports the lane that actually served your answer (rather than the one we would like to claim). Licensed engagements run exclusively on Australian-sovereign compute. Read the full position →

Who runs it

CyberSentien is founded and led by Aneis Samaan, Founder & Managing Director. If you are evaluating us, you will deal with him directly.

Company details

Legal entityCyberSentien Pty Ltd
ACN688 655 334
RegisteredNew South Wales, Australia
Established2 July 2025
Contactsales@cybersentien.com

See it on the real engine

A working demo on live machinery — synthetic sample documents, watermarked outputs, nothing of yours uploaded or retained.

Try the live demo →Talk to us