Trust centre

What protects your evidence, who can reach it, where it runs, and what we have not done yet. Every statement on this page was verified against the running system, and anything we cannot demonstrate is listed as outstanding rather than left out.

Last verified 11 August 2026 · questions: compliance@cybersentien.com

The entity

🏢 Who you contract with

CyberSentien · ACN 688 655 334 · Sydney, NSW, Australia. An Australian company, Australian-owned, contracting under Australian law.

✉ Security & privacy contact

compliance@cybersentien.com · vulnerability reports via our security.txt. Contractual notices are served by email — see the DPA note below.

At a glance

ControlStatus
Encryption at restAES-256-GCM envelope encryption. A per-file data key is wrapped by a versioned key ring, so a key can be rotated without making existing evidence unreadable.
Encryption in transitHTTPS/TLS everywhere; HSTS enabled on the engine host.
Evidence integrityEvery accepted artefact is timestamped and SHA-256-lineaged; issued reports carry an integrity anchor a third party can verify without an account.
Audit logAppend-only and hash-chained, so an altered or removed entry breaks the chain.
BackupsDaily, encrypted, with hash-chained manifests and a weekly deep verification. Currently stored on the same host — see Backups below.
Restore testingA full restore into an isolated target was executed and verified on production on 11 August 2026. Before that date we had never proven a restore, and said so.
Production accessA single administrator key. No shared logins, no vendor access.
Independent certificationNone held. No ISO 27001, no SOC 2, no IRAP assessment of ourselves. Roadmap, never claimed.

Where your data runs

Licensed engagements run on Australian-sovereign infrastructure under Australian ownership, with the AI inside that boundary rather than a third-party AI API.

The public evaluation demo is the one exception, and we state it everywhere it applies: demo answers are generated outside Australia on third-party GPU capacity, and each carries an on-screen disclosure. No customer evidence is processed there — the demo runs on synthetic sample documents. Full detail on the sovereignty page.

Sub-processors

The complete list. A sub-processor register that omits the inconvenient entry is worse than none, because it is the one a reviewer will find.
Sub-processorPurpose & location
BinaryLaneEngine hosting. Australian provider, Australian infrastructure.
RenderStatic hosting for this marketing website. No customer evidence is stored here.
RunPodGPU capacity for public demo AI answers only — outside Australia, with the specific country varying by provider capacity. Never used for licensed engagements or customer evidence.
Microsoft 365Business email for enquiries and correspondence.
GoDaddyDNS for cybersentien.com.

Backups and recovery — stated precisely

✅ What is true today

Backups run daily, are encrypted, and carry hash-chained manifests so a tampered or missing archive is detectable. A deep verification runs weekly. On 11 August 2026 a full restore was executed into an isolated target and verified end to end.

⚠ What is not true yet

Backups are currently held on the same host as the data they protect. They defend against corruption and accidental deletion; they do not yet defend against loss of the host itself. Off-site replication to a second Australian location is the next item of work, and we will not describe our recovery position as complete until it is done.

What we have not done yet

The section most vendors leave out. If any of these is a blocker for your procurement, tell us and we will say honestly whether and when it changes.

📜 No independent certification

We hold no ISO 27001 certificate, no SOC 2 report and no IRAP assessment of our own platform. We build tooling that prepares organisations for those assessments; we have not yet completed one for ourselves, and we will not imply otherwise.

💾 No off-site backup replication

As above. In progress, and stated here rather than buried.

👥 No penetration test report to share

The platform has been adversarially audited in depth internally, and the findings drove real fixes. That is not the same as an independent third-party penetration test, and we do not present it as one.

🌐 Single-region, single-host today

The engine runs on one Australian host. There is no multi-region failover and no published uptime SLA. For engagements where that matters, the Sovereign tier is a dedicated deployment inside your own boundary.

Data processing agreement

A DPA is available on request from compliance@cybersentien.com. Because we publish no street address or telephone number, contractual notices under that agreement are served by email to the addresses named in the executed document. Australian law; Australian jurisdiction.

Reporting a vulnerability

Email compliance@cybersentien.com, or use the contact in our security.txt. We will acknowledge, investigate, and tell you what we found — including when the answer is that you were right. We do not pursue researchers who report in good faith.

🔎 Verify it rather than trust it

The demo is the real engine. Open it, try to make it show you a pass it cannot prove, and check a report's integrity anchor yourself.