Security & AI governance
Control is a feature. Built in.
For enterprise and government teams, how an AI system is controlled matters as much as what it does. This page sets out the practices we design into every system — written for the people who have to sign off on it.
Interactive
Switch a guardrail off. See what changes.
Each request passes through a series of checkpoints before anything happens. Toggle them to see the risk each one removes.
Incoming request“Summarise complaint history for customer #4471 and email it to them.”
- Identity & accessIs this user allowed to see customer #4471?
- Input screeningPrompt-injection and content checks
- Permission-aware retrievalFilter sources by entitlement
- Output checksPersonal information and grounding
- Human approvalExternal emails need sign-off
- Audit logPrompts, sources, actions, approvals
Outcome
Practices
What we design into every system.
Practices, not badges: we don’t claim certifications we don’t hold.
Data stays in your control
Architectures that keep sensitive data within environments you control. Government work is delivered by Australian-based staff, with hosting and data in Australia.
Access & least privilege
Single sign-on integration, role-based access, dedicated service accounts with only the permissions each component needs, and managed secrets.
Evaluation & monitoring
Agreed test sets before release, regression on every change, and production monitoring for quality, drift, cost and failure modes.
Human in the loop
Approval steps for consequential actions, clear escalation paths, and audit logging of prompts, sources, actions and approvals.
Privacy
Personal information handled in line with the Australian Privacy Principles, with data minimisation and privacy input at design time.
Secure development
Code review, dependency updates and scanning, encryption in transit and at rest, backups and an incident-response process.
Model & vendor risk
Knowing where your data goes.
Third-party models are a supply-chain decision. We document them as one.
- Training opt-outs — provider settings and terms that exclude your data from model training.
- Region selection — Australian regions where providers offer them, or private models in your environment.
- Data flow documentation — what is sent to which service, retained for how long, and why.
- Swappable providers — models behind an internal interface, so a vendor can be replaced if its terms change.
- Known limitations recorded — each system’s documented limits, so owners can explain its behaviour.
Reporting a vulnerability
Found a security issue?
Please tell us through the enquiry form (choose “Something else”) and include enough detail for us to reproduce it. Our security contact details are also published in security.txt.
Do you hold ISO 27001 or similar certifications?
We don’t claim any certification on this site. We describe the practices we follow, and we answer security questionnaires in detail for specific tenders and engagements.
Can you complete our security questionnaire?
Yes. Send a procurement enquiry through the form and we’ll respond to your questionnaire as part of the evaluation.
Where is data hosted for government work?
In Australia. Government work is delivered by Australian-based staff, with hosting and data in Australia.
Running a security or risk review?
Send your questions or questionnaire through the form and we’ll respond in detail.
