Sovereign by Architecture. Secure by Design.
Annie's security posture starts with a structural guarantee: your data never leaves your infrastructure. Here's an open view of our architecture, certifications, and the controls we operate as the platform builder.
Our Commitment to Security
Security isn't a checkbox — it's built into how we design, build, and operate the Annie platform.
At Annie, trust is built into the architecture before any control or process. Because Annie deploys on infrastructure you control, your inference data never traverses our systems — eliminating the largest class of third-party data risk by design. The controls documented here describe how we operate as the platform builder: how we build, audit, and secure the code and models that run on your infrastructure. We hold ISO 27001 certification and operate under a formal Information Security Management System (ISMS) that is independently audited every year.
Independently Verified
Our certifications are issued and renewed through accredited third-party auditors, not self-assessments.
ISO/IEC 27001 is the internationally recognised standard for information security management. Certification requires a comprehensive ISMS covering risk assessment, security controls, and continuous improvement — audited annually by an accredited certification body.
- Formal Information Security Management System (ISMS)
- Annual third-party surveillance audits
- Risk assessment and treatment framework
- Covers design, development, and operation of the Annie platform
- Mandatory employee security training and awareness
Annie is built for Australian regulated industries. We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Because Annie deploys on infrastructure you control, the majority of personal data processed by the platform never leaves your jurisdiction.
- Australian Privacy Principles (APPs) applied to all data handling
- Privacy Impact Assessment process for new features
- Notifiable Data Breaches (NDB) scheme obligations met
- Individual access and correction rights supported
- Data minimisation applied across platform development
Annie's architecture is designed to support compliance with the Australian Government Information Security Manual (ISM) and to enable PROTECTED workload classification on appropriate sovereign infrastructure. Controls align with ASD / ACSC guidance.
- Air-gappable deployment — no external network dependency required
- No inference data crosses external API boundaries
- Supports deployment on ASD-listed cloud services
- Audit logging at every pipeline stage
- Supply chain security controls for model and code provenance
Annie is not itself an APRA-regulated entity, but the platform is architecturally designed to help APRA-regulated customers (banks, insurers, superannuation funds) meet their CPS 234 obligations around information security capability, policy, and incident management.
- On-premise deployment supports data localisation requirements
- Audit trail supports board-level reporting obligations
- Third-party risk reduced by eliminating external API dependencies
- Incident response documentation available for customer ISMS integration
- Penetration testing reports available under NDA for due diligence
How We Protect Your Data
Our controls span physical, technical, and organisational layers — all mapped to the ISO 27001 Annex A control set.
Strict access governance ensures only authorised personnel can reach sensitive systems and data.
- Role-based access control (RBAC) across all systems
- Multi-factor authentication enforced for all staff
- Least-privilege principle applied by default
- Access reviews conducted quarterly
All customer data is encrypted in transit and at rest using industry-standard algorithms.
- TLS 1.2 or higher for all data in transit
- AES-256 encryption for all data at rest
- Encryption keys managed via Google Cloud KMS
- HTTPS enforced with HSTS preloading
Continuous monitoring detects anomalies and security events before they become incidents.
- Centralised security logging and SIEM alerting
- Automated anomaly detection on key systems
- Audit trails retained for all privileged actions
- Uptime and availability monitoring 24/7
We proactively find and fix vulnerabilities before they can be exploited.
- Dependency scanning on every code merge
- Regular penetration testing by third parties
- Responsible disclosure programme in place
- Critical patches applied within 24 hours
A documented and rehearsed incident response plan minimises the impact of any security event.
- Formal Incident Response Plan reviewed annually
- Defined severity classifications and escalation paths
- Customer breach notification within 72 hours
- Post-incident reviews and lessons learned
Regular backups and tested recovery procedures protect against data loss.
- Automated daily backups of all customer data
- Geographically redundant backup storage
- Recovery Time Objective (RTO) tested quarterly
- Business continuity plan maintained
Security awareness is embedded into how our team works — from day one.
- Security awareness training on joining and annually
- Acceptable use and confidentiality agreements
- Phishing simulation exercises conducted regularly
- Background checks for all new hires
Security is integrated into every stage of our software development lifecycle.
- Mandatory code review before production merges
- OWASP Top 10 considered in design and review
- Staging environment mirrors production
- Infrastructure-as-code with change control
Your Data, Your Rights
We collect only what we need, retain it only as long as necessary, and make it easy for you to exercise your rights.
A Data Processing Agreement (DPA) governs how Annie processes any personal data on your behalf in the course of platform delivery and support. Enterprise customers can request a countersigned copy.
- Included in standard Terms of Service
- Defines controller / processor responsibilities
- Covers sub-processor obligations
- Signed copies available on request
We retain only the data required to deliver and support the Annie platform. Inference data processed by Annie on your infrastructure is not retained by us at all — it never reaches our systems.
- Account data deleted within 30 days of contract end
- Billing records retained for 7 years (legal requirement)
- Support log data retained for 90 days
- No inference or conversation data retained by Annie
Under the Australian Privacy Act 1988 (Cth) you have rights regarding the personal data Annie holds about you. Contact us at privacy@go-annie.com to exercise any of these.
- Right to access your personal data
- Right to correction of inaccurate data
- Right to complain to the OAIC
- Right to know how your data is used
Annie is built to eliminate cross-border data risk by design. Because the platform deploys on infrastructure you control, your inference data, prompts, and responses never leave your jurisdiction — and never traverse Annie's systems.
- Inference data stays on your infrastructure, always
- Fully air-gappable — no outbound network calls required
- Deployable on Australian sovereign cloud or private data centre
- No cross-border transfers for AI processing
Annie uses Workforce Foundation Models trained from scratch and deployed on your infrastructure. There are no external AI model providers involved in inference. Your data is not sent to any third-party AI system — ever.
- All inference runs on sovereign models on your hardware
- No queries routed to external AI APIs
- Models trained on sovereign data — no external weights
- Cognition Stream fine-tuning runs entirely on your infrastructure
We use cookies on this marketing website to measure traffic and improve the experience. You can manage your preferences at any time via our cookie banner. No behavioural advertising cookies are used.
- Cookie consent collected before any analytics
- Google Analytics used for website traffic only
- No cross-site tracking or advertising pixels
- Preferences can be updated at any time
Third-Party Sub-processors
These are the companies we use to operate Annie's development, marketing, and billing infrastructure. AI inference sub-processors are not listed here because inference runs on your sovereign infrastructure — not ours.
| Provider | Purpose | Category | Location |
|---|---|---|---|
Google Cloud Platform
Google LLC
|
Development infrastructure, CI/CD pipelines, and internal tooling used by the Annie engineering team. Not used for customer inference or data processing. | Dev Infrastructure | Australia |
|
Google Analytics
Google LLC
|
Website traffic analytics and usage measurement on the go-annie.com marketing website only. Activated with cookie consent. No customer or inference data involved. | Analytics | United States |
Have a Security Question?
Our security team is happy to answer questions, provide documentation, or discuss our controls in more depth.