Real-time AI threat detection, cryptographic audit trails, and on-demand regulatory evidence — built for financial institutions that cannot afford to guess.
Every major regulator has published AI-specific requirements. APRA, EU AI Act, MAS, NAIC — all issued in the last 24 months. The question is no longer whether your AI is governed — it is whether you can prove it.
Built specifically for regulated financial institutions. Every layer is independently auditable and maps to the regulatory article it satisfies.
Every agent interaction screened in real time. Manipulation, social engineering, and malicious intent detected before execution — with configurable enforcement from flag to block to human review — across single messages and entire sessions.
Full technical breakdown — architecture, controls, and audit methodology — available in our technical brief. Request it here.
Every interaction recorded in a tamper-evident audit trail that cannot be altered after the fact. Every decision traced back to the exact regulatory requirement it satisfies.
Full technical breakdown — architecture, controls, and audit methodology — available in our technical brief. Request it here.
Every major regulatory framework, covered. Submission-ready evidence packages generated on demand — no consultant, no delay.
Full technical breakdown — architecture, controls, and audit methodology — available in our technical brief. Request it here.
AI risk reporting built for directors, not engineers. Clear summaries and milestone tracking, in language boards can act on.
Full technical breakdown — architecture, controls, and audit methodology — available in our technical brief. Request it here.
Third-party AI models used inside your institution fall under your regulatory obligation. Structured assessment templates for every vendor AI system your organisation touches.
Full technical breakdown — architecture, controls, and audit methodology — available in our technical brief. Request it here.
AI governance mapped automatically to your three lines structure — ownership, oversight, and audit, all documented and ready to evidence.
Full technical breakdown — architecture, controls, and audit methodology — available in our technical brief. Request it here.
Regulators expect proof, not promises. WithinBounds delivers full compliance coverage across every framework that matters to your institution.
Most institutions scramble when an examiner arrives. WithinBounds doesn't. Whatever a regulator wants, you have it — ready, every time.
Book a 30-minute walkthrough. We will show you the audit chain, the threat feed, and the evidence package your institution would hand to any regulator tomorrow.
WithinBounds Pty Ltd ("WithinBounds", "we", "our", "us") operates the AI governance and compliance platform accessible at www.withinbounds.ai and app.withinbounds.ai. This Privacy Policy explains how we collect, use, disclose, and protect personal information in connection with our website, platform, and services.
We are committed to compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), the EU General Data Protection Regulation (GDPR) where applicable, and the Singapore Personal Data Protection Act 2012 (PDPA).
Account information: When you request a demo or create an account, we collect your name, work email address, organisation name, and role title.
Platform usage data: We collect information about how you use the WithinBounds platform — pages visited, features used, session duration, and error logs — to improve our service and provide technical support.
Interaction data processed on your behalf: When your institution's AI agents send interactions to the WithinBounds SDK for assessment, we process the content of those interactions as a data processor under your instruction. We do not use this data for any purpose other than providing the agreed service. Raw interaction inputs are never stored — only hashed identifiers and classification metadata are retained.
Communications: If you contact us by email or through the demo request form, we retain those communications to respond and follow up.
Technical information: IP address, browser type, device type, and cookies. We use strictly necessary cookies for session security and your stored consent preference. Analytics cookies (Google Analytics) are only set if you accept them via the cookie banner — see Section 8 for full details.
We do not sell personal information. We do not use your data for advertising purposes. We do not share your data with third parties except as described in this policy.
We apply jurisdiction-appropriate retention periods to all data:
Audit chain entries are immutable and cannot be deleted during the applicable retention period — this is a regulatory requirement, not a choice. Once the retention period expires, data is deleted in accordance with our data disposal policy.
WithinBounds applies bank-grade security controls to all data we hold. This includes: strict per-tenant data isolation ensuring no cross-tenant data access; cryptographic audit chain ensuring tamper-evidence of all AI governance records; TLS 1.3 in transit; AES-256 at rest; multi-factor authentication required for all platform access; and SOC 2 aligned security controls (CC1–CC8).
We conduct regular security assessments and penetration testing. Our security posture is documented in our SOC 2 Readiness Report, available to enterprise customers on request.
Australian residents: You have the right to access personal information we hold about you, and to request correction of inaccurate information. Contact us at info@withinbounds.ai.
EU residents: Under GDPR, you have the right to access, rectification, erasure (subject to legal retention obligations), portability, and objection to processing. You may also lodge a complaint with your national supervisory authority.
Singapore residents: Under the PDPA, you have the right to access and correct personal data we hold about you.
WithinBounds operates infrastructure in Australia and may use cloud service providers with data centres in other jurisdictions. Where data is transferred outside Australia, we ensure appropriate safeguards are in place in accordance with the Privacy Act 1988 (Cth) and applicable international frameworks.
EU personal data is transferred in compliance with GDPR Chapter V requirements, including Standard Contractual Clauses where applicable.
We use cookies in two categories. You can manage your preferences at any time using the Cookie Preferences link in the footer.
| Cookie | Purpose | Duration | Provider |
|---|---|---|---|
| wb_cookie_consent_v2 | Stores your cookie preferences so you are not asked again | 1 year (localStorage) | WithinBounds |
These cookies are only set if you accept analytics cookies via the cookie banner. They help us understand which pages are visited and how visitors navigate the site. All data is aggregated and does not identify individual visitors.
| Cookie | Purpose | Duration | Provider |
|---|---|---|---|
| _ga | Distinguishes unique visitors for Google Analytics | 2 years | |
| _ga_XXXXXXXXXX | Maintains session state for Google Analytics 4 | 2 years |
Google Analytics is operated by Google LLC. Google may transfer data to the United States and other jurisdictions. Where EU personal data is involved, this transfer is governed by Standard Contractual Clauses. Google's privacy policy is available at policies.google.com/privacy.
We do not use advertising cookies, social media tracking cookies, or any cookies that share your data with third parties for marketing purposes.
Where GDPR applies, we rely on the following lawful bases for processing your personal information:
EU residents have the right to lodge a complaint with their national supervisory authority. A list of EU supervisory authorities is available at edpb.europa.eu.
We use a limited number of third-party service providers (sub-processors) to operate the Service, including cloud infrastructure providers. A current list of sub-processors is available on request by emailing info@withinbounds.ai. We will notify enterprise customers of material changes to our sub-processor list in accordance with our Data Processing Agreement.
For privacy enquiries, data access requests, correction requests, or to report a concern, contact our Privacy Officer:
WithinBounds Pty Ltd
ABN 50 699 438 349 · ACN 699 438 349
Central House, 101 Moray Street, South Melbourne VIC 3205, Australia
info@withinbounds.ai
If you are an Australian resident and your complaint is not resolved to your satisfaction, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
These Terms of Service ("Terms") govern your access to and use of the WithinBounds platform, API, SDK, and associated services (collectively, the "Service") provided by WithinBounds Pty Ltd ("WithinBounds", "we", "us"). By accessing or using the Service, you agree to be bound by these Terms. If you are using the Service on behalf of a financial institution or other organisation, you represent that you have authority to bind that organisation.
WithinBounds provides an AI governance and regulatory compliance platform designed for regulated financial institutions. The Service includes: real-time AI threat detection via the WithinBounds SDK; cryptographic audit trail generation and storage; on-demand regulatory evidence package generation; board-level risk reporting; vendor risk assessment tooling; and associated APIs and documentation.
The Service is designed to assist your institution in meeting obligations under applicable regulatory frameworks including APRA CPS 234, the EU AI Act, MAS FEAT/AIRM, and related requirements. The Service does not constitute legal or compliance advice. Your institution retains responsibility for its regulatory compliance obligations.
You may use the Service solely for your institution's internal AI governance and compliance purposes, in accordance with these Terms and all applicable laws and regulations. You must not:
Your institution is the data controller for all interaction data and personal information processed through the Service. WithinBounds acts as a data processor on your behalf. Our data processing practices are governed by our Privacy Policy and, for enterprise customers, a Data Processing Agreement which supplements these Terms.
Raw interaction inputs submitted to the WithinBounds SDK are not stored. Only hashed identifiers, classification metadata, and audit chain entries are retained. The cryptographic audit chain is immutable by design and cannot be altered or deleted during the applicable regulatory retention period.
WithinBounds retains all intellectual property rights in the Service, including the platform, SDK, detection algorithms, regulatory mapping knowledge base, and all associated documentation. These Terms do not grant you any rights in WithinBounds' intellectual property other than the limited licence to use the Service as described herein.
You retain ownership of all data your institution submits to the Service. You grant WithinBounds a limited licence to process that data solely for the purpose of providing the Service.
We will use commercially reasonable efforts to maintain Service availability. Planned maintenance will be communicated in advance where possible. We do not warrant uninterrupted or error-free operation of the Service. Our target availability SLA for enterprise customers is specified in your Service Agreement.
The Service is provided "as is" and "as available". To the maximum extent permitted by law, WithinBounds disclaims all warranties, express or implied, including warranties of merchantability, fitness for a particular purpose, and non-infringement.
To the maximum extent permitted by applicable law, WithinBounds' total liability for any claim arising out of or relating to these Terms or the Service shall not exceed the amounts paid by you to WithinBounds in the twelve months preceding the claim.
You acknowledge that the Service generates evidence packages and audit trails intended for regulatory purposes. You are responsible for reviewing all generated documentation before submitting it to a regulator or auditor. WithinBounds makes no representation that any generated documentation will be accepted by any particular regulatory authority.
These Terms apply for the duration of your use of the Service. Either party may terminate access for material breach upon written notice if the breach is not remedied within 30 days. Upon termination, your right to use the Service ceases immediately. Data retained for regulatory compliance purposes will be held for the applicable retention period before deletion.
These Terms are governed by the laws of New South Wales, Australia. Any disputes will be subject to the exclusive jurisdiction of the courts of New South Wales, Australia, unless otherwise agreed in writing.
We may update these Terms from time to time. Material changes will be communicated by email to the registered account holder. Continued use of the Service after the effective date of changes constitutes acceptance of the updated Terms.
For questions about these Terms, contact info@withinbounds.ai.
WithinBounds Pty Ltd · ABN 50 699 438 349 · Central House, 101 Moray Street, South Melbourne VIC 3205, Australia