Platform
Platform Overview Observe Mode Enforce Mode Orchestrate Mode
Company
About Partners Contact
Resources
White Papers & Docs Blog ROI Calculator Pricing
▶ Try Live Demo Book a Session →
▶ Try Live Demo Book a Strategic AI Session →
Trust & Security

Security is Not a Feature.
It is the Foundation.

Songlines Control® is built for the most highly regulated environments in Australia — government, defence, financial services, and critical infrastructure. Every architectural decision reflects that.

Governance Controls — On by Default

Unlike platforms that treat security as an add-on, Songlines Control® ships with all critical governance controls enabled out of the box. Administrators can configure, not compromise.

Sovereign Mode
Enforce all AI traffic to sovereign-compliant endpoints only — no data leaves Australian jurisdiction
HITL Approval Workflows
Require human approval for high-risk AI operations before execution proceeds
PII Auto-Redaction
Automatically detect and redact personally identifiable information before sending to any model
Prompt Injection Prevention
Block prompt injection attempts in real time at the control layer — before they reach the model
Shadow AI Detection & Governance
Automatically discover unsanctioned AI tools across your organisation, score them for risk, and enforce policy rules — with employee self-service declaration and board-level reporting

Core Security Architecture

Sovereign Infrastructure

All data processed through our managed SaaS platform remains entirely within Australia. No offshore routing, processing, or storage — guaranteed.

Zero-Trust Architecture

Every request is authenticated, authorised, and evaluated against enterprise policy before execution. Least-privilege access enforced at every layer. Upstream AI provider requests are protected by a strict header allowlist — only safe, explicitly approved headers are forwarded. Internal metadata, cookies, and custom headers are stripped at the gateway.

Immutable Audit Trail

All records are cryptographically signed using SHA-256 and HMAC. Records cannot be modified or deleted — providing tamper-evident logs for regulatory submissions.

PII Auto-Redaction

PII, PHI, and sensitive corporate data are automatically detected and redacted at the edge. Sensitive information never reaches external AI models.

Role-Based Access Control

Granular RBAC with per-user AI spend attribution. Admins, users, and service accounts each have precisely scoped permissions — nothing more.

Flexible Deployment

Deploy as Managed SaaS (Australian region), Private Cloud / VPC, or fully air-gapped on-premise. The same control plane, any environment.

Header Allowlisting

Only explicitly approved headers (content-type, authorization, accept, user-agent, x-request-id) are forwarded to upstream AI providers. All other headers — including cookies, internal routing metadata, and custom headers — are stripped at the gateway layer before any external request is made.

Session Hardening

Session tokens expire after 30 days with automatic re-authentication required. Cookies are signed with HMAC-SHA256, scoped to the application domain, and set with HttpOnly, Secure, and SameSite=Lax attributes.

Tenant Isolation

All data queries are scoped by both user identity and organisation ID. API keys, telemetry events, policy rules, and audit logs are isolated at the database layer — preventing cross-tenant data leakage even in multi-organisation deployments.

Immutable Audit & Compliance Log

Every AI interaction — request, model selection, policy decision, token count, cost, and outcome — is recorded in a tamper-evident log. The audit trail is ISO 27001 aligned and audit-ready for Australian government compliance requirements.

Songlines Control® Audit & Compliance — immutable audit trail showing all AI interactions, policy decisions, and system events

Recent Security Hardening

In July 2026, Songlines Control® underwent a comprehensive security review. The following enhancements were implemented:

Control Description
SSRF Prevention Removed arbitrary upstream URL routing. Only 5 allowlisted AI providers are accepted.
Endpoint Authentication All scheduled and internal endpoints now require valid session authentication.
Org Enumeration Prevention Public-facing portal URLs use randomised organisation slugs instead of sequential numeric IDs.
Session Duration Default session lifetime reduced from 12 months to 30 days with mandatory re-authentication.
Header Allowlist Gateway proxy forwards only 5 explicitly approved headers to upstream providers.
Tenant Isolation API keys and data queries enforce dual-scope filtering (userId + orgId) at the database layer.

These controls were verified through internal penetration testing and code review. No critical vulnerabilities were identified.

Compliance & Regulatory Alignment

Songlines Control® is designed to support compliance across the frameworks that matter most to Australian enterprise and government organisations.

Vulnerability Disclosure

We welcome responsible disclosure from the security community. If you believe you have discovered a security vulnerability in our platform, please contact our security team at security@cetusai.com.au. We will acknowledge receipt within 24 hours and respond with a remediation timeline within 72 hours.