Official Anthropic PartnerIoT Global Awards 2023 Winner- Cloud Analytics software
Arrochar Labs
ARROCHAR
LABS
Security

We take AI security serious.

When you bring AI into a government agency or enterprise, the biggest question isn't "will it work?" - it's "can we trust it?"

We build every engagement around the answer being yes. Not bolted on afterwards. Not "we'll get to that." Built in from the start.

Six pillars of secure AI deployment

Every engagement is built around these six areas - the ones our government and enterprise clients care about most.

Pillar 01

Data sovereignty

Your data stays in the region you operate in, hosted on infrastructure in your chosen region with no offshore processing — even for model inference. This keeps your data within your jurisdiction, under the privacy laws that apply to you, and it is never used to train external models.

Data residencyISO 27001SOC 2
Pillar 02

Security hardened

Every product is built to recognised security baselines like the CIS Controls, the NIST Cybersecurity Framework, and ISO 27001 — international standards that form the foundation of enterprise cyber defence. Application control, patching, MFA, admin privilege restriction — all built in at the maturity level your organisation is targeting.

CIS ControlsNIST CSFISO 27001
Pillar 03

Assurance-ready architecture

Controls are baked in so the product supports your audit and assurance against frameworks such as SOC 2, ISO 27001 and ISO/IEC 42001, rather than complicating it. Network segmentation, cryptography, access control, and system hardening — all structured for regulated and sensitive workloads from the start.

SOC 2ISO 27001ISO/IEC 42001
Pillar 04

Privacy by Design

AI systems can process sensitive personal information at scale — which makes privacy controls non-negotiable. We build to the privacy laws that apply to you, including GDPR, CCPA, and the privacy regimes that apply to you, embedding data minimisation, purpose limitation, and consent management directly into solution architecture.

GDPRCCPALocal privacy law
Pillar 05

AI-Specific Safety Controls

Traditional security frameworks weren’t built for prompt injection, model hallucination, or training data poisoning. We layer dedicated AI safety controls on top — input validation, output guardrails, red-teaming before go-live, and model access controls aligned to the OWASP LLM Top 10 and ISO/IEC 42001.

OWASP LLM Top 10ISO/IEC 42001NIST AI RMF
Pillar 06

Continuous Monitoring & Assurance

Security isn’t a one-time deliverable. Every solution we deploy includes structured logging, real-time monitoring, and drift detection so you can demonstrate ongoing compliance — not just compliance at launch. Audit-ready dashboards give your security team clear visibility at all times.

ISO 27001SOC 2ISO/IEC 42001
ACSC Essential Eight

All eight strategies. Covered.

The Essential Eight is the Australian Cyber Security Centre's baseline for cyber defence. Every deployment is hardened against all eight mitigation strategies at the maturity level your organisation is targeting — and multi-factor authentication leads, because compromised credentials are how most breaches start. Operating outside Australia? The same controls map directly to CIS Controls, UK Cyber Essentials, and Singapore CSA Cyber Essentials — one control set, every market.

Multi-factor authentication

Phishing-resistant MFA — passkeys and hardware security keys — on all access to admin consoles, code, pipelines, and client data. SMS codes don’t count. No exceptions.

Application control

Only approved applications and signed code execute in deployment environments.

Patch applications

Automated dependency and framework patching, with critical fixes prioritised within 48 hours.

Restrict admin privileges

Least privilege by default — dedicated admin accounts, scoped tokens, no shared credentials.

Patch operating systems

OS and runtime patching automated across the stack, on supported versions only.

User application hardening

Browsers and user-facing components locked down to reduce attack surface.

Office macro settings

Macros disabled or restricted to signed, vetted code — the classic malware door stays shut.

Regular backups

Offsite backups of code, configuration, and data with tested recovery procedures.

We hold ourselves to the same standard

Trust in a product starts with trust in the people who run it. These are the controls we apply to our own systems — the ones that hold your data.

Phishing-resistant MFA on our own accounts

Every administrative account across our identity, code, hosting, and email systems is protected by multi-factor authentication, with passkeys and hardware security keys as our standard.

Data minimisation by design

Our marketing sites run with no database at all — we collect only what a request needs, hold it with reputable providers, and never use your data to train external models.

Encrypted everywhere

Every site and product endpoint is HTTPS-only with modern TLS. There is no unencrypted path to anything we run.

Documented and reviewed

Our security architecture is documented, mapped to the Essential Eight, and reviewed quarterly against an active remediation roadmap — the same discipline we bring to client engagements.

Global coverage

Wherever you operate, we speak your regulator's language

One control architecture, mapped to the security, privacy, and AI governance frameworks of every major market we serve — so your compliance team isn't translating between regimes.

United States

Security
NIST CSF 2.0, SOC 2 Trust Services Criteria, CIS Controls
Privacy
CCPA/CPRA and US state privacy laws
AI governance
NIST AI Risk Management Framework
Government
FedRAMP-aligned cloud architecture

Europe & United Kingdom

Security
ISO/IEC 27001, NIS2 for critical sectors, UK Cyber Essentials
Privacy
GDPR and UK GDPR, EU-region data residency
AI governance
EU AI Act readiness, ISO/IEC 42001
Government
NCSC Cyber Assessment Framework alignment

Singapore

Security
CSA Cyber Essentials and Cyber Trust marks
Privacy
PDPA, in-country data residency available
AI governance
IMDA Model AI Governance Framework (incl. GenAI)
Sector
MAS Technology Risk Management for financial services

Southeast Asia

Security
ISO/IEC 27001 baseline with regional hosting options
Privacy
Malaysia PDPA, Thailand PDPA, Indonesia PDP Law, Philippines DPA
AI governance
ASEAN Guide on AI Governance and Ethics

Australia & New Zealand

Security
ACSC Essential Eight, ISM, IRAP-ready architecture
Privacy
Privacy Act (APPs), NZ Privacy Act
AI governance
AU Voluntary AI Safety Standard, AI Ethics Principles
Government
PSPF and ISM at OFFICIAL and PROTECTED

Everywhere we operate

Security
ISO/IEC 27001 and SOC 2 as the universal baseline
AI governance
ISO/IEC 42001, OWASP LLM Top 10
Data
Your data stays in your chosen region — never used to train external models

The standards behind our approach

Every engagement draws on these frameworks as appropriate to your context and classification level.

E8
ACSC Essential Eight
ISM
Information Security Manual (ASD)
NIS2
EU Network & Information Security Directive
AI Act
EU Artificial Intelligence Act
PDPA
Singapore Personal Data Protection Act
MAS TRM
MAS Technology Risk Management (Singapore)
IMDA
Model AI Governance Framework (Singapore)
27001
ISO/IEC 27001 Information Security
SOC 2
SOC 2 (Trust Services Criteria)
42001
ISO/IEC 42001 AI Management
GDPR
EU General Data Protection Regulation
CIS
CIS Critical Security Controls
NIST AI
NIST AI Risk Management Framework
OWASP
OWASP LLM Top 10
NIST CSF
NIST Cybersecurity Framework

Need the full technical detail?

Our Security Deep Dive covers every control domain with standards mapping, implementation detail, and FAQ - written for security teams and assessors.

Read the Deep Dive →

Have a question about securing your AI deployment?

We're happy to walk through how these controls apply to your specific environment. No pitch, no pressure.

Get in Touch →