// NSW Government Vendor Due Diligence — Sovereign Architecture

Forensic Discovery of Personal Information
Across Your Entire Data Estate.

NexiGuard Sentinel is a zero-impact, on-premise daemon engineered with Rust and WASM to secure Australia's most critical unstructured data.

Initiate Deep Scan Now
// Operational Flow

Three Steps to Forensic Clarity.

From deployment to a PIA-ready report — with no changes to your production environment.

Deploy

Drop the self-contained binary onto any Windows Server or Linux host. No installer, no network configuration, no persistent service, and no elevated permissions beyond read access to the target volume.

Scan

Sentinel traverses your target volume in Ghost Mode — reading every file, image, and document without modifying access timestamps or triggering a single backup event. Fully invisible to your existing infrastructure.

Report

Receive a structured findings report itemising every PII match by file path, data type, confidence tier, and forensic metadata — formatted for direct use in a Privacy Impact Assessment.

// Operational Context

Why NexiGuard Sentinel?

Most enterprise tools were not designed for what your archive actually contains.

The Blind Spot

Standard scanners miss PII in unstructured data, scanned forms, and legacy images. We uncover the "Dark Data" competitors can't see.

Infrastructure Risk

Enterprise tools trigger recursive backup loops, bloat storage costs, and lock production files. NexiGuard operates in "Ghost Mode"—invisible to your existing backups.

Sovereign Case

Built in Australia, NexiGuard provides a sovereign solution with zero data egress. Your data stays on your LAN, where it belongs.

// Core Architecture

Engineered for Invisible,
Advanced Observability.

// 01

Forensic Ghost Mode

Kernel-level timestamp preservation via Win32 SetFileTime ensures zero backup triggers and full forensic timeline integrity. Your scan leaves no trace it occurred.

// 02

Localized WASM OCR

Integrated, high-performance local OCR layer scans image-based PII, legacy forms, and handwritten entries with zero external dependencies. All processing stays on-device.

// 03

Unicode Normalization

Flattens character substitution and leetspeak obfuscation before processing—defeating attempts to conceal sensitive data through encoding variance or homoglyph injection.

// 04

Zero Data Egress

Sovereign Australian architecture designed for compliance with the NSW PPIPA. Guaranteed zero metadata leakage to public cloud infrastructure, ever.

// Detection Capability

What Sentinel Finds.

Engineered to surface the full spectrum of Australian PII across structured records, scanned documents, and unstructured legacy archives.

Government Identifiers
Tax File Number (TFN) Medicare Number Australian Passport Driver's Licence ABN / ACN Centrelink CRN
Personal Information
Full Name Date of Birth Residential Address Phone Number Email Address Gender Marker
Financial Data
BSB + Account Number Credit Card Number Expiry + CVV Patterns Bank Statement Data Superannuation USI
Health Records
Medicare Card IHI (Individual Healthcare ID) Health Fund Member ID Clinical Record References DVA File Number
Visual & Unstructured (OCR)
Scanned PDF Forms Handwritten Entries Image-Embedded Text Fax & Photocopy Records Redacted-but-Readable Fields
Legacy & Archive Formats
Mainframe Exports Flat-File CSV Dumps Unindexed File Shares Proprietary DB Exports Tape-Migrated Archives
// Regulatory Alignment

Built for the Australian Compliance Landscape.

NexiGuard's architecture is designed around the specific obligations facing NSW Government agencies and their supply chain.

Federal — Cth

Privacy Act 1988

Core federal legislation governing the collection, use, and disclosure of personal information by Commonwealth agencies and private sector organisations with turnover above $3M.

Federal — Cth

Australian Privacy Principles (APPs 1–13)

Sentinel directly supports obligations under APPs 1, 4, 6, 11, and 12 — covering data minimisation, unsolicited information, secondary use, security, and access rights.

NSW State

Privacy and Personal Information Protection Act 1998 (PPIPA)

Governs public sector agencies across NSW. Sentinel's zero-egress, on-premise architecture ensures compliance by design — no personal data leaves the agency boundary.

NSW Health

Health Records and Information Privacy Act 2002 (HRIPA)

Covers health information held by NSW public and private health organisations. Sentinel's OCR layer specifically targets clinical record formats common in legacy health archives.

NSW Government

NSW Cyber Security Policy (2019)

Sentinel's Ghost Mode and append-only audit log directly support the Policy's data asset management and incident preparedness requirements for NSW Government agencies.

International

ISO/IEC 27001:2022 Alignment

Architecture supports Annex A controls across access management (A.9), operations security (A.12), and information classification (A.8) without requiring a standalone certification.

Australian Federal

ASD ISM / IRAP Posture

Designed for alignment with the Australian Government Information Security Manual and suitable for inclusion in IRAP-assessed environments at PROTECTED and below.

// Technical Specification

Deployment & Report Output.

Everything your IT security team needs to assess operational risk before procurement approval.

// Deployment Requirements

OS Support Windows Server 2016 / 2019 / 2022  ·  Windows 10/11  ·  Ubuntu 20.04+  ·  RHEL 8+
Distribution Single self-contained binary — no installer, no runtime dependencies, no framework requirements
Architecture x86_64 (primary)  ·  ARM64 on roadmap
Network Zero outbound connections required — fully air-gap and classified-network compatible
Permissions Read-only volume access — no write permissions, no kernel module, no persistent service
Memory Ultra-low footprint — optimised for sustained, high-volume scanning without memory pressure on production hosts
Scheduling CLI-driven — compatible with Windows Task Scheduler and POSIX cron
Audit Log Append-only local manifest — tamper-evident record of scan parameters, scope, and runtime

// Report Output

Formats JSON  ·  CSV  ·  Plain-text summary  ·  PDF executive report
Per Finding File path  ·  PII category  ·  Match confidence tier  ·  File type  ·  Byte offset  ·  Preserved original timestamps
PIA Ready Structured output designed for direct submission in a Privacy Impact Assessment under PPIPA and the APPs
Confidence Tiers High (checksum-validated)  ·  Medium (pattern-matched)  ·  Low (contextual heuristic) — each tier independently filterable
Redaction Map Optional output: precise byte-range map for downstream redaction tooling — no redaction performed by Sentinel itself
Scan Manifest Signed record of operator identity, scan parameters, target scope, file count, and total runtime — suitable for chain-of-custody documentation
Retention All output stored locally at a path you specify — Sentinel retains nothing after process exit
// Secure Channel

Request a Confidential Data Audit.

Verify NexiGuard's precision on a targeted, read-only volume. Expect a direct response within one business day.

READ-ONLY  ·  NON-DESTRUCTIVE  ·  NDA PROTECTED

All communications are treated with strict confidentiality.