Trust centre

What protects your evidence, who can reach it, where it runs, and what we have not done yet. Every statement on this page was verified against the running system, and anything we cannot demonstrate is listed as outstanding rather than left out.

Last full verification 11 August 2026 · the processing-location statement below was corrected and re-verified on 21 August 2026, after inference moved onto each deployment's own box · questions: compliance@cybersentien.com

The entity

🏢 Who you contract with

CyberSentien · ACN 688 655 334 · Sydney, NSW, Australia. An Australian company, Australian-owned, contracting under Australian law.

✉ Security & privacy contact

compliance@cybersentien.com · vulnerability reports via our security.txt. Contractual notices are served by email — see the DPA note below.

At a glance

ControlStatus
Encryption at restAES-256-GCM envelope encryption. A per-file data key is wrapped by a versioned key ring, so a key can be rotated without making existing evidence unreadable.
Encryption in transitHTTPS/TLS everywhere; HSTS enabled on the engine host.
Evidence integrityEvery accepted artefact is timestamped and SHA-256-lineaged; issued reports carry an integrity anchor a third party can verify without an account.
Audit logAppend-only and hash-chained, so an altered or removed entry breaks the chain.
BackupsTwo layers: daily application backups (encrypted, hash-chained manifests, weekly deep verification) and daily full-disk backups taken by our hosting provider. Both are held within Australia — see Backups below for the limit.
Restore testingA full restore into an isolated target was executed and verified on production on 11 August 2026. Before that date we had never proven a restore, and said so.
Production accessA single administrator key. No shared logins, no vendor access.
Independent certificationNone held. No ISO 27001, no SOC 2, no IRAP assessment of ourselves. Roadmap, never claimed.

Where your data runs

Licensed engagements run on Australian-sovereign infrastructure under Australian ownership, with the AI inside that boundary rather than a third-party AI API.

That now includes the public demo. Demo answers are generated on the demo box's own CPU in Australia, inside the same boundary, with no third-party AI API. The engine reports the lane that actually served an answer at /api/ai-statement — ask it rather than taking this page's word for it. Full detail on the sovereignty page.

Sub-processors

The complete list. A sub-processor register that omits the inconvenient entry is worse than none, because it is the one a reviewer will find.
Sub-processorPurpose & location
BinaryLaneEngine hosting. Australian provider, Australian infrastructure.
RenderStatic hosting for this marketing website. No customer evidence is stored here.
RunPodDormant — no longer processes anything. Previously supplied GPU capacity for public demo answers. Since August 2026 every deployment, demo included, generates on its own Australian box, and no traffic is routed here.
CloudflareCDN and TLS termination for this static marketing website. Sees requests to cybersentien.com only — the lead form and the engine bypass it entirely and terminate in Australia. No customer evidence passes through it.
Microsoft 365Business email for enquiries and correspondence.
StripeCard payments for subscriptions and single-report purchases. Checkout runs on Stripe’s own hosted page — card details are entered there and never reach CyberSentien systems. What transits Stripe is the buyer’s email address, the billing name and address Stripe collects, the organisation name if given, and which plan or report is being bought. No client evidence, assessment content or report text is sent. Stripe processes payment data on its own infrastructure, which includes recipients outside Australia.
GoDaddyDomain registration and DNS for cybersentien.com — the record of where the domain points, and the nameservers that answer that question for visitors. It hosts nothing: no engine, no website content, no customer evidence and no assessment data passes through it.

Backups and recovery — stated precisely

✅ Application backups

Daily, encrypted, carrying hash-chained manifests so a tampered or missing archive is detectable, with a deep verification weekly. On 11 August 2026 a full restore was executed into an isolated target and verified end to end.

✅ Whole-server backups

Our Australian hosting provider also takes a daily full-disk backup of the server, held separately from the running machine and restorable independently of anything we run. So the loss of the server itself is a recoverable event, not a terminal one.

⚠ The limit, stated plainly

Both layers are held within the same Australian facility as the server. That covers server failure, corruption and accidental deletion. It does not cover the loss of the facility itself. A geographically separate Australian copy is the next item of work, and we will not describe our recovery position as complete until it exists.

What we have not done yet

The section most vendors leave out. If any of these is a blocker for your procurement, tell us and we will say honestly whether and when it changes.

📜 No independent certification

We hold no ISO 27001 certificate, no SOC 2 report and no IRAP assessment of our own platform. We build tooling that prepares organisations for those assessments; we have not yet completed one for ourselves, and we will not imply otherwise.

💾 No geographically separate backup copy

Two independent backup layers exist and both are in Australia, but both sit in the same facility as the server. A second-location copy is in progress, and stated here rather than buried.

👥 No penetration test report to share

The platform has been adversarially audited in depth internally, and the findings drove real fixes. That is not the same as an independent third-party penetration test, and we do not present it as one.

🌐 Single-region, single-host today

The engine runs on one Australian host. There is no multi-region failover and no published uptime SLA. For engagements where that matters, talk to us — a deployment model beyond a dedicated Australian box is scoped and quoted per engagement.

Data processing agreement

A DPA is available on request from compliance@cybersentien.com. Because we publish no street address or telephone number, contractual notices under that agreement are served by email to the addresses named in the executed document. Australian law; Australian jurisdiction.

Reporting a vulnerability

Email compliance@cybersentien.com, or use the contact in our security.txt. We will acknowledge, investigate, and tell you what we found — including when the answer is that you were right. We do not pursue researchers who report in good faith.

🔎 Verify it rather than trust it

The demo is the real engine. Open it, try to make it show you a pass it cannot prove, and check a report's integrity anchor yourself.