Four systems agree. Then the AI acts.
Most AI platforms ship the model and ask you to trust the output. XIntelliSync built the verification engine alongside it. Every AI action on your business passes through four independent systems — or it halts and tells you why.
AES-256
Encryption at rest
TLS 1.3
Encryption in transit
24 / 7
Security monitoring
90-day
Audit log retention
Your data. Your rules. No exceptions.
The commitments that matter most to legal teams, CFOs, and compliance officers — in plain language, backed by contract.
Your data never trains our AI
Not now. Not ever. No data you submit — financial records, customer data, documents — is used to train, fine-tune, or improve any AI model. This is a contractual commitment, not a policy aspiration.
Every AI decision is cryptographically verified
Each AI analysis step is captured in a tamper-evident flight record, sealed with SHA-256. If a single byte changes after the fact, verification fails visibly. Enterprise customers can download and verify their full AI audit history at any time.
You own every output
Every report, insight, forecast, and document generated using your data belongs to your business. XIntelliSync asserts no intellectual property claim over AI-generated outputs produced within your account.
Three-tier redaction for Privacy Act compliance
One AI record, three sharing levels: full detail for your operators, redacted for support teams, and customer-safe exports for Privacy Act APP 12 data access requests — each separately hashed and verifiable.
Enterprise AI Accountability — Cryptographic Audit Trail
Enterprise tier customers get access to the full AI Accountability Centre: downloadable SHA-256 verified flight records for every AI analysis, chain-of-custody logs, three-tier redacted export packs for Privacy Act APP 12 data access requests, and support ticket bundles with tamper-proof integrity verification. This is available under your account at /enterprise/trust-center.
Built on certified infrastructure. Designed for Australian law.
Compliance isn't a checkbox. It's the architecture.
Australian Privacy Act 1988
AlignedAPP-aligned controls across all 13 Australian Privacy Principles, including cross-border disclosure safeguards (APP 8), security obligations (APP 11), and access/correction rights (APP 12).
Notifiable Data Breaches Scheme
OperationalDocumented incident response procedures aligned with OAIC notification requirements, including customer notification workflows for eligible data breaches likely to cause serious harm.
SOC 2 Type II
Partner CertifiedCore infrastructure operates on SOC 2 Type II certified partner platforms covering security, availability, and confidentiality trust service criteria.
ISO 27001
Partner CertifiedNetwork security and global infrastructure managed through ISO 27001 certified partner infrastructure, covering information security management systems.
PCI DSS Level 1
Partner CertifiedAll payment processing is handled by a PCI DSS Level 1 certified payments partner. No raw card data ever touches XIntelliSync systems.
ACSC Essential Eight
AlignedSecurity practices aligned with the Australian Cyber Security Centre Essential Eight framework, including application hardening, MFA, access restriction, and backup controls.
OWASP Top 10
ProtectedApplication security controls are designed to address OWASP Top 10 risk categories including injection, broken authentication, and security misconfiguration.
GDPR-Aware
DesignedData subject request handling, consent-aware flows, and data processing transparency implemented for XIntelliSync customers with international users or EU operations.
Certifications marked "Partner Certified" are held by the specialist infrastructure partners that underpin specific services within the XIntelliSync platform, covering those respective services. XIntelliSync AI Pty Ltd implements security controls aligned with these frameworks and maintains an Australian-first privacy program under the Privacy Act 1988 (Cth).
Eight layers between your data and the world.
AES-256 Encryption at Rest
All business data encrypted at rest using AES-256 — the same standard used by financial institutions and government agencies.
TLS 1.3 Encryption in Transit
Every connection between your browser and our platform is encrypted using TLS 1.3. No data travels unencrypted.
Zero-Trust Access Model
No user, system, or service is trusted by default. Every access request is verified, scoped to least privilege, and logged.
Multi-Factor Authentication
MFA available on all plans. Enterprise tier supports SAML SSO and SCIM directory sync for centralised identity management.
Role-Based Access Control
Granular permissions ensure team members can only access what their role requires. Access is reviewed and deprovisioned immediately on offboarding.
Immutable Audit Trails
Every data access, admin action, and system event is logged in append-only audit trails. Logs are retained for 90 days on standard plans.
Automated Backups
Daily automated backups with encrypted storage and defined retention. Recovery procedures are documented and exercised as part of operational readiness.
Continuous Security Monitoring
Continuous automated monitoring and alerting across production systems, with escalation procedures for anomaly detection and incident response.
Australian-first data handling. Australian legal posture. Clear control.
XIntelliSync operates with an Australian-first hosting and privacy posture. Primary business data is intended to remain within Australian-hosted systems, with any required external subprocessors handled under documented Privacy Act safeguards and contractual controls. For businesses with APRA obligations, ASX reporting requirements, or APP cross-border disclosure concerns, that control model matters.
- Australian-first hosting and data handling policy
- APP 8 cross-border disclosure safeguards documented for external subprocessors
- Privacy Act 1988 obligations documented and maintained
- OAIC complaint-path support where required by law
- Data subject access requests supported (APP 12)
Data Return on Cancellation
Full export available from account settings
Permanent Data Deletion
After account closure — deletion certificate on request (Enterprise)
Audit Log Retention
Standard plans. Extended retention available Enterprise tier
Backup Retention
Point-in-time recovery. Encrypted backup storage.
Breach Notification
Handled under applicable Privacy Act and NDB obligations
Your procurement team has questions. We have the documentation.
Security questionnaires, DPAs, SOC 2 reports, and a direct line to our security team — on request, under NDA where required.
Security Overview
A non-confidential security overview document covering architecture, controls, certifications, and data handling practices.
Request OverviewData Processing Addendum
Our DPA covers GDPR Article 28 obligations, subprocessor commitments, Privacy Act requirements, and breach notification timelines.
Request DPASOC 2 Report Access
Third-party attestation reports from our infrastructure partners are available under NDA for qualified enterprise reviewers.
Request ReportSecurity Team — Direct Line
For vulnerability disclosure, security questionnaires, APRA CPS 234 inquiries, or to book a security briefing with our team.
Questions legal teams actually ask.
Plain answers. No hedging.
The back-office OS your legal team will actually sign off on.
Australian-built. APP-aligned. AI-accountable. 150 agents. One platform your CFO, legal team, and operations team can all get behind.
XIntelliSync AI Pty Ltd · Sydney, Australia 🇦🇺 · Privacy Policy · Security · Terms