Songlines Control is built for the most highly regulated environments in Australia — government, defence, financial services, and critical infrastructure. Every architectural decision reflects that.
Unlike platforms that treat security as an add-on, Songlines Control ships with all critical governance controls enabled out of the box. Administrators can configure, not compromise.
All data processed through our managed SaaS platform remains entirely within Australia. No offshore routing, processing, or storage — guaranteed.
Every request is authenticated, authorised, and evaluated against enterprise policy before execution. Least-privilege access enforced at every layer.
All records are cryptographically signed using SHA-256 and HMAC. Records cannot be modified or deleted — providing tamper-evident logs for regulatory submissions.
PII, PHI, and sensitive corporate data are automatically detected and redacted at the edge. Sensitive information never reaches external AI models.
Granular RBAC with per-user AI spend attribution. Admins, users, and service accounts each have precisely scoped permissions — nothing more.
Deploy as Managed SaaS (Australian region), Private Cloud / VPC, or fully air-gapped on-premise. The same control plane, any environment.
Every AI interaction — request, model selection, policy decision, token count, cost, and outcome — is recorded in a tamper-evident log. The audit trail is ISO 27001 aligned and IRAP-ready for Australian government compliance requirements.
Songlines Control is designed to support compliance across the frameworks that matter most to Australian enterprise and government organisations.
We welcome responsible disclosure from the security community. If you believe you have discovered a security vulnerability in our platform, please contact our security team at security@cetusai.com.au. We will acknowledge receipt within 24 hours and respond with a remediation timeline within 72 hours.