Repositioned compliance plans for mid-market security
Auditor-ready evidence monitoring mapped to APRA standards, built to secure your AI posture.
Essentials
For Australian mid-market entities needing basic visibility and audit-ready reports.
$1500/per month
50 – 150 staff · 1 org
- 6 Telemetry capture vectors
- APRA CPS 234 & ASD E8 mapping
- Privacy Act 1988 mapping
- Unified discovery feed
- Real-time leakage alerts (Email)
- One-click signed PDF audit packs
- 90-day data retention
- Sydney (ap-southeast-2) residency
Recommended
Professional
Comprehensive compliance monitoring and risk posture tracking for regulated entities.
$3500/per month
150 – 500 staff · 2 orgs
- Everything in Essentials
- APRA CPS 230 operational risk rules
- Real-time leakage alerts (Slack + Teams)
- Risk posture reporting & benchmarking
- Incident timeline forensics
- Auditor-portal read-only access
- 1-year data retention
- Priority 24/7 compliance support
Enterprise
Custom compliance monitoring, dedicated infrastructure, and advanced integrations.
$7,500 - 15,000/per month
500+ staff or regulated entities
- Everything in Professional
- Unlimited orgs & custom rules
- Private Link & custom VPC hosting
- Custom regulatory mappings
- SIEM integrations (Beta Splunk/Sentinel)
- SSO / SAML authentication
- 3-year data retention SLA
- Dedicated compliance advisor
Framework control matrix & features
| Feature | Essentials | Professional | Enterprise |
|---|---|---|---|
| Telemetry capture vectors (6) | |||
| Unified discovery feed | |||
| APRA CPS 234 & ASD E8 | |||
| APRA CPS 230 mapping | |||
| Privacy Act 1988 provisions | |||
| One-click signed PDF audit packs | |||
| Slack & Teams alerts | Email only | ||
| Incident timelines & forensics | |||
| Auditor portal access | |||
| SSO / SAML | |||
| SIEM integrations | Beta | Custom (Beta) | |
| Data retention | 90 days | 1 year | 3 years SLA |
Compliance & Security FAQs
Where is Stack Breach data stored? Do you support Australian Data Residency?
Yes. By default, all Australian customer telemetry, violations, and report data are stored and processed strictly within the AWS ap-southeast-2 (Sydney) region. This ensures compliance with local data sovereignty regulations and sector-specific rules.
What is your SOC 2 Type II certification status?
Stack Breach is currently SOC 2 Type I compliant. Our formal SOC 2 Type II auditing window is currently underway and is scheduled to be completed by Q4 2026. Enterprise clients can request our current Type I report and interim compliance bridge letters.
Do you integrate with corporate SIEM/SOAR platforms?
Yes. Native connectors for Microsoft Sentinel and Splunk are currently in beta, allowing IT managers to stream AI violations and policy alerts directly into their primary security operations center. Full general availability is scheduled for late Q3 2026.
Does Stack Breach read raw message content or prompts?
No. Our network proxy and browser agents capture outbound connection metadata (endpoints, timestamps, data volume, and domain risk profiles) without inspecting or decrypting raw text payloads. This guarantees employee privacy while validating strict compliance controls.
How does the APRA CPS 230 deadline affect our organization?
APRA's CPS 230 vendor contract deadline passed on 1 July 2026. Regulated entities must maintain active, verifiable audit trails of all service providers (including AI models). Stack Breach automatically generates these cryptographically-signed compliance evidence packs.