ALVOR
Platform
Advisory
PricingBlog
Get Demo
ALVOR
Platform
Advisory
PricingBlog
Get Demo

For Australian organisations

Built in Australia for Australian obligations.

Alvor Pty Ltd is a Melbourne company. The platform runs on a dedicated instance in the Sydney region or on your own servers, and it carries the frameworks Australian teams are held to: the Essential Eight, the ISM, APRA CPS 234, ISO 27001, in one record, with evidence attached once.

Get DemoThe obligation map

Your instance

ap-southeast-2 · Sydney

Tenancy

Dedicated

Database

Yours alone

Backups

Nightly, in region

AI provider

Your key, your region

Sydney regionSelf-hostedSingle-tenantBYOM AI

Or the same platform on your own servers, or air-gapped, scoped per engagement.

The obligation map

Four kinds of Australian organisation, and what each is held to.

Most of the frameworks below are asked for by someone specific: a prime, a regulator, an agency's authorising officer, a customer's procurement team. The right-hand column says how Alvor helps with each.

Government and defence suppliers

  • Essential Eight to ML2

    PSPF Policy 10; primes pass it down by contract

    Ships at ML1 to ML3

  • The ISM

    The control manual behind every authorisation

    Added in ASD's own structure

  • IRAP assessment

    Cloud, outsourced ICT and gateway systems up to SECRET

    The record the assessor reads

APRA-regulated finance

  • CPS 234 Information Security

    In force since 1 July 2019; 72-hour incident notification

    Ships in the standard's own wording

  • CPS 230 Operational Risk

    In force since 1 July 2025; existing contracts from 1 July 2026

    Readiness with Alvor Advisory

Critical infrastructure

  • SOCI Act

    Risk management program obligations for responsible entities

    Readiness with Alvor Advisory

  • Essential Eight and ISM

    Increasingly written into sector rules and customer contracts

    Ships at ML1 to ML3

Everyone

  • Privacy Act and the NDB scheme

    Notifiable data breaches; OAIC recorded 1,205 in 2025

    Incident and risk records

  • ISO 27001:2022

    Certified by a JAS-ANZ accredited body; the questionnaire answer

    Ships with every Annex A control

  • Customer security questionnaires

    The obligation nobody legislated and everybody has

    Vendor portal

One record

Evidence attached once, read by every framework you answer to.

The Essential Eight at every maturity level, ISO 27001:2022 with every Annex A control, and APRA CPS 234 in the standard's own wording install from the library. You can add any framework in Alvor, so the ISM goes in with ASD's own structure and behaves like the rest.

A crosswalk maps controls between installed frameworks, so the MFA evidence you attach for the Essential Eight is the MFA evidence ISO 27001 and CPS 234 read. Status does not propagate across a crosswalk. Each framework is assessed against its own wording, which is what an auditor will hold you to anyway.

Evidence

Entra ID MFA policy export

Owner

Identity lead

Valid until

12 Mar 2027

Essential Eight

ML1 to ML3

In the library

ISO 27001:2022

Every Annex A control

In the library

APRA CPS 234

The standard's wording

In the library

The ISM

Added in ASD's structure

Add any framework

ISO 27001 in Australia

Certified by a JAS-ANZ accredited body, not by a tool.

ISO 27001 is the answer to most customer questionnaires and the common base under the Australian frameworks. Four things to have straight before you start.

The standard

AS/NZS ISO/IEC 27001:2023 adopts ISO/IEC 27001:2022 identically, with the 2024 climate amendment.

Who certifies

A certification body accredited by JAS-ANZ, the joint accreditation body for Australia and New Zealand. Registers are public.

The old edition

Certificates against the 2013 edition ceased to be valid after 31 October 2025. A supplier still citing one is out of date.

What it is not

There is no equivalence between ISO 27001 and the ISM or the Essential Eight. Government buyers will ask for both.

Free Statement of Applicability builderISO 27001 in Alvor

Where it runs

Sydney, your data centre, or nowhere near the internet.

Alvor is single-tenant only. There is no shared database and no multi-tenant tier to opt out of. Where the instance lives is a parameter, and the AI provider is your key in your region.

Dedicated cloud instance in Sydney

One instance per customer in the AWS region you choose, including ap-southeast-2: your own database and cache on an encrypted volume, nightly backups in region, a known-good snapshot before every release.

On-premise

The same containerised platform, all eight modules, run by your own team on infrastructure you control inside your own network. For entities whose data cannot leave.

Air-gapped

The same platform with no path to the internet. AI runs on a model you host, with vLLM, Ollama or any OpenAI-compatible endpoint, or not at all.

Deployment modelsSelf-hosted AI models

Advisory

Engagements run by people who work in these frameworks.

Alvor Advisory is the same team, on the same record. Each engagement is scoped on its own and ends with evidence in the platform rather than a slide deck.

APRA CPS 230 and CPS 234 readiness

Control-by-control gap registers, critical operations and service-provider risk, and a board-ready assurance summary.

SOCI readiness

The critical infrastructure risk management program, evidenced before the responsible entity attests.

Identity and access against the Essential Eight

Privileged access and MFA measured against the strategies and CPS 234's expectations, mapped across to ISO 27001.

SSP as a Service

The authorisation package for an ISM or IRAP engagement, written from the record and then handed to an independent assessor.

Questions

Common questions about Alvor in Australia

On a dedicated single-tenant instance in the AWS region you choose, including Sydney (ap-southeast-2), with your own database and cache on an encrypted volume and nightly backups in region. If data cannot leave your network, the same platform runs on your own servers or air-gapped.

Get started

See how Alvor works for your role

Whether you lead security, run IT, manage compliance, or sit in the C-suite - we'll show you your view.

Request DemoView Pricing
ALVOR

Security architecture management and compliance: connected into one source of truth.

Security,
Simplified.

Platform

  • Overview
  • AI Assistant
  • Secure by Design
  • Asset Management
  • Risk Management
  • Compliance
  • Policy
  • Security Management
  • Third-Party Risk Management
  • Business Continuity

Capabilities

  • Security Architecture
  • Security Design Review
  • Threat Modeling
  • Dependency Mapping
  • Data Governance
  • Components & SBOM
  • System Security Plan
  • Deployment models

Solutions

  • All solutions
  • CISO
  • Security architect
  • GRC lead
  • Engineering leader
  • Startups
  • Mid-Market
  • Enterprise
  • Regulated & Sovereign
  • Australia

Frameworks

  • ISO 27001
  • SOC 2
  • NIST CSF
  • HIPAA
  • GDPR
  • ISM
  • IRAP
  • Essential Eight
  • ASD Essentials
  • SABSA
  • PCI DSS
  • CMMC
  • FedRAMP
  • Control alignment

Advisory

  • Advisory overview
  • Assess
  • Architect
  • Build
  • Operate
  • All engagements

Company

  • About
  • Blog
  • Security
  • Pricing
  • Compare Alvor

© 2026 Alvor Pty Ltd · ABN 40 700 022 546 · All rights reserved.

PrivacyTermsCookie PolicyDisclosure