The Maelstrom AI Trust Centre

This Trust Centre shows how we protect data, the legal terms we offer, and the companies we rely on. Our Information Security Management System is aligned to ISO/IEC 27001:2022. Customers, prospects and auditors can request the detailed ISMS documents.

The downpipes vendor security pack

Running a vendor security review of downpipes, our no-custody Cloudflare backup and disaster-recovery platform? The evidence pack gathers the architecture, security posture, control mappings, the shared-responsibility boundary and a pre-answered questionnaire in one place, scoped to downpipes. Free, no NDA, and downloadable as a PDF.

Check our commitments without asking

We publish the security overview, our privacy notices, our data processing agreements and our sub-processor list. Anyone can read them, with no sales call, no NDA, and no login.

The detailed ISMS documents describe our internal systems in depth: the scope statement, the Statement of Applicability, the risk register, our policies and procedures, and supporting evidence. We share these with customers, prospects and auditors on request, under a non-disclosure agreement.

Want a detailed ISMS document? Email support@maelstrom.au and tell us which document you need and why.

One management system, many regimes

Our ISMS is structured to the ISO/IEC 27001:2022 management-system clauses and Annex A controls. We will pursue certification when it is commercially justified; until an accredited body has issued a certificate we describe this as alignment, not certification. We keep a mapping to each standard below, with the evidence that supports it, and share it on request.

ISO/IEC 27001:2022

Information security management system. Structure, Annex A controls, and risk methodology. Alignment, not certification. Statement of Applicability available on request.

ISO/IEC 27701:2019

Privacy information management extension. Annex A controls mapped for our role as a controller, and Annex B controls for our role as a processor.

GDPR & UK GDPR

Designed to meet the General Data Protection Regulation. Lawful bases, data subject rights, and records of processing.

CCPA

California Consumer Privacy Act. Self-assessed compliance statement, available on request.

CSA Cloud Controls Matrix

Self-assessment available on request.

What we publish

13 public documents. The other ISMS documents are available on request.

Who operates this ISMS

The Information Security Management System described here is owned and operated by Maelstrom AI, the company behind downpipes, our no-custody Cloudflare backup and disaster-recovery platform. This Trust Centre governs the company that builds and runs it.

Questions about a control, a mapping, or a data processing arrangement are welcome. Reach us through the contact page.

EntityMaelstrom AI Pty Ltd ATF Maelstrom AI Holding Trust
ABN61 633 823 792
JurisdictionVictoria, Australia
AddressPO Box 169, St Arnaud VIC 3478