The Maelstrom AI Trust Centre
This Trust Centre shows how we protect data, the legal terms we offer, and the companies we rely on. Our Information Security Management System is aligned to ISO/IEC 27001:2022. Customers, prospects and auditors can request the detailed ISMS documents.
The downpipes vendor security pack
Running a vendor security review of downpipes, our no-custody Cloudflare backup and disaster-recovery platform? The evidence pack gathers the architecture, security posture, control mappings, the shared-responsibility boundary and a pre-answered questionnaire in one place, scoped to downpipes. Free, no NDA, and downloadable as a PDF.
Check our commitments without asking
We publish the security overview, our privacy notices, our data processing agreements and our sub-processor list. Anyone can read them, with no sales call, no NDA, and no login.
The detailed ISMS documents describe our internal systems in depth: the scope statement, the Statement of Applicability, the risk register, our policies and procedures, and supporting evidence. We share these with customers, prospects and auditors on request, under a non-disclosure agreement.
One management system, many regimes
Our ISMS is structured to the ISO/IEC 27001:2022 management-system clauses and Annex A controls. We will pursue certification when it is commercially justified; until an accredited body has issued a certificate we describe this as alignment, not certification. We keep a mapping to each standard below, with the evidence that supports it, and share it on request.
ISO/IEC 27001:2022
Information security management system. Structure, Annex A controls, and risk methodology. Alignment, not certification. Statement of Applicability available on request.
ISO/IEC 27701:2019
Privacy information management extension. Annex A controls mapped for our role as a controller, and Annex B controls for our role as a processor.
GDPR & UK GDPR
Designed to meet the General Data Protection Regulation. Lawful bases, data subject rights, and records of processing.
CCPA
California Consumer Privacy Act. Self-assessed compliance statement, available on request.
CSA Cloud Controls Matrix
Self-assessment available on request.
What we publish
13 public documents. The other ISMS documents are available on request.
Who operates this ISMS
The Information Security Management System described here is owned and operated by Maelstrom AI, the company behind downpipes, our no-custody Cloudflare backup and disaster-recovery platform. This Trust Centre governs the company that builds and runs it.
Questions about a control, a mapping, or a data processing arrangement are welcome. Reach us through the contact page.
| Entity | Maelstrom AI Pty Ltd ATF Maelstrom AI Holding Trust |
| ABN | 61 633 823 792 |
| Jurisdiction | Victoria, Australia |
| Address | PO Box 169, St Arnaud VIC 3478 |