Cetus AI Announces Comprehensive Security Hardening for Songlines Control Platform
Australian enterprise AI governance platform strengthens zero-trust architecture with SSRF prevention, tenant isolation, and session hardening controls
BRISBANE, AUSTRALIA — Cetus AI, the Australian developer of the Songlines Control enterprise AI governance platform, today announced the completion of a comprehensive security review and hardening programme across its platform. The enhancements address emerging threat vectors specific to enterprise AI deployments and reinforce the platform's suitability for government, financial services, and critical infrastructure environments.
The security hardening, completed in July 2026, introduces six new controls verified through internal penetration testing and code review. No critical vulnerabilities were identified during the assessment.
New Security Controls
| Control | Description |
|---|---|
| SSRF Prevention | Removed arbitrary upstream URL routing. Only 5 allowlisted AI providers are accepted. |
| Endpoint Authentication | All scheduled and internal endpoints now require valid session authentication. |
| Org Enumeration Prevention | Public-facing portal URLs use randomised organisation slugs instead of sequential numeric IDs. |
| Session Duration | Default session lifetime reduced from 12 months to 30 days with mandatory re-authentication. |
| Header Allowlist | Gateway proxy forwards only 5 explicitly approved headers to upstream providers. |
| Tenant Isolation | API keys and data queries enforce dual-scope filtering (userId + orgId) at the database layer. |
Platform Context
These enhancements complement the existing security architecture of Songlines Control, which includes sovereign Australian infrastructure, PII auto-redaction, prompt injection prevention, human-in-the-loop approval workflows, and an immutable cryptographically signed audit trail.
Songlines Control is available on the Microsoft Azure Marketplace and is designed to support compliance with ISO 27001, ISO 42001, the Australian Government Information Security Manual (ISM), the Essential Eight maturity model, the Privacy Act 1988, the Australian Public Service AI Policy 2024, and AASB S2 climate disclosure requirements.
Executive Commentary
“Enterprise AI platforms are increasingly targeted by sophisticated threat actors who understand that a single compromised AI gateway can expose an entire organisation's intellectual property and sensitive data,” said Mark Kelly, Founder and CEO of Cetus AI. “These hardening measures reflect our commitment to maintaining the security posture that regulated Australian organisations require — not as a response to an incident, but as a proactive investment in platform integrity.”
Availability
The security enhancements are live across all Songlines Control deployments as of July 2026. No customer action is required. Full details are available on the Cetus AI Trust & Security page.