Governance isn't our fine print. It's our product.
Every claim on this page is one your board, auditor or regulator can test. This is how we run our own firm, how we configure every deployment, and the standards each engagement is delivered against.
The rules every Keelix agent runs under
Operational, never professional
Agents take the document- and transaction-heavy back office: intake, notes, reports, claims, scheduling, comms. Clinical judgments, credit decisions and regulated advice stay with qualified humans — that line is drawn in writing for every agent we build.
Human-in-the-loop by default
Every agent output is a reviewable draft. Signatures, submissions to regulators or funders, and substantive client content are always human-approved. Exception-only review is earned through measured reliability, never assumed.
Audit-trailed & monitored
Agents log what they read, produced and who approved it. Output quality is monitored continuously — through the build and under the ongoing retainer — so reliability is a measured number, not a feeling.
Held to the standard we implement
Our methodology maps to the frameworks Australian organisations already trust — and we are putting our own firm through the same certification we help clients prepare for.
ISO/IEC 27001 (information security). Engagements are delivered against an ISO 27001-aligned methodology. Our own ISMS is operating and independent certification by a JAS-ANZ-accredited body is underway.
ISO/IEC 42001 (AI management systems). The governance frameworks we stand up for clients are built on ISO 42001 and the National AI Centre's Guidance for AI Adoption. Our own 42001 certification follows our 27001 audit.
Privacy Act 1988, APPs & Notifiable Data Breaches. We maintain our own privacy policy, secure handling of any client personal information we touch, and a breach-response plan aligned to the NDB scheme. Cross-border disclosure (APP 8) is assessed on every engagement.
Data residency, configured per client. Every deployment follows a documented standard for the commercial tier, data-retention and residency settings that match your obligations — confirmed before anything is switched on, not discovered after.
Platform credentials. We build on Claude and run our own firm on it; Claude Partner Network membership and platform certification are in progress, alongside Microsoft security and compliance credentials (SC-300, SC-400) for the M365 estates we secure.
The independence rule. We de-risk your path to certification — we never issue it. Advisory and audit roles stay separate, so our recommendations are never marking their own homework.
Built around the rules of the industries we serve
Regulated sectors don't need generic AI policies — they need agents designed around the specific artefacts their regulator asks for. Sector compliance capability is being built out alongside our certification programme.
Broking & financial services
Best Interests Duty documentation, ASIC record-keeping expectations and APRA awareness — including CPS 234 (information security) and CPS 230 (operational risk) where a client sits in an APRA-regulated group, with material-service-provider contract terms handled up front.
Allied health & NDIS
NDIS Practice Standards evidence, incident and complaints handling, and the audit-pack discipline the Quality and Safeguards Commission expects. Health information is treated as sensitive information under the Privacy Act, with stricter handling by default.
Aged care
Reporting and accountability under the new Aged Care Act — board-level accountability and public disclosure obligations — built into agent design so compliance evidence assembles continuously, not in a pre-audit scramble.
Government, critical infrastructure or health data in scope? Engagements touching government systems (ISM, Essential Eight), SOCI-covered assets or health information are flagged early — they reshape scope, and we'd rather tell you that in week one than discover it in week six.
The pre-engagement gate we run on ourselves
Before we sign, every engagement passes a documented checklist — because the fastest way to architect a client into breach is to skip the boring questions.
- ✓Client type identified — standard, APRA-regulated, critical infrastructure, government or health — and the obligations that switch on with it.
- ✓Data in scope classified — personal, sensitive or health information, the volumes involved, and the systems it lives in.
- ✓Residency confirmed — where data must be processed and stored, and that the planned platform configuration meets it.
- ✓Cover and contract fit checked — professional indemnity adequate to the engagement, scope and liability terms in place, sector-specific clauses added where required.
- ✓Independence preserved — we are advising and remediating, never certifying the same work.
Put our posture in front of your board
Ask us the hard questions — data handling, residency, breach response, audit trails. That conversation is the fastest way to know if we're who we say we are.
Certification claims on this page describe work in progress and are updated as milestones are reached. Nothing on this page is legal advice; regulatory obligations sit primarily with data controllers, and we recommend independent legal review for your specific circumstances.