What protects your evidence, who can reach it, where it runs, and what we have not done yet. Every statement on this page was verified against the running system, and anything we cannot demonstrate is listed as outstanding rather than left out.
Last full verification 11 August 2026 · the processing-location statement below was corrected and re-verified on 21 August 2026, after inference moved onto each deployment's own box · questions: compliance@cybersentien.com
CyberSentien · ACN 688 655 334 · Sydney, NSW, Australia. An Australian company, Australian-owned, contracting under Australian law.
compliance@cybersentien.com · vulnerability reports via our security.txt. Contractual notices are served by email — see the DPA note below.
| Control | Status |
|---|---|
| Encryption at rest | AES-256-GCM envelope encryption. A per-file data key is wrapped by a versioned key ring, so a key can be rotated without making existing evidence unreadable. |
| Encryption in transit | HTTPS/TLS everywhere; HSTS enabled on the engine host. |
| Evidence integrity | Every accepted artefact is timestamped and SHA-256-lineaged; issued reports carry an integrity anchor a third party can verify without an account. |
| Audit log | Append-only and hash-chained, so an altered or removed entry breaks the chain. |
| Backups | Two layers: daily application backups (encrypted, hash-chained manifests, weekly deep verification) and daily full-disk backups taken by our hosting provider. Both are held within Australia — see Backups below for the limit. |
| Restore testing | A full restore into an isolated target was executed and verified on production on 11 August 2026. Before that date we had never proven a restore, and said so. |
| Production access | A single administrator key. No shared logins, no vendor access. |
| Independent certification | None held. No ISO 27001, no SOC 2, no IRAP assessment of ourselves. Roadmap, never claimed. |
Licensed engagements run on Australian-sovereign infrastructure under Australian ownership, with the AI inside that boundary rather than a third-party AI API.
That now includes the public demo. Demo answers are generated on the demo box's own CPU in Australia, inside the same boundary, with no third-party AI API. The engine reports the lane that actually served an answer at /api/ai-statement — ask it rather than taking this page's word for it. Full detail on the sovereignty page.
| Sub-processor | Purpose & location |
|---|---|
| BinaryLane | Engine hosting. Australian provider, Australian infrastructure. |
| Render | Static hosting for this marketing website. No customer evidence is stored here. |
| RunPod | Dormant — no longer processes anything. Previously supplied GPU capacity for public demo answers. Since August 2026 every deployment, demo included, generates on its own Australian box, and no traffic is routed here. |
| Cloudflare | CDN and TLS termination for this static marketing website. Sees requests to cybersentien.com only — the lead form and the engine bypass it entirely and terminate in Australia. No customer evidence passes through it. |
| Microsoft 365 | Business email for enquiries and correspondence. |
| Stripe | Card payments for subscriptions and single-report purchases. Checkout runs on Stripe’s own hosted page — card details are entered there and never reach CyberSentien systems. What transits Stripe is the buyer’s email address, the billing name and address Stripe collects, the organisation name if given, and which plan or report is being bought. No client evidence, assessment content or report text is sent. Stripe processes payment data on its own infrastructure, which includes recipients outside Australia. |
| GoDaddy | Domain registration and DNS for cybersentien.com — the record of where the domain points, and the nameservers that answer that question for visitors. It hosts nothing: no engine, no website content, no customer evidence and no assessment data passes through it. |
Daily, encrypted, carrying hash-chained manifests so a tampered or missing archive is detectable, with a deep verification weekly. On 11 August 2026 a full restore was executed into an isolated target and verified end to end.
Our Australian hosting provider also takes a daily full-disk backup of the server, held separately from the running machine and restorable independently of anything we run. So the loss of the server itself is a recoverable event, not a terminal one.
Both layers are held within the same Australian facility as the server. That covers server failure, corruption and accidental deletion. It does not cover the loss of the facility itself. A geographically separate Australian copy is the next item of work, and we will not describe our recovery position as complete until it exists.
We hold no ISO 27001 certificate, no SOC 2 report and no IRAP assessment of our own platform. We build tooling that prepares organisations for those assessments; we have not yet completed one for ourselves, and we will not imply otherwise.
Two independent backup layers exist and both are in Australia, but both sit in the same facility as the server. A second-location copy is in progress, and stated here rather than buried.
The platform has been adversarially audited in depth internally, and the findings drove real fixes. That is not the same as an independent third-party penetration test, and we do not present it as one.
The engine runs on one Australian host. There is no multi-region failover and no published uptime SLA. For engagements where that matters, talk to us — a deployment model beyond a dedicated Australian box is scoped and quoted per engagement.
A DPA is available on request from compliance@cybersentien.com. Because we publish no street address or telephone number, contractual notices under that agreement are served by email to the addresses named in the executed document. Australian law; Australian jurisdiction.
Email compliance@cybersentien.com, or use the contact in our security.txt. We will acknowledge, investigate, and tell you what we found — including when the answer is that you were right. We do not pursue researchers who report in good faith.
The demo is the real engine. Open it, try to make it show you a pass it cannot prove, and check a report's integrity anchor yourself.