What protects your evidence, who can reach it, where it runs, and what we have not done yet. Every statement on this page was verified against the running system, and anything we cannot demonstrate is listed as outstanding rather than left out.
Last verified 11 August 2026 · questions: compliance@cybersentien.com
CyberSentien · ACN 688 655 334 · Sydney, NSW, Australia. An Australian company, Australian-owned, contracting under Australian law.
compliance@cybersentien.com · vulnerability reports via our security.txt. Contractual notices are served by email — see the DPA note below.
| Control | Status |
|---|---|
| Encryption at rest | AES-256-GCM envelope encryption. A per-file data key is wrapped by a versioned key ring, so a key can be rotated without making existing evidence unreadable. |
| Encryption in transit | HTTPS/TLS everywhere; HSTS enabled on the engine host. |
| Evidence integrity | Every accepted artefact is timestamped and SHA-256-lineaged; issued reports carry an integrity anchor a third party can verify without an account. |
| Audit log | Append-only and hash-chained, so an altered or removed entry breaks the chain. |
| Backups | Daily, encrypted, with hash-chained manifests and a weekly deep verification. Currently stored on the same host — see Backups below. |
| Restore testing | A full restore into an isolated target was executed and verified on production on 11 August 2026. Before that date we had never proven a restore, and said so. |
| Production access | A single administrator key. No shared logins, no vendor access. |
| Independent certification | None held. No ISO 27001, no SOC 2, no IRAP assessment of ourselves. Roadmap, never claimed. |
Licensed engagements run on Australian-sovereign infrastructure under Australian ownership, with the AI inside that boundary rather than a third-party AI API.
The public evaluation demo is the one exception, and we state it everywhere it applies: demo answers are generated outside Australia on third-party GPU capacity, and each carries an on-screen disclosure. No customer evidence is processed there — the demo runs on synthetic sample documents. Full detail on the sovereignty page.
| Sub-processor | Purpose & location |
|---|---|
| BinaryLane | Engine hosting. Australian provider, Australian infrastructure. |
| Render | Static hosting for this marketing website. No customer evidence is stored here. |
| RunPod | GPU capacity for public demo AI answers only — outside Australia, with the specific country varying by provider capacity. Never used for licensed engagements or customer evidence. |
| Microsoft 365 | Business email for enquiries and correspondence. |
| GoDaddy | DNS for cybersentien.com. |
Backups run daily, are encrypted, and carry hash-chained manifests so a tampered or missing archive is detectable. A deep verification runs weekly. On 11 August 2026 a full restore was executed into an isolated target and verified end to end.
Backups are currently held on the same host as the data they protect. They defend against corruption and accidental deletion; they do not yet defend against loss of the host itself. Off-site replication to a second Australian location is the next item of work, and we will not describe our recovery position as complete until it is done.
We hold no ISO 27001 certificate, no SOC 2 report and no IRAP assessment of our own platform. We build tooling that prepares organisations for those assessments; we have not yet completed one for ourselves, and we will not imply otherwise.
As above. In progress, and stated here rather than buried.
The platform has been adversarially audited in depth internally, and the findings drove real fixes. That is not the same as an independent third-party penetration test, and we do not present it as one.
The engine runs on one Australian host. There is no multi-region failover and no published uptime SLA. For engagements where that matters, the Sovereign tier is a dedicated deployment inside your own boundary.
A DPA is available on request from compliance@cybersentien.com. Because we publish no street address or telephone number, contractual notices under that agreement are served by email to the addresses named in the executed document. Australian law; Australian jurisdiction.
Email compliance@cybersentien.com, or use the contact in our security.txt. We will acknowledge, investigate, and tell you what we found — including when the answer is that you were right. We do not pursue researchers who report in good faith.
The demo is the real engine. Open it, try to make it show you a pass it cannot prove, and check a report's integrity anchor yourself.