ProductAgentic Operating System (aOS)Agent HubReference architectureIntegrations
IndustriesMiningConstructionPublic SectorFinancial ServicesProperty
CompanyAboutHow we workCase studiesContact
TrustTrust CentreComplianceDeployment options
Contact
Trust Centre

Built for sovereignty.

How Manifest protects the confidentiality, integrity and availability of your data, and keeps a person accountable for every decision an agent makes. Every claim on this page is backed by a control, a certificate or a name.

DeploymentOn-prem · Private cloud
Data residencyAustralia, or inside your walls
Training on customer dataNever
ExceptionsReviewed by a person
Security questionsAnswered within one business day
Monitoring

Controls, checked continuously.

Twelve control families, mapped to SOC 2 and ISO 27001. A green mark means the control is in place and evidenced; an orange one means a person owns the step. Open a family for its controls.

Access security

7 controls
  • Unique access IDs, MFA enforced for every account
  • Role-based access: agents and people see only their scope
  • Encryption at rest (AES-256) and in transit (TLS 1.2+)
  • Quarterly access reviews
  • Privileged access logged and time-boxed
  • Automatic de-provisioning on exit
  • Access exceptions approved by a named owner

AI governance

6 controls
  • No customer data used to train any model
  • Every agent action logged with input, output and decision
  • Exceptions routed to a named person before any write-back
  • Agent scope limited to its workflow and data
  • Human review thresholds set per use case
  • Model changes recorded and reversible

Data sovereignty

5 controls
  • On-prem and private-cloud deployment options
  • Models and vector indexes stay inside the customer boundary
  • Document lineage, audit trail and DRM on every file
  • Australian regions only for managed tenancies
  • Customer-managed encryption keys on private cloud

Change management

6 controls
  • Change management policy
  • Configuration and asset management policy
  • Software change testing before release
  • Peer review on every change
  • Production changes approved by a named owner
  • Rollback tested per release

Availability

3 controls
  • Business continuity and disaster recovery policy
  • BCDR plan tested annually
  • Backup restoration testing

Confidentiality

4 controls
  • Data classification policy
  • Data retention and disposal policy
  • Certified disposal of customer data on exit
  • Confidentiality agreements for all staff and contractors

Vulnerability management

3 controls
  • Third-party penetration test, annually
  • Vulnerability and patch management policy
  • Dependency scanning on every build

Incident response

4 controls
  • Incident response plan, tested annually
  • Security incidents tracked to closure
  • A named responder on call, not a queue
  • Customer notification within agreed timeframes

Risk assessment

4 controls
  • Annual risk assessment
  • Vendor due diligence review
  • Vendor risk management policy
  • Risk register reviewed quarterly

Network security

3 controls
  • Network security policy
  • Endpoint security on every managed device
  • Segmented environments per customer

Organisational

15 controls
  • Code of conduct and security training for all staff
  • Background checks for roles with data access
  • Cyber insurance in place
  • Information security policy, reviewed annually
  • Acceptable use policy
  • Security roles and responsibilities assigned

Physical security

2 controls
  • Physical security policy
  • Data-centre access limited to named personnel
Architecture

Your data never leaves your walls.

The aOS, its agents, the models and the vector index all run inside a boundary you control: your data centre, your private cloud, or an Australian region. What crosses the boundary is your decision, and it's logged.

01 · YOUR DATA & SYSTEMSSAP · TechnologyOne · Oracle · document stores 02 · COMPUTE & MODELSInside the boundary · never trained on your data 03 · CONTEXT & KNOWLEDGEVector index · lineage · retention rules 04 · AGENTSEvery action logged · exceptions to a person 05 · AGENTIC OPERATING SYSTEMRole-based access · MFA · audit trail SOVEREIGN BOUNDARYYour data centre · private cloud · AU region
01
Nothing is re-keyed, nothing is copied outConnectors read from and write back to your systems of record. Manifest holds no shadow copy of your ledger.
02
Models run where the data isFine-tuned LLM engine and GPU compute deploy inside the boundary. Model-agnostic, so a model change never means a data move.
03
Every document has a lineageWho ingested it, what the agent read, what it produced, who approved it. Retention and disposal follow your policy, not ours.
04
Agents act, people decideAn agent can extract, match and draft. Anything that changes a record of value goes to a named person first.
Compliance

Certified and audited.

Certifications and frameworks, with the current status of each.

SOC 2SOC 2 Type II

Independently audited security, availability and confidentiality controls across every system that touches customer data.

Certified
ISO 27001ISO 27001

Certified information security management system, the international standard.

Certified
GDPRGDPR

Privacy by design, aligned to the strictest global standard for personal data.

Aligned
APPAustralian Privacy Principles

Handling of personal information under the Privacy Act 1988, for Australian enterprise and government customers.

Aligned
Hosting

Three ways to deploy.

Same platform, same controls. The difference is where the boundary sits.

Sovereign

On-premises

Everything inside your data centre, including models and compute. Air-gapped where required. Proven with an Indian defence client.

Data never leaves site

Private

Private cloud

Your tenancy, your keys, in an Australian region. Manifest operates the platform; you own the data and the encryption keys.

AU region · customer-managed keys

Managed

Public cloud

Manifest-managed tenancy in an Australian region for proofs of value and smaller teams. Isolated per customer, same audit trail.

AU region · isolated tenancy

People

A person, not a policy.

Certificates say what was true on audit day. This is the moment in the product where a person takes the decision, and the log records who.

human in the loopBank reconciliation · exception
Manifest agentStatement line 1,206 ($1,250.00) doesn't match the ledger entry ($1,205.00). I've held it. Approve the variance, or raise it with the bank?
Daniel · FinanceRaise it with the bank. Note the fee was reversed on the 3rd.
Decision by Daniel · logged 09:14 · nothing posted to the ledger
Disclosure

Found something? Tell a person.

Report a vulnerability, or ask the question your security team needs answered before procurement can sign. A named person replies within one business day.

Security
info@manifestai.com.au
Disclosure
Coordinated disclosure. We acknowledge within 2 business days and won't pursue good-faith researchers.
Status
Incident notices published here and emailed to nominated contacts.

no ticket numbers, a name and a reply