Built for sovereignty.
How Manifest protects the confidentiality, integrity and availability of your data, and keeps a person accountable for every decision an agent makes. Every claim on this page is backed by a control, a certificate or a name.
Controls, checked continuously.
Twelve control families, mapped to SOC 2 and ISO 27001. A green mark means the control is in place and evidenced; an orange one means a person owns the step. Open a family for its controls.
Access security
7 controls
- Unique access IDs, MFA enforced for every account
- Role-based access: agents and people see only their scope
- Encryption at rest (AES-256) and in transit (TLS 1.2+)
- Quarterly access reviews
- Privileged access logged and time-boxed
- Automatic de-provisioning on exit
- Access exceptions approved by a named owner
AI governance
6 controls
- No customer data used to train any model
- Every agent action logged with input, output and decision
- Exceptions routed to a named person before any write-back
- Agent scope limited to its workflow and data
- Human review thresholds set per use case
- Model changes recorded and reversible
Data sovereignty
5 controls
- On-prem and private-cloud deployment options
- Models and vector indexes stay inside the customer boundary
- Document lineage, audit trail and DRM on every file
- Australian regions only for managed tenancies
- Customer-managed encryption keys on private cloud
Change management
6 controls
- Change management policy
- Configuration and asset management policy
- Software change testing before release
- Peer review on every change
- Production changes approved by a named owner
- Rollback tested per release
Availability
3 controls
- Business continuity and disaster recovery policy
- BCDR plan tested annually
- Backup restoration testing
Confidentiality
4 controls
- Data classification policy
- Data retention and disposal policy
- Certified disposal of customer data on exit
- Confidentiality agreements for all staff and contractors
Vulnerability management
3 controls
- Third-party penetration test, annually
- Vulnerability and patch management policy
- Dependency scanning on every build
Incident response
4 controls
- Incident response plan, tested annually
- Security incidents tracked to closure
- A named responder on call, not a queue
- Customer notification within agreed timeframes
Risk assessment
4 controls
- Annual risk assessment
- Vendor due diligence review
- Vendor risk management policy
- Risk register reviewed quarterly
Network security
3 controls
- Network security policy
- Endpoint security on every managed device
- Segmented environments per customer
Organisational
15 controls
- Code of conduct and security training for all staff
- Background checks for roles with data access
- Cyber insurance in place
- Information security policy, reviewed annually
- Acceptable use policy
- Security roles and responsibilities assigned
Physical security
2 controls
- Physical security policy
- Data-centre access limited to named personnel
Your data never leaves your walls.
The aOS, its agents, the models and the vector index all run inside a boundary you control: your data centre, your private cloud, or an Australian region. What crosses the boundary is your decision, and it's logged.
- 01
- Nothing is re-keyed, nothing is copied outConnectors read from and write back to your systems of record. Manifest holds no shadow copy of your ledger.
- 02
- Models run where the data isFine-tuned LLM engine and GPU compute deploy inside the boundary. Model-agnostic, so a model change never means a data move.
- 03
- Every document has a lineageWho ingested it, what the agent read, what it produced, who approved it. Retention and disposal follow your policy, not ours.
- 04
- Agents act, people decideAn agent can extract, match and draft. Anything that changes a record of value goes to a named person first.
Certified and audited.
Certifications and frameworks, with the current status of each.
Independently audited security, availability and confidentiality controls across every system that touches customer data.
CertifiedCertified information security management system, the international standard.
CertifiedPrivacy by design, aligned to the strictest global standard for personal data.
AlignedHandling of personal information under the Privacy Act 1988, for Australian enterprise and government customers.
AlignedThree ways to deploy.
Same platform, same controls. The difference is where the boundary sits.
On-premises
Everything inside your data centre, including models and compute. Air-gapped where required. Proven with an Indian defence client.
Data never leaves site
Private cloud
Your tenancy, your keys, in an Australian region. Manifest operates the platform; you own the data and the encryption keys.
AU region · customer-managed keys
Public cloud
Manifest-managed tenancy in an Australian region for proofs of value and smaller teams. Isolated per customer, same audit trail.
AU region · isolated tenancy
A person, not a policy.
Certificates say what was true on audit day. This is the moment in the product where a person takes the decision, and the log records who.
Found something? Tell a person.
Report a vulnerability, or ask the question your security team needs answered before procurement can sign. A named person replies within one business day.
- Security
- info@manifestai.com.au
- Disclosure
- Coordinated disclosure. We acknowledge within 2 business days and won't pursue good-faith researchers.
- Status
- Incident notices published here and emailed to nominated contacts.
no ticket numbers, a name and a reply