No. When Annie is deployed on your infrastructure, all inference — the process of generating outputs from your data — happens locally, on your hardware. Your prompts, context, and results never traverse external networks or reach Evari's systems.
Specifically:
- Inference data — prompts and responses are processed entirely within your environment
- Cognition Stream — fine-tuning runs on your infrastructure using data you have accumulated; training data does not leave your environment
- Judgment Panel — consensus processing happens between models running on your infrastructure
- Telemetry — optional; can be fully disabled for air-gapped deployments
Annie does not use a software-as-a-service model where requests are routed to a central processing environment. The platform runs on your infrastructure; Evari does not have access to your inference traffic.
Annie does not use your data to train shared models. Any fine-tuning through the Cognition Stream uses your data to improve models running on your infrastructure only — those improvements stay within your environment and are never shared with other customers.
To be precise:
- Shared model training — your data is never used to update any Workforce Foundation Model or shared model deployed to other customers
- Cognition Stream — fine-tuning runs locally, using data accumulated from your own workflows, producing model improvements that apply only to your deployment
- Evari access — Evari does not have access to your inference data, prompts, or fine-tuning datasets unless you explicitly grant access for a specific support or audit purpose
This is a fundamental property of Annie's sovereign architecture: your AI system improves on your data, for your purposes, and the results remain entirely yours.
Annie's compliance posture is designed for regulated Australian industries. Current certifications and framework alignment include:
ISO 27001 — The Annie platform operates under an ISO 27001-certified information security management system, covering risk management, access control, incident response, and continuous improvement.
Australian Privacy Act 1988 — Annie's architecture and operations are designed to comply with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs). Data handling, access controls, and retention policies are structured accordingly.
ASD Information Security Manual (ISM) alignment — Annie's deployment architecture — including air-gap capability, access control, and audit logging — is aligned with ASD ISM controls, positioning Annie for deployment in government environments where PROTECTED classification is relevant.
APRA CPS 234 design support — Annie's data residency, access controls, and incident response design are structured to support APRA CPS 234 compliance for regulated financial services entities.
For specific compliance documentation, contact us during the enterprise briefing process.
APRA CPS 234 requires regulated entities to maintain information security capabilities commensurate with the threats facing their information assets, and to notify APRA of material information security incidents.
Annie supports CPS 234 compliance in four key areas:
Data residency — Annie can be deployed on Australian infrastructure with no cross-border data transfers, supporting the control requirements CPS 234 imposes on cloud and outsourced arrangements.
Access controls — Annie's role-based access control and audit logging are designed to meet CPS 234's requirements for controlling and monitoring access to information assets.
Third-party risk — Because Annie's inference runs on your infrastructure rather than a third-party cloud, the AI inference function is not treated as a third-party arrangement for CPS 234 purposes. This substantially reduces the third-party risk management burden associated with AI adoption.
Incident documentation — Annie's audit trail and Judgment Panel records support the documentation requirements that underpin CPS 234 incident assessment and notification obligations.
Annie does not provide legal or compliance advice. Engage your compliance team and external advisers to assess CPS 234 applicability to your specific deployment.
Annie is architecturally designed to support PROTECTED-level workloads. Key properties that make this possible:
- Air-gappable — Annie can operate with zero external network connectivity; no external AI APIs, no cloud-connected inference
- On-premise deployment — Annie runs on your hardware, within your secure facility, with no external dependency after initial deployment
- ASD ISM alignment — Annie's access controls, audit logging, and data handling are aligned with ASD Information Security Manual controls
- Sovereign model weights — Workforce Foundation Models are trained from scratch; they do not inherit weights from any US-incorporated AI provider
- Verifiable audit trail — the Judgment Panel produces a structured, tamper-evident record of all significant outputs
PROTECTED accreditation is a process that involves your organisation, your hosting provider, and the Australian Signals Directorate. Annie's architecture is designed to support that process — accreditation itself is not a product Annie provides.
Contact us for a confidential enterprise briefing to discuss PROTECTED-level deployment requirements.