Repositioned compliance plans for mid-market security

Auditor-ready evidence monitoring mapped to APRA standards, built to secure your AI posture.

Essentials

For Australian mid-market entities needing basic visibility and audit-ready reports.

$1500/per month

50 – 150 staff · 1 org

Secure staging slot
  • 6 Telemetry capture vectors
  • APRA CPS 234 & ASD E8 mapping
  • Privacy Act 1988 mapping
  • Unified discovery feed
  • Real-time leakage alerts (Email)
  • One-click signed PDF audit packs
  • 90-day data retention
  • Sydney (ap-southeast-2) residency
Recommended

Professional

Comprehensive compliance monitoring and risk posture tracking for regulated entities.

$3500/per month

150 – 500 staff · 2 orgs

Secure staging slot
  • Everything in Essentials
  • APRA CPS 230 operational risk rules
  • Real-time leakage alerts (Slack + Teams)
  • Risk posture reporting & benchmarking
  • Incident timeline forensics
  • Auditor-portal read-only access
  • 1-year data retention
  • Priority 24/7 compliance support

Enterprise

Custom compliance monitoring, dedicated infrastructure, and advanced integrations.

$7,500 - 15,000/per month

500+ staff or regulated entities

Talk to sales
  • Everything in Professional
  • Unlimited orgs & custom rules
  • Private Link & custom VPC hosting
  • Custom regulatory mappings
  • SIEM integrations (Beta Splunk/Sentinel)
  • SSO / SAML authentication
  • 3-year data retention SLA
  • Dedicated compliance advisor

Framework control matrix & features

FeatureEssentialsProfessionalEnterprise
Telemetry capture vectors (6)
Unified discovery feed
APRA CPS 234 & ASD E8
APRA CPS 230 mapping
Privacy Act 1988 provisions
One-click signed PDF audit packs
Slack & Teams alertsEmail only
Incident timelines & forensics
Auditor portal access
SSO / SAML
SIEM integrationsBetaCustom (Beta)
Data retention90 days1 year3 years SLA

Compliance & Security FAQs

Where is Stack Breach data stored? Do you support Australian Data Residency?
Yes. By default, all Australian customer telemetry, violations, and report data are stored and processed strictly within the AWS ap-southeast-2 (Sydney) region. This ensures compliance with local data sovereignty regulations and sector-specific rules.
What is your SOC 2 Type II certification status?
Stack Breach is currently SOC 2 Type I compliant. Our formal SOC 2 Type II auditing window is currently underway and is scheduled to be completed by Q4 2026. Enterprise clients can request our current Type I report and interim compliance bridge letters.
Do you integrate with corporate SIEM/SOAR platforms?
Yes. Native connectors for Microsoft Sentinel and Splunk are currently in beta, allowing IT managers to stream AI violations and policy alerts directly into their primary security operations center. Full general availability is scheduled for late Q3 2026.
Does Stack Breach read raw message content or prompts?
No. Our network proxy and browser agents capture outbound connection metadata (endpoints, timestamps, data volume, and domain risk profiles) without inspecting or decrypting raw text payloads. This guarantees employee privacy while validating strict compliance controls.
How does the APRA CPS 230 deadline affect our organization?
APRA's CPS 230 vendor contract deadline passed on 1 July 2026. Regulated entities must maintain active, verifiable audit trails of all service providers (including AI models). Stack Breach automatically generates these cryptographically-signed compliance evidence packs.