Newsroom

Press Releases & Announcements

Official announcements from Cetus AI on product updates, security advisories, partnerships, and company milestones.

7 August 2026 — For Immediate Release

Cetus AI Launches Founding University Partner Program for Australian Higher Education

Songlines Control® to be deployed at no cost to 3–5 Australian universities as Founding Partners, addressing the sector’s critical AI governance gap in academic integrity, research compliance, and sustainability reporting

BRISBANE, AUSTRALIA — Cetus AI, the Australian developer of the Songlines Control® enterprise AI governance platform, today announced the launch of its Founding University Partner Program — offering 3–5 Australian universities full platform access at no cost for 12 months to address the sector’s escalating AI governance crisis.

The announcement follows the release of a new white paper, AI Governance for Australian Universities: Why Higher Education Needs an Institutional AI Control Plane, which details how 53.6% of Australian tertiary submissions now contain AI-generated content, 94% of higher education staff use AI tools, and yet only 54% know whether their institution has a policy governing that use.

The Governance Gap

Australian universities face a unique convergence of regulatory pressure. TEQSA has signalled a shift to a regulatory-led framework from 2026. The ARC and NHMRC have jointly called for strengthened research integrity systems. Privacy Act reforms increase penalties for offshore data transfer. And from 2025, large entities — including the Group of Eight universities — must disclose climate-related financial risks under the Australian Sustainability Reporting Standards (ASRS).

“Policy without enforcement architecture is aspirational, not operational,” said Mark Austin, CEO of Cetus AI. “Universities need infrastructure that makes governance automatic — not dependent on individual compliance. That’s exactly what Songlines Control provides.”

What Founding Partners Receive

Founding Partners gain full access to the Songlines Control platform for 12 months, including:

Policy Engine — Course-level AI policies enforced automatically across all user types
Cost Attribution — Real-time AI spend tracking per faculty, school, and individual
PII Auto-Redaction — Student records and research participant data protected before AI processing
Data Sovereignty — All AI interactions remain in Australia (Azure AU East) by architecture
Reviewable Evidence Trail — Cryptographically signed logs for TEQSA compliance and ARC/NHMRC audits
Sustainability Module — AI carbon footprint tracking per department for ASRS reporting

Partnership Terms

The program is limited to 5 Founding Partners nationally. Ongoing commercial arrangements are discussed confidentially with each institution before the partnership period concludes, with no obligation to continue. In return, partners provide logo rights, participation in one joint case study, quarterly feedback sessions, and willingness to serve as a named reference.

Market Context

Australia has 43 universities with a combined student population exceeding 1.5 million and staff numbering over 130,000. The 2026–27 federal budget allocated $70 million in AI acceleration funding for the education sector, signalling government recognition that institutions need AI infrastructure — not just AI policies.

Songlines Control is available on the Microsoft Azure Marketplace and has commenced SOC 2 Type II certification. All data remains in Australia by architecture, not just by policy.

Resources

Download White Paper: AI Governance for Australian Universities (PDF)

Download Founding University Partner Program Overview (PDF)

Contact

Mark Austin, CEO
Cetus AI Pty Ltd
mark@cetusai.com.au
cetusai.com.au

3 August 2026 — For Immediate Release

Cetus AI Commences SOC 2 Type II Certification for Songlines Control Platform

Australian AI governance platform pursues gold-standard independent security certification, covering Security, Availability, and Confidentiality Trust Service Criteria

BRISBANE, AUSTRALIA — Cetus AI, the Australian developer of the Songlines Control® enterprise AI governance platform, today announced it has formally commenced the SOC 2 Type II certification process. The assessment covers the Security, Availability, and Confidentiality Trust Service Criteria — reflecting the standards expected by enterprise and government customers for AI governance platforms.

SOC 2 Type II is the gold standard for SaaS security assurance. Unlike a point-in-time assessment, it requires an extended observation period during which an independent auditor verifies that security controls are not merely designed — they are operating effectively, consistently, and without exception.

Why SOC 2 Matters for AI Governance

Organisations evaluating AI governance platforms face a fundamental trust question: how do I know the platform governing my AI is itself governed to the highest standard? Enterprise buyers, government procurement teams, and regulated industries are no longer satisfied with vendor self-attestation. They require independent evidence that the platforms handling their most sensitive operational data meet the same security standards they demand of their own systems.

Compliance Roadmap

Milestone Status Target
ISO 27001 Alignment Complete
Security Hardening Review Complete July 2026
Annual Penetration Testing (Third-Party, CREST-Accredited) ● Scheduled Q3 2026
SOC 2 Type I Assessment ● In Progress Q4 2026
SOC 2 Type II Observation Period ○ Planned Q1–Q2 2027

Controls Already in Place

Songlines Control® was architected with security-first principles from inception. The following controls are already operational and form the basis of the SOC 2 assessment:

  • Sovereign Infrastructure — All data processed and stored within Azure Australia East (Sydney, NSW). No offshore routing, processing, or storage.
  • Zero-Trust Architecture — Every request authenticated, authorised, and evaluated against enterprise policy before execution.
  • Tamper-Evident Records — Configured governance records can be cryptographically signed and maintained as append-only entries; coverage depends on connected sources, retention and privileged administration.
  • PII Auto-Redaction — Sensitive data automatically detected and redacted at the edge before reaching external AI models.
  • Tenant Isolation — All data queries scoped by both user identity and organisation ID at the database layer.
  • Encryption — AES-256 at rest, TLS 1.3 in transit. Australian-resident encryption keys.

Additional Security Commitments

Alongside this announcement, Cetus AI has published updated commitments on its Trust & Security page, including:

  • Australian Deployment Options — Data flows and residency boundaries are confirmed for each customer architecture and connected service.
  • Independent Penetration Testing — Annual testing by a CREST-accredited Australian security firm.
  • Incident Response SLA — Critical: 1-hour acknowledgement, 4-hour response, 24-hour resolution.
  • Responsible Disclosure Program — Formal vulnerability reporting policy with safe harbour for good-faith researchers.

Executive Commentary

“We believe that the platform responsible for governing an organisation's AI estate must itself be held to the highest standard of security, transparency, and accountability. SOC 2 Type II is not the ceiling — it is the baseline,” said Mark Austin, CEO of Cetus AI. “The question is not whether AI governance platforms need independent security certification. The question is why any organisation would trust a governance vendor that has not pursued it.”

Availability

Full details on Cetus AI's security posture, compliance roadmap, and incident response commitments are available on the Trust & Security page. The complete announcement document is available for download as a PDF.

Media Contact
Cetus AI Communications
media@cetusai.com.au
www.cetusai.com.au


About Cetus AI — Cetus AI is an Australian enterprise AI governance company headquartered in Brisbane, Queensland. Its flagship platform, Songlines Control®, helps organisations establish configured visibility, governance and enforcement across connected AI models and workflows. The platform is purpose-built for regulated industries including government, financial services, healthcare, and critical infrastructure, and is available on the Microsoft Azure Marketplace. ABN 16 695 570 819.
8 July 2026 — For Immediate Release

Cetus AI Announces Comprehensive Security Hardening for Songlines Control Platform

Australian enterprise AI governance platform strengthens zero-trust architecture with SSRF prevention, tenant isolation, and session hardening controls

BRISBANE, AUSTRALIA — Cetus AI, the Australian developer of the Songlines Control enterprise AI governance platform, today announced the completion of a comprehensive security review and hardening programme across its platform. The enhancements address emerging threat vectors specific to enterprise AI deployments and reinforce the platform's suitability for government, financial services, and critical infrastructure environments.

The security hardening, completed in July 2026, introduces six new controls verified through internal penetration testing and code review. No critical vulnerabilities were identified during the assessment.

New Security Controls

Control Description
SSRF Prevention Removed arbitrary upstream URL routing. Only 5 allowlisted AI providers are accepted.
Endpoint Authentication All scheduled and internal endpoints now require valid session authentication.
Org Enumeration Prevention Public-facing portal URLs use randomised organisation slugs instead of sequential numeric IDs.
Session Duration Default session lifetime reduced from 12 months to 30 days with mandatory re-authentication.
Header Allowlist Gateway proxy forwards only 5 explicitly approved headers to upstream providers.
Tenant Isolation API keys and data queries enforce dual-scope filtering (userId + orgId) at the database layer.

Platform Context

These enhancements complement the existing security architecture of Songlines Control, which includes sovereign Australian infrastructure, PII auto-redaction, prompt injection prevention, human-in-the-loop approval workflows, and an immutable cryptographically signed audit trail.

Songlines Control is available on the Microsoft Azure Marketplace and is designed to support compliance with ISO 27001, ISO 42001, the Australian Government Information Security Manual (ISM), the Essential Eight maturity model, the Privacy Act 1988, the Australian Public Service AI Policy 2024, and AASB S2 climate disclosure requirements.

Executive Commentary

“Enterprise AI platforms are increasingly targeted by sophisticated threat actors who understand that a single compromised AI gateway can expose an entire organisation's intellectual property and sensitive data,” said Mark Austin, CEO of Cetus AI. “These hardening measures reflect our commitment to maintaining the security posture that regulated Australian organisations require — not as a response to an incident, but as a proactive investment in platform integrity.”

Availability

The security enhancements are live across all Songlines Control deployments as of July 2026. No customer action is required. Full details are available on the Cetus AI Trust & Security page.

Media Contact
Cetus AI Communications
media@cetusai.com.au
www.cetusai.com.au


About Cetus AI — Cetus AI is an Australian enterprise AI governance company headquartered in Brisbane, Queensland. Its flagship platform, Songlines Control, helps organisations establish configured visibility, governance and enforcement across connected AI models and workflows. The platform is purpose-built for regulated industries including government, financial services, healthcare, and critical infrastructure, and is available on the Microsoft Azure Marketplace. ABN 16 695 570 819.