Trust & Security

Trust is the product.

MineGuard AI is built secure by design, with zero-data-retention AI models, sovereign hosting, data and AI inference in your region, encryption in transit and at rest, and humans in control at every decision gate.

Encrypted in transit & at rest
Zero data retention
Sovereign hosting & AI
Human-in-the-loop

Aligned today. Certification underway.

We already operate to ISO 27001 and SOC 2 Type 2 controls, and formal certification is in progress. We comply with GDPR and the Australian Privacy Act now.

ISO 27001:2022

Certification in progress

Information security management systems — international standard for managing sensitive company information.

SOC 2 Type-2

Audit in progress

Service organisation controls for security, availability, processing integrity, confidentiality, and privacy.

GDPR

Compliant

General Data Protection Regulation — European Union data protection and privacy regulation.

Privacy Act 1988

Compliant

Australian federal privacy legislation governing the handling of personal information by organisations.

Every subprocessor that handles your data already holds independent SOC 2 or ISO 27001 certification. View the subprocessor register →

Your region for hosting, data and AI inference

All three layers of MineGuard AI can run in the region your organisation requires, so evidence, records and AI processing stay under the jurisdiction you choose.

Layer Application hosting Database and files AI inference
MineGuard-managed Australia or Singapore Australia or Singapore Australia or Singapore
Dedicated regional Your chosen region Your chosen region Your chosen region
Your cloud tenant Your own subscription Your own subscription Your own subscription

AI models run through enterprise cloud AI services with zero data retention. If a model is not offered in your region, we agree an in-region alternative with you before go-live.

Aligned to the NIST AI Risk Management Framework

MineGuard Solutions Pty Ltd aligns its AI development and operations to the NIST AI Risk Management Framework 1.0. Our published AI Risk & Compliance Statement explains governance, model lifecycle controls, and continuous monitoring across Govern · Map · Measure · Manage.

It's not a certification; it's a transparent, evidence-backed operating standard.

Download NIST AI RMF Statement (PDF)
01

Govern

Organisational policies, roles, and accountability structures for responsible AI.

02

Map

Contextual understanding of AI risks, impacts, and stakeholder requirements.

03

Measure

Quantitative and qualitative assessment of AI system performance and risk.

04

Manage

Continuous monitoring, response, and improvement of AI risk controls.

AI assists. People decide.

Every MineGuard workflow is built human-in-the-loop: the platform drafts, routes, and surfaces evidence — nothing is published to the field without named human approval.

Step 1

AI Drafts

AI analyses your evidence and generates structured outputs — timelines, root causes, compliance checks, and recommendations.

Step 2

Humans Review

Every AI-generated output is presented for human inspection. Edit, refine, challenge, or reject — your team is always in control.

Step 3

Named Approval

Nothing reaches the field without a named human approver signing off. Full audit trail of who approved what, when.

Your data stays yours.

Enterprise-grade security controls protect your data at every layer.

Encryption in transit and at rest
Role-based access controls (RBAC)
Tenant-level data separation
No model training on your data
Delete on request — your data, your rules
Full audit logging
Hosting, database and AI inference in your chosen region
Continuous monitoring & incident response

Privacy, sovereignty and responsible AI controls

Is customer data used to train public AI models?

No. Client data is not used to train public models. Customer data is handled for the configured workflow and remains subject to agreed access, retention and deletion controls.

Can MineGuard AI run in our country?

Yes. We can deploy the application, database and AI inference in the cloud region your organisation requires, or into your own cloud subscription. Our managed service runs in Australia or Singapore.

Does our data leave the region for AI processing?

Not with a regional or customer-tenant deployment. AI inference runs in the same region as your data, through enterprise AI services with zero data retention. We confirm model availability for your region before go-live.

What sensitive information might be uploaded?

Depending on the workflow, customers may upload incident evidence, witness statements, photos, safety management system documents, procedures, risk registers, verification records and other operational safety material.

How are AI-generated outputs governed?

MineGuard AI is designed around human review, evidence traceability, access controls, audit logs and clear limits. Outputs should be reviewed and approved by competent people before operational use.

Trusted by teams across mining and heavy industry

  • QMIHSC
  • Dyno Nobel
  • South32
  • Aeris
  • Jellinbah
  • Middlemount
  • MMAA
  • Perenti

Logos denote organisations currently piloting MineGuard AI solutions; appearance does not imply commercial endorsement.

Have questions about our security posture?

Request our full security pack or speak with our team about compliance, data residency, and AI governance.