Data protection and residency
- Australian data residency by default. We build in your own environment wherever possible, or in the Australian regions of Microsoft Azure, AWS or Google Cloud.
- For the most sensitive workloads we run open-weight models entirely inside your tenancy, on-premise or fully offline, so your data never leaves your control.
- Data is encrypted in transit and at rest. We use only the data each use case needs and work with de-identified or synthetic data where practical.
- At the end of an engagement we return or securely delete your data and confirm this in writing.
Access control
- Least-privilege, named access provisioned by your team, with multi-factor authentication on every account we use.
- Separate credentials and environments for every client. Secrets live in managed secret stores, never in source code.
- All access is removed when the engagement ends.
People
Every engagement is led by our principal and staffed with the relevant professionals your goal requires. Everyone who works on your engagement is bound by confidentiality obligations at least as strict as those in our agreement with you, and you can ask who will have access to your data before work begins.
Third-party services
- We only use enterprise or API services whose terms prohibit training on your data.
- Any third-party service that will process your data is named in your statement of work for your approval before work begins.
- Our designs are model-agnostic, so you can change providers without rebuilding.
AI governance
Every system we deliver is governed against the six essential practices in Australia's Guidance for AI Adoption and documented in a way that maps to ISO/IEC 42001:
- Decide who is accountable. A named owner for each AI system, its risks and its outcomes.
- Understand impacts and plan accordingly. An impact assessment for the people and decisions each system affects.
- Measure and manage risks. A risk register with controls, tested before go-live.
- Share essential information. System documentation, and support for disclosures you need to make, including automated decision-making disclosures under the Privacy Act.
- Test and monitor. Evaluation suites before release, and monitoring for quality, drift and misuse after it.
- Maintain human control. Human approval for high-impact decisions, with clear override and shutdown paths.
Secure delivery
- Threat modelling for every AI system, including the risks in the OWASP Top 10 for LLM Applications such as prompt injection and excessive agency.
- Code review, dependency scanning and secret scanning on every change.
- Audit logging of automated actions, retained in your environment.
- Security controls designed with the ASD Essential Eight in mind.
Confidentiality and intellectual property
- A mutual non-disclosure agreement before discovery begins.
- Deliverables and source code created for you are assigned to you on payment.
- We keep our pre-existing tools and methods and grant you a perpetual licence to any that are embedded in your solution.
Vulnerability disclosure
If you believe you have found a security vulnerability in our website or systems, email security@sovereignsystemslabs.com with enough detail for us to reproduce it. We acknowledge reports within two business days.
Please do not access or change data beyond what is needed to demonstrate the issue, do not degrade our services, and give us reasonable time to fix the issue before disclosing it. We will not pursue action against people who report in good faith and follow this policy. Our security.txt has the same details.
Documentation for your review
On request, and under NDA, we provide completed security questionnaires, our standard terms and a data handling summary specific to your engagement. Email contact@sovereignsystemslabs.com and tell us what your procurement process needs.