Sovereign by design.
Nothing leaves the boundary.

When your evidence is sensitive, the first question isn't “is it accurate” — it's “where does it go”. For a licensed engagement, the answer is: nowhere. Every deployment, including the public demo, generates its answers on its own box — Australian-hosted, inside the deployment boundary, with no third-party AI API in the loop. The engine states its own processing location on request, and you can check it: /api/ai-statement reports the lane that actually served your answer (rather than the one we would like to claim). Licensed engagements run exclusively on Australian-sovereign compute. This page states exactly what that means, and exactly where the edges are.

Talk sovereignty with us →

The four commitments

🇦🇺 Australian-owned hosting

Paying clients run on Australian-sovereign infrastructure with Australian-owned hosting providers — AI inference included. Every paying client runs on their own dedicated box, with their evidence and AI-usage records inside it.

🧠 Local AI — no third-party AI API

For licensed engagements the AI that assists assessment runs inside the boundary. There is no OpenAI, no Anthropic, no cloud AI API in the loop — not for your evidence, and not even for the record that AI was used. If the local model is unavailable, AI answers fail closed rather than fall back to a cloud.

🗑 Customer-controlled retention

The public demo uses synthetic data. Licensed engagements retain evidence, findings, approvals and reports under the agreed policy so their lineage remains auditable. A tenant owner can create an integrity-manifested export before deletion; active legal holds and retained backups remain governed by the engagement and backup policies. Contact-form details are retained only to reply.

🔐 Tamper-evident lineage

Every report carries a validation run id and a SHA-256 integrity anchor chained into an append-only ledger. Change one character after issue and the chain breaks — so an auditor can prove a report is exactly what was issued.

The honest edge

Sovereignty claims deserve precision, so here is ours, stated plainly.

This website is static

The page you're reading was generated from the engine's catalogue data at build time and is served as plain files. The engine itself never runs in the public serving path — there is nothing here to breach.

The CDN boundary

If a global CDN fronts this marketing site, it fronts the static marketing edge ONLY: no customer evidence, no engine traffic and no assessment data ever transits it. Lead-form submissions can be routed to an Australian-terminated endpoint that bypasses the CDN entirely. We'd rather state the boundary than pretend it isn't there.

No third-party trackers, no external assets

No third-party analytics, no external fonts, no CDN JavaScript. We keep first-party, cookieless engagement analytics on our own Australian endpoint (see the Privacy Policy) and honour Do‑Not‑Track — so open your browser's network panel: every request is ours.

Certifications — stated as roadmap, never claimed

ROADMAP · IRAP assessment of our own hosting

We build to ISM-aligned practice and assess ourselves with our own engine, but our hosting has not undergone an IRAP assessment. It's on the roadmap; until it's done, you won't see the claim here.

ROADMAP · ISO/IEC 27001 certification

Our ISMS practices track ISO/IEC 27001, and certification of CyberSentien itself is a roadmap item — not a current claim. We hold the same line we hold for your controls: no evidence, no green.

ROADMAP · SOC 2 attestation

A SOC 2 Type II attestation for the hosted service is planned. Until an independent auditor signs it, it stays on this roadmap list.

Why say this at all? Because a compliance vendor that overstates its own compliance can't be trusted to grade yours. No false green — including about ourselves.

Put the sovereignty story in front of procurement

Run the gated demo, verify the sealed report, inspect the network panel. Then let's talk about your boundary.

Open the gated demo →Contact us →