New
Enterprise Trust

Governance mappings built for Australian regulated sectors.

This reference documents how ThreatLynx supports governance readiness and evidence workflows relevant to Australian regulatory frameworks. Mappings indicate areas of operational governance support — not compliance certification or legal attestation.

Essential EightAPRA CPS 234Privacy ActISO 27001SOC 2 — PlannedIRAP — On request
ThreatLynx Governance Mapping Pack · Version 1.0 · Generated 2026 · threatlynx.com.au/security/mapping-pack

Framework mappings are operational governance references. They indicate areas where ThreatLynx supports governance readiness activities — not compliance certification, legal attestation, or regulatory endorsement of any kind.

Framework mapping overview

ThreatLynx provides governance visibility and evidence workflow support across six Australian and international regulatory frameworks. Coverage depth varies by framework.

ASD / ACSC

ASD Essential Eight

Mapping available

Governance support

ThreatLynx provides an inventory of discovered OAuth-connected applications and governance decision records. This supports Application Control maturity assessment by documenting which third-party applications have been reviewed, approved, or blocked.

Relevant controls

Application Control (ML2 / ML3)
User Application Hardening
Restrict Admin Privileges (partial)

Evidence outputs

OAuth-connected application inventoryAuthorised vs. ungoverned application recordGovernance decision log with timestamps

ThreatLynx does not provide endpoint detection, patch management, or multi-factor authentication controls. E8 coverage is limited to application visibility and governance evidence.

APRA

APRA CPS 234

Mapping available

Governance support

APRA-regulated entities are expected to maintain a register of information assets including third-party systems. ThreatLynx provides a continuously updated inventory of connected SaaS applications and their granted permissions — directly relevant to para 15 (information assets) and para 36 (third-party risk) obligations.

Relevant controls

Information asset identification (para 15)
Third-party information security capability (para 36)
Incident response and notification (para 37)

Evidence outputs

Third-party SaaS asset registerOAuth permission scope recordsGovernance status and review history

ThreatLynx supports asset identification and governance record-keeping. It does not assess vendors' information security capability or produce formal attestations required under CPS 234.

OAIC

Privacy Act 1988 (APPs)

Evidence support

Governance support

ThreatLynx helps identify which third-party applications have OAuth access to personal information held in Google Workspace or Microsoft 365. Vendor jurisdiction data supports APP 8 cross-border disclosure assessment. Governance records support APP 11 reasonable-steps obligations.

Relevant controls

APP 1 — Open and transparent management
APP 8 — Cross-border disclosure visibility
APP 11 — Security of personal information

Evidence outputs

Applications with access to personal data scopesVendor jurisdiction and incorporation recordsGovernance review decisions for data-handling apps

ThreatLynx does not assess the content or type of personal information held, provide a Privacy Impact Assessment, or constitute legal advice on APP compliance obligations.

ISO / IEC

ISO/IEC 27001:2022

Mapping available

Governance support

ThreatLynx provides asset inventory, supplier relationship visibility (Annex A.5.19), and access control records (A.9.4) — directly relevant to ISO 27001:2022 Annex A controls. Governance audit logs support evidence requirements for certification audits.

Relevant controls

A.5.19 — Information security in supplier relationships
A.8.6 — Management of technical vulnerabilities (partial)
A.8.7 — Application controls
A.9.4 — Access control

Evidence outputs

Supplier (SaaS) inventory with access recordsPermission scope and access control registerGovernance workflow audit trail

ThreatLynx provides supporting evidence for a subset of ISO 27001:2022 controls. It does not constitute an ISMS, replace formal ISO certification, or assess the completeness of an organisation's control implementation.

AICPA

SOC 2 Type II

Planned · Q2 2026

Governance support

ThreatLynx is designed with reference to SOC 2 Trust Service Criteria. A formal SOC 2 Type II examination is planned. Current governance workflow outputs can support a customer's SOC 2 vendor management evidence where ThreatLynx is part of their control environment.

Relevant controls

CC6.1 — Logical and physical access controls
CC7.1 — System operation and monitoring
CC9.2 — Vendor and partner management

Evidence outputs

OAuth access inventory (vendor management evidence)Governance workflow records (access control support)Audit trail (monitoring evidence)

ThreatLynx has not completed a formal SOC 2 Type II examination. "Planned" status indicates roadmap intent, not current certification. Organisations requiring vendor SOC 2 attestation should note this limitation.

ASD / DTA

IRAP (ISM / PSPF)

On request

Governance support

ThreatLynx governance evidence outputs are designed to support Australian Government IRAP assessment preparation. Evidence packages are available on request for government agencies conducting IRAP assessments.

Relevant controls

ISM-1380 — Application control
ISM-0042 — System owners and responsibilities
PSPF Policy 10 — Safeguarding information

Evidence outputs

Application inventory suitable for IRAP evidence packagesOwnership and accountability recordsGovernance decision log

ThreatLynx has not been formally assessed under IRAP. Evidence packages are operational governance references — not IRAP attestations or ASD-endorsed outputs.

Governance mapping table

A structured reference of ThreatLynx governance support areas by regulatory body and framework. Notes column identifies coverage boundaries and limitations.

Regulatory bodyFrameworkControl areasThreatLynx supportEvidence outputNotes
ASD / ACSCEssential EightApplication Control · User App HardeningOAuth application inventory · Governance workflow records · Approved / blocked statusApplication register · Governance decision log · Evidence exportML2 / ML3 readiness support. No endpoint or EDR coverage.
APRACPS 234Information assets · Third-party riskSaaS asset register · Permission scope records · Third-party governance historyAsset register export · Third-party inventory · Governance logPara 15 (information assets) and Para 36 (third-party) support. Not a formal CPS 234 assessment.
OAICPrivacy Act — APPsAPP 1 · APP 8 · APP 11Data scope identification · Vendor jurisdiction data · Governance decisions for PII-access appsPII-scope application list · Cross-border vendor register · Review historyIdentifies apps with personal data access. Does not assess content or constitute legal advice.
ISO / IEC27001:2022A.5.19 · A.8.7 · A.9.4Supplier inventory · Application access register · Governance audit trailVendor inventory · Permission register · Audit logSupports Annex A evidence for subset of controls. Not a replacement for ISMS or ISO certification.
AICPASOC 2CC6.1 · CC9.2Vendor access inventory · Access governance recordsVendor access register · Governance decision logSOC 2 Type II examination planned Q2 2026. Not currently certified.
ASD / DTAIRAP / ISM / PSPFISM-1380 · ISM-0042 · PSPF Policy 10Application control evidence · Ownership records · Governance documentationIRAP evidence package (on request)Evidence package available on request. Not formally IRAP assessed.
DTAHosting Certification FrameworkData sovereignty · ResidencyAustralian (Sydney) target hosting region · Region pinned to Australia at deploy timePer-deployment residency confirmation documentationCustomer security telemetry hosted in Australia (Sydney) as the target region, with residency confirmed per deployment; named US subprocessors for email/billing. Hosting certification not formally assessed.

Coverage designations indicate the nature of operational governance support provided. They do not constitute compliance assessments, legal opinions, or regulatory approvals.

Evidence outputs

ThreatLynx produces structured governance records and evidence exports suitable for internal audit, access review cycles, and regulator evidence requests.

SaaS application inventory

A point-in-time record of all discovered OAuth-connected applications — including application name, vendor, connected users, granted scopes, risk score, and governance status.

CSV exportPDF summaryAPI access

Relevant frameworks

Essential EightCPS 234ISO 27001

OAuth scope register

A structured record of all active OAuth permission grants — scope strings, access type (read / write / delete), sensitivity classification, and whether persistent access is granted.

CSV exportPDF summary

Relevant frameworks

Essential EightPrivacy ActISO 27001

Governance decision log

An append-only log of all governance actions — status changes, owner assignments, rationale capture, and review dates — with actor attribution and ISO 8601 timestamps.

CSV exportPDF audit trailAPI access

Relevant frameworks

CPS 234ISO 27001SOC 2IRAP

AI and agent identity register

A catalogue of applications identified as AI-capable, automation platforms, or non-human identities — with confidence levels, detection signals, and associated governance status.

CSV exportPDF summary

Relevant frameworks

Essential EightCPS 234

Risk posture summary

A scored summary of the application portfolio — applications by risk band (Critical / High / Medium / Low), ungoverned count, open findings, and governance maturity metrics.

PDF executive summaryCSV data

Relevant frameworks

CPS 234ISO 27001SOC 2

Evidence snapshot export

A combined export capturing inventory state, governance decisions, scope records, risk scores, and audit trail at a nominated point in time — suitable for access reviews and regulator evidence requests.

PDF evidence packCSV bundle

Relevant frameworks

CPS 234Essential EightISO 27001IRAP

Evidence outputs are operational governance records produced by ThreatLynx based on discovered OAuth metadata. They should be reviewed by your security, legal, and compliance teams before use in formal audit or regulatory submissions. Evidence does not constitute compliance attestation or legal sign-off.

Important information

The following information is provided to support informed procurement, legal review, and governance decision-making.

About ThreatLynx governance mapping references

ThreatLynx is a governance and visibility platform for SaaS applications and OAuth-connected systems. It is not a certification body, accredited auditor, or regulatory authority.

Framework mappings in this document are rules-based operational references identifying areas where ThreatLynx governance workflows and evidence outputs may support an organisation's readiness activities. They are not compliance assessments, audit opinions, legal determinations, or regulatory endorsements.

Organisations remain solely responsible for their own compliance with applicable laws, regulations, and standards — including the Privacy Act 1988, APRA prudential standards, ASD Essential Eight requirements, and any other applicable framework.

Framework mapping references should be reviewed by qualified security, legal, and compliance advisors before being relied upon in formal governance processes, audit submissions, or regulatory dealings.

APRA-regulated entities

ThreatLynx has not been assessed, endorsed, or accredited by the Australian Prudential Regulation Authority (APRA). CPS 234 alignment references indicate areas of operational support for asset identification and third-party governance — not a formal APRA compliance determination. Regulated entities should engage their APRA relationship manager and compliance function before relying on ThreatLynx output in prudential reporting or self-assessments.

Australian Consumer Law (ACL)

ThreatLynx Pty Ltd makes no representation that use of this platform ensures compliance with any legal obligation. References to "alignment", "mapping available", or "evidence support" describe operational functionality — not legal compliance outcomes or guarantees. Nothing in this document constitutes a warranty, guarantee, or representation under the Australian Consumer Law or any other statute.

Government and IRAP procurement

ThreatLynx has not been formally assessed under IRAP (Information Security Registered Assessors Program). References to IRAP readiness support indicate that governance evidence outputs are designed to support IRAP assessment preparation activities. A formal IRAP assessment by an ASD-listed IRAP assessor is required for government use at Protected level and above.

ISO and SOC 2 certification status

ThreatLynx is designing its security controls with reference to ISO/IEC 27001:2022 and SOC 2 Trust Service Criteria. Formal certification and examination have not yet been completed. "Controls-aligned" and "Planned" designations indicate internal programme intent — not current third-party certification.

Security posture and data residency

Current security capabilities and planned certifications. Procurement teams and security reviewers should note distinctions between operational capabilities and certification status.

CapabilityCurrent statusNotes
Data residencyAustralia (Sydney) · target regionRegion pinned to Australia at deploy time; residency confirmed per customer deployment. Named US subprocessors for email/billing
Encryption at restAuthenticated encryptionFernet (AES-128-CBC + HMAC) with key rotation; per-tenant AWS KMS envelope encryption rolling out
Encryption in transitTLS 1.2 / 1.3All API and web traffic encrypted
Tenant isolationRow-level securityData access controls per workspace tenant
Audit loggingAppend-only governance logActor-attributed, timestamped entries
RBACRole-based access controlAdmin, reviewer, and read-only roles
SOC 2 Type IIPlanned · Q2 2026Examination not yet completed
ISO 27001Controls-alignedFormal certification not yet obtained
IRAP assessmentOn requestEvidence packages available; not IRAP assessed

Security posture information is current as at publication date. Certification status should be verified directly with ThreatLynx for time-sensitive procurement decisions.

What ThreatLynx processes

ThreatLynx processes OAuth grant metadata from workspace admin APIs — application names, client IDs, granted scope strings, user counts, and vendor information. It does not process, store, or access email content, file content, calendar event details, message payloads, or employee activity data. Full details are documented in our Privacy Policy and Terms of Service.

Request a governance review session

We can walk your security, risk, or compliance team through ThreatLynx governance capabilities and framework alignment in your context — no sales pressure, no unsolicited follow-up.

ThreatLynx Governance Mapping Pack · This document is a governance reference only and does not constitute compliance certification, legal advice, or regulatory endorsement.

ThreatLynx Pty Ltd · threatlynx.com.au · © 2026