Australian Business OS — Trust Centre

Four systems agree. Then the AI acts.

Most AI platforms ship the model and ask you to trust the output. XIntelliSync built the verification engine alongside it. Every AI action on your business passes through four independent systems — or it halts and tells you why.

IntelliX Omega · 29 layers · 388+ phases
Horizon · runtime supervision · never sleeps
XAVS · 10-dimension agent scoring
XGVS · 356+ gates · 34 compliance frameworks

AES-256

Encryption at rest

TLS 1.3

Encryption in transit

24 / 7

Security monitoring

90-day

Audit log retention

AI Governance

Your data. Your rules. No exceptions.

The commitments that matter most to legal teams, CFOs, and compliance officers — in plain language, backed by contract.

Your data never trains our AI

Not now. Not ever. No data you submit — financial records, customer data, documents — is used to train, fine-tune, or improve any AI model. This is a contractual commitment, not a policy aspiration.

Every AI decision is cryptographically verified

Each AI analysis step is captured in a tamper-evident flight record, sealed with SHA-256. If a single byte changes after the fact, verification fails visibly. Enterprise customers can download and verify their full AI audit history at any time.

You own every output

Every report, insight, forecast, and document generated using your data belongs to your business. XIntelliSync asserts no intellectual property claim over AI-generated outputs produced within your account.

Three-tier redaction for Privacy Act compliance

One AI record, three sharing levels: full detail for your operators, redacted for support teams, and customer-safe exports for Privacy Act APP 12 data access requests — each separately hashed and verifiable.

Enterprise AI Accountability — Cryptographic Audit Trail

Enterprise tier customers get access to the full AI Accountability Centre: downloadable SHA-256 verified flight records for every AI analysis, chain-of-custody logs, three-tier redacted export packs for Privacy Act APP 12 data access requests, and support ticket bundles with tamper-proof integrity verification. This is available under your account at /enterprise/trust-center.

Certifications & Compliance

Built on certified infrastructure. Designed for Australian law.

Compliance isn't a checkbox. It's the architecture.

Australian Privacy Act 1988

Aligned

APP-aligned controls across all 13 Australian Privacy Principles, including cross-border disclosure safeguards (APP 8), security obligations (APP 11), and access/correction rights (APP 12).

Notifiable Data Breaches Scheme

Operational

Documented incident response procedures aligned with OAIC notification requirements, including customer notification workflows for eligible data breaches likely to cause serious harm.

SOC 2 Type II

Partner Certified

Core infrastructure operates on SOC 2 Type II certified partner platforms covering security, availability, and confidentiality trust service criteria.

ISO 27001

Partner Certified

Network security and global infrastructure managed through ISO 27001 certified partner infrastructure, covering information security management systems.

PCI DSS Level 1

Partner Certified

All payment processing is handled by a PCI DSS Level 1 certified payments partner. No raw card data ever touches XIntelliSync systems.

ACSC Essential Eight

Aligned

Security practices aligned with the Australian Cyber Security Centre Essential Eight framework, including application hardening, MFA, access restriction, and backup controls.

OWASP Top 10

Protected

Application security controls are designed to address OWASP Top 10 risk categories including injection, broken authentication, and security misconfiguration.

GDPR-Aware

Designed

Data subject request handling, consent-aware flows, and data processing transparency implemented for XIntelliSync customers with international users or EU operations.

Certifications marked "Partner Certified" are held by the specialist infrastructure partners that underpin specific services within the XIntelliSync platform, covering those respective services. XIntelliSync AI Pty Ltd implements security controls aligned with these frameworks and maintains an Australian-first privacy program under the Privacy Act 1988 (Cth).

Security Architecture

Eight layers between your data and the world.

AES-256 Encryption at Rest

All business data encrypted at rest using AES-256 — the same standard used by financial institutions and government agencies.

TLS 1.3 Encryption in Transit

Every connection between your browser and our platform is encrypted using TLS 1.3. No data travels unencrypted.

Zero-Trust Access Model

No user, system, or service is trusted by default. Every access request is verified, scoped to least privilege, and logged.

Multi-Factor Authentication

MFA available on all plans. Enterprise tier supports SAML SSO and SCIM directory sync for centralised identity management.

Role-Based Access Control

Granular permissions ensure team members can only access what their role requires. Access is reviewed and deprovisioned immediately on offboarding.

Immutable Audit Trails

Every data access, admin action, and system event is logged in append-only audit trails. Logs are retained for 90 days on standard plans.

Automated Backups

Daily automated backups with encrypted storage and defined retention. Recovery procedures are documented and exercised as part of operational readiness.

Continuous Security Monitoring

Continuous automated monitoring and alerting across production systems, with escalation procedures for anomaly detection and incident response.

Data Sovereignty

Australian-first data handling. Australian legal posture. Clear control.

XIntelliSync operates with an Australian-first hosting and privacy posture. Primary business data is intended to remain within Australian-hosted systems, with any required external subprocessors handled under documented Privacy Act safeguards and contractual controls. For businesses with APRA obligations, ASX reporting requirements, or APP cross-border disclosure concerns, that control model matters.

  • Australian-first hosting and data handling policy
  • APP 8 cross-border disclosure safeguards documented for external subprocessors
  • Privacy Act 1988 obligations documented and maintained
  • OAIC complaint-path support where required by law
  • Data subject access requests supported (APP 12)

Data Return on Cancellation

Full export available from account settings

30 days

Permanent Data Deletion

After account closure — deletion certificate on request (Enterprise)

90 days

Audit Log Retention

Standard plans. Extended retention available Enterprise tier

90 days

Backup Retention

Point-in-time recovery. Encrypted backup storage.

30 days

Breach Notification

Handled under applicable Privacy Act and NDB obligations

Prompt
For Enterprise & Legal Teams

Your procurement team has questions. We have the documentation.

Security questionnaires, DPAs, SOC 2 reports, and a direct line to our security team — on request, under NDA where required.

Security Overview

A non-confidential security overview document covering architecture, controls, certifications, and data handling practices.

Request Overview

Data Processing Addendum

Our DPA covers GDPR Article 28 obligations, subprocessor commitments, Privacy Act requirements, and breach notification timelines.

Request DPA

SOC 2 Report Access

Third-party attestation reports from our infrastructure partners are available under NDA for qualified enterprise reviewers.

Request Report

Security Team — Direct Line

For vulnerability disclosure, security questionnaires, APRA CPS 234 inquiries, or to book a security briefing with our team.

[email protected]

Questions legal teams actually ask.

Plain answers. No hedging.

The back-office OS your legal team will actually sign off on.

Australian-built. APP-aligned. AI-accountable. 150 agents. One platform your CFO, legal team, and operations team can all get behind.

XIntelliSync AI Pty Ltd · Sydney, Australia 🇦🇺 · Privacy Policy · Security · Terms