Governance mappings built for Australian regulated sectors.
This reference documents how ThreatLynx supports governance readiness and evidence workflows relevant to Australian regulatory frameworks. Mappings indicate areas of operational governance support — not compliance certification or legal attestation.
Framework mappings are operational governance references. They indicate areas where ThreatLynx supports governance readiness activities — not compliance certification, legal attestation, or regulatory endorsement of any kind.
Framework mapping overview
ThreatLynx provides governance visibility and evidence workflow support across six Australian and international regulatory frameworks. Coverage depth varies by framework.
ASD / ACSC
ASD Essential Eight
Governance support
ThreatLynx provides an inventory of discovered OAuth-connected applications and governance decision records. This supports Application Control maturity assessment by documenting which third-party applications have been reviewed, approved, or blocked.
Relevant controls
Evidence outputs
ThreatLynx does not provide endpoint detection, patch management, or multi-factor authentication controls. E8 coverage is limited to application visibility and governance evidence.
APRA
APRA CPS 234
Governance support
APRA-regulated entities are expected to maintain a register of information assets including third-party systems. ThreatLynx provides a continuously updated inventory of connected SaaS applications and their granted permissions — directly relevant to para 15 (information assets) and para 36 (third-party risk) obligations.
Relevant controls
Evidence outputs
ThreatLynx supports asset identification and governance record-keeping. It does not assess vendors' information security capability or produce formal attestations required under CPS 234.
OAIC
Privacy Act 1988 (APPs)
Governance support
ThreatLynx helps identify which third-party applications have OAuth access to personal information held in Google Workspace or Microsoft 365. Vendor jurisdiction data supports APP 8 cross-border disclosure assessment. Governance records support APP 11 reasonable-steps obligations.
Relevant controls
Evidence outputs
ThreatLynx does not assess the content or type of personal information held, provide a Privacy Impact Assessment, or constitute legal advice on APP compliance obligations.
ISO / IEC
ISO/IEC 27001:2022
Governance support
ThreatLynx provides asset inventory, supplier relationship visibility (Annex A.5.19), and access control records (A.9.4) — directly relevant to ISO 27001:2022 Annex A controls. Governance audit logs support evidence requirements for certification audits.
Relevant controls
Evidence outputs
ThreatLynx provides supporting evidence for a subset of ISO 27001:2022 controls. It does not constitute an ISMS, replace formal ISO certification, or assess the completeness of an organisation's control implementation.
AICPA
SOC 2 Type II
Governance support
ThreatLynx is designed with reference to SOC 2 Trust Service Criteria. A formal SOC 2 Type II examination is planned. Current governance workflow outputs can support a customer's SOC 2 vendor management evidence where ThreatLynx is part of their control environment.
Relevant controls
Evidence outputs
ThreatLynx has not completed a formal SOC 2 Type II examination. "Planned" status indicates roadmap intent, not current certification. Organisations requiring vendor SOC 2 attestation should note this limitation.
ASD / DTA
IRAP (ISM / PSPF)
Governance support
ThreatLynx governance evidence outputs are designed to support Australian Government IRAP assessment preparation. Evidence packages are available on request for government agencies conducting IRAP assessments.
Relevant controls
Evidence outputs
ThreatLynx has not been formally assessed under IRAP. Evidence packages are operational governance references — not IRAP attestations or ASD-endorsed outputs.
Governance mapping table
A structured reference of ThreatLynx governance support areas by regulatory body and framework. Notes column identifies coverage boundaries and limitations.
| Regulatory body | Framework | Control areas | ThreatLynx support | Evidence output | Notes |
|---|---|---|---|---|---|
| ASD / ACSC | Essential Eight | Application Control · User App Hardening | OAuth application inventory · Governance workflow records · Approved / blocked status | Application register · Governance decision log · Evidence export | ML2 / ML3 readiness support. No endpoint or EDR coverage. |
| APRA | CPS 234 | Information assets · Third-party risk | SaaS asset register · Permission scope records · Third-party governance history | Asset register export · Third-party inventory · Governance log | Para 15 (information assets) and Para 36 (third-party) support. Not a formal CPS 234 assessment. |
| OAIC | Privacy Act — APPs | APP 1 · APP 8 · APP 11 | Data scope identification · Vendor jurisdiction data · Governance decisions for PII-access apps | PII-scope application list · Cross-border vendor register · Review history | Identifies apps with personal data access. Does not assess content or constitute legal advice. |
| ISO / IEC | 27001:2022 | A.5.19 · A.8.7 · A.9.4 | Supplier inventory · Application access register · Governance audit trail | Vendor inventory · Permission register · Audit log | Supports Annex A evidence for subset of controls. Not a replacement for ISMS or ISO certification. |
| AICPA | SOC 2 | CC6.1 · CC9.2 | Vendor access inventory · Access governance records | Vendor access register · Governance decision log | SOC 2 Type II examination planned Q2 2026. Not currently certified. |
| ASD / DTA | IRAP / ISM / PSPF | ISM-1380 · ISM-0042 · PSPF Policy 10 | Application control evidence · Ownership records · Governance documentation | IRAP evidence package (on request) | Evidence package available on request. Not formally IRAP assessed. |
| DTA | Hosting Certification Framework | Data sovereignty · Residency | Australian (Sydney) target hosting region · Region pinned to Australia at deploy time | Per-deployment residency confirmation documentation | Customer security telemetry hosted in Australia (Sydney) as the target region, with residency confirmed per deployment; named US subprocessors for email/billing. Hosting certification not formally assessed. |
Coverage designations indicate the nature of operational governance support provided. They do not constitute compliance assessments, legal opinions, or regulatory approvals.
Evidence outputs
ThreatLynx produces structured governance records and evidence exports suitable for internal audit, access review cycles, and regulator evidence requests.
SaaS application inventory
A point-in-time record of all discovered OAuth-connected applications — including application name, vendor, connected users, granted scopes, risk score, and governance status.
Relevant frameworks
OAuth scope register
A structured record of all active OAuth permission grants — scope strings, access type (read / write / delete), sensitivity classification, and whether persistent access is granted.
Relevant frameworks
Governance decision log
An append-only log of all governance actions — status changes, owner assignments, rationale capture, and review dates — with actor attribution and ISO 8601 timestamps.
Relevant frameworks
AI and agent identity register
A catalogue of applications identified as AI-capable, automation platforms, or non-human identities — with confidence levels, detection signals, and associated governance status.
Relevant frameworks
Risk posture summary
A scored summary of the application portfolio — applications by risk band (Critical / High / Medium / Low), ungoverned count, open findings, and governance maturity metrics.
Relevant frameworks
Evidence snapshot export
A combined export capturing inventory state, governance decisions, scope records, risk scores, and audit trail at a nominated point in time — suitable for access reviews and regulator evidence requests.
Relevant frameworks
Evidence outputs are operational governance records produced by ThreatLynx based on discovered OAuth metadata. They should be reviewed by your security, legal, and compliance teams before use in formal audit or regulatory submissions. Evidence does not constitute compliance attestation or legal sign-off.
Important information
The following information is provided to support informed procurement, legal review, and governance decision-making.
About ThreatLynx governance mapping references
ThreatLynx is a governance and visibility platform for SaaS applications and OAuth-connected systems. It is not a certification body, accredited auditor, or regulatory authority.
Framework mappings in this document are rules-based operational references identifying areas where ThreatLynx governance workflows and evidence outputs may support an organisation's readiness activities. They are not compliance assessments, audit opinions, legal determinations, or regulatory endorsements.
Organisations remain solely responsible for their own compliance with applicable laws, regulations, and standards — including the Privacy Act 1988, APRA prudential standards, ASD Essential Eight requirements, and any other applicable framework.
Framework mapping references should be reviewed by qualified security, legal, and compliance advisors before being relied upon in formal governance processes, audit submissions, or regulatory dealings.
APRA-regulated entities
ThreatLynx has not been assessed, endorsed, or accredited by the Australian Prudential Regulation Authority (APRA). CPS 234 alignment references indicate areas of operational support for asset identification and third-party governance — not a formal APRA compliance determination. Regulated entities should engage their APRA relationship manager and compliance function before relying on ThreatLynx output in prudential reporting or self-assessments.
Australian Consumer Law (ACL)
ThreatLynx Pty Ltd makes no representation that use of this platform ensures compliance with any legal obligation. References to "alignment", "mapping available", or "evidence support" describe operational functionality — not legal compliance outcomes or guarantees. Nothing in this document constitutes a warranty, guarantee, or representation under the Australian Consumer Law or any other statute.
Government and IRAP procurement
ThreatLynx has not been formally assessed under IRAP (Information Security Registered Assessors Program). References to IRAP readiness support indicate that governance evidence outputs are designed to support IRAP assessment preparation activities. A formal IRAP assessment by an ASD-listed IRAP assessor is required for government use at Protected level and above.
ISO and SOC 2 certification status
ThreatLynx is designing its security controls with reference to ISO/IEC 27001:2022 and SOC 2 Trust Service Criteria. Formal certification and examination have not yet been completed. "Controls-aligned" and "Planned" designations indicate internal programme intent — not current third-party certification.
Security posture and data residency
Current security capabilities and planned certifications. Procurement teams and security reviewers should note distinctions between operational capabilities and certification status.
| Capability | Current status | Notes |
|---|---|---|
| Data residency | Australia (Sydney) · target region | Region pinned to Australia at deploy time; residency confirmed per customer deployment. Named US subprocessors for email/billing |
| Encryption at rest | Authenticated encryption | Fernet (AES-128-CBC + HMAC) with key rotation; per-tenant AWS KMS envelope encryption rolling out |
| Encryption in transit | TLS 1.2 / 1.3 | All API and web traffic encrypted |
| Tenant isolation | Row-level security | Data access controls per workspace tenant |
| Audit logging | Append-only governance log | Actor-attributed, timestamped entries |
| RBAC | Role-based access control | Admin, reviewer, and read-only roles |
| SOC 2 Type II | Planned · Q2 2026 | Examination not yet completed |
| ISO 27001 | Controls-aligned | Formal certification not yet obtained |
| IRAP assessment | On request | Evidence packages available; not IRAP assessed |
Security posture information is current as at publication date. Certification status should be verified directly with ThreatLynx for time-sensitive procurement decisions.
What ThreatLynx processes
ThreatLynx processes OAuth grant metadata from workspace admin APIs — application names, client IDs, granted scope strings, user counts, and vendor information. It does not process, store, or access email content, file content, calendar event details, message payloads, or employee activity data. Full details are documented in our Privacy Policy and Terms of Service.
Request a governance review session
We can walk your security, risk, or compliance team through ThreatLynx governance capabilities and framework alignment in your context — no sales pressure, no unsolicited follow-up.
Related governance references
ThreatLynx Governance Mapping Pack · This document is a governance reference only and does not constitute compliance certification, legal advice, or regulatory endorsement.
ThreatLynx Pty Ltd · threatlynx.com.au · © 2026