Compliance brief
Gateway: compliance, security and data governance.
This brief is for the risk, legal and procurement teams evaluating KYZON Gateway. It sets out how Gateway supports your regulatory obligations, how KYZON handles your data, our certification status, and your audit rights.
Last updated: June 2026 · KYZON Pty Ltd · AWS Sydney (ap-southeast-2)
Your obligations
How Gateway supports each framework.
Gateway is a control that supports your obligations. It does not make your organisation compliant; compliance stays with you. Below is the specific support Gateway provides under each framework, with an honest note where a framework needs a certification we do not yet hold.
Regulatory context: in January 2026 the OAIC ran its first privacy-policy compliance sweep across around 60 organisations and has signalled a more proactive enforcement posture ahead of the automated-decision obligations that commence on 10 December 2026.
| Framework | The obligation | How Gateway supports it |
|---|---|---|
| APRA CPS 234 (Information Security) | Maintain an information security capability proportionate to threats, including for information assets managed by third parties. In force since 2019. | Every AI request and response is logged and policy-checked on Australian infrastructure, with SSO, role-based access control and encryption in transit and at rest. Gateway turns an ungoverned AI data flow into a monitored, controlled boundary. |
| APRA CPS 230 (Operational Risk Management) | Manage operational and service-provider risk: maintain a service-provider register, formal agreements and monitoring. In force 1 July 2025; existing service-provider contracts transition by the earlier of renewal or 1 July 2026. | Gateway is a documented, in-region service provider with a Data Processing Agreement, a disclosed sub-processor list and contractual audit rights, which is what CPS 230 service-provider management requires. In-region operation supports your residency and continuity controls. |
| Privacy Act (automated-decision transparency, APP 1.7 to 1.9) | From 10 December 2026, disclose in your privacy policy how personal information is used in automated decisions that could significantly affect an individual. | Gateway logs every AI request and response, giving you the records to identify which automated processes use personal information and to support the inventory and transparency work the obligation requires. Gateway provides the audit trail; your privacy policy stays yours to write. |
| Essential Eight | Baseline mitigation strategies, where mandated, for example across government. | Gateway supports specific controls relevant to AI usage, including centralised logging, monitoring and access control. Gateway is one component of an Essential Eight posture, not full coverage of it. |
| Hosting Certification Framework | Hosting requirements for certain government workloads. | Gateway runs on AWS in Sydney, which holds the relevant infrastructure certifications. KYZON's own assessment against government hosting requirements is on our roadmap; see certifications below. |
| IRAP | Security assessment for government systems handling sensitive or classified information. | An IRAP assessment of Gateway is roadmapped, not yet held. We state this plainly rather than imply coverage we do not have. |
Security and data
How KYZON handles your data.
KYZON's own infrastructure runs in Australia. The model providers Gateway routes to are offshore, which is the crossing Gateway exists to log and govern. Everything below is implemented today.
| Control | Status today |
|---|---|
| Data residency | All KYZON infrastructure runs on AWS Sydney (ap-southeast-2). Nothing transits foreign infrastructure by default. The model providers Gateway routes to are offshore and are disclosed as sub-processors. |
| Encryption in transit | All traffic is encrypted in transit over HTTPS and TLS. |
| Encryption at rest | The database and object storage (S3) are encrypted at rest at the storage layer. |
| Access control | Single sign-on (SSO) and role-based access control (RBAC). |
| Logging | Requests and responses are logged to AWS Sydney to provide your audit trail. |
| Log retention | Logs are retained for between 30 days and 6 months depending on the use case. |
| Retention and deletion | Data retention and deletion policies are in place. |
Certifications
Where we are, stated plainly.
We will not claim certifications we have not earned. We hold no completed certifications yet. Below is the actual status of each, in sequence. This is the basis on which your risk function can clear an early vendor: an honest position, a path, and the right to verify it.
| Certification | Status |
|---|---|
| SOC 2 Type II | In progress |
| ISO 27001 | Roadmapped |
| APRA-aligned documentation (CPS 234 and CPS 230 mapping) | In development |
| IRAP assessment | Roadmapped |
Transparency
Sub-processors disclosed. Audit rights contractual.
Sub-processors, disclosed
KYZON discloses its sub-processors in two categories: AWS, which provides the infrastructure in Sydney, and the AI model providers Gateway routes to. The current named list is in our sub-processor list, available on request.
Audit rights, contractual
Enterprise agreements include the contractual right for your auditor to examine KYZON directly. You do not have to take our certification status on faith. You can verify it. For an early vendor, this is the point.
Data Processing Agreement
A DPA is available, covering how KYZON processes personal information on your behalf, including residency, sub-processors, retention and deletion.
Next step
Request the documentation, or start a security review.
Available to send today: the Data Processing Agreement and the current sub-processor list. For a deeper review, our team will walk your risk and security people through the architecture and answer your questionnaire directly.