# AES Tech: full content reference > Independent AI tool reviews, ranked buyer guides, and practical comparison tables for teams that need the right software before they spend. Operated by Australian Enterprise Services (Australia). Reviews are independent and hands-on. Some outbound links are affiliate links, marked rel="sponsored". Canonical site: https://aestech.com.au # AI tool reviews ## AI Writing ### ChatGPT (4.7/5) - https://aestech.com.au/tools/chatgpt/ Vendor: OpenAI. Pricing: Free / $20mo. Free tier: yes. Best for: All-round writing, brainstorming, and everyday tasks. Verdict: undefined Pros: Best-known, huge ecosystem; Strong general writing & reasoning; Voice, image, and data tools built in. Cons: Can be generic without good prompting; Usage limits on the free tier. ### Claude (4.8/5) - https://aestech.com.au/tools/claude/ Vendor: Anthropic. Pricing: Free / $20mo. Free tier: yes. Best for: Long-form writing, analysis, and careful reasoning. Verdict: undefined Pros: Excellent long-form & nuanced writing; Large context window; Strong at detailed instructions. Cons: Smaller plugin ecosystem than ChatGPT; Image generation not built in. ### Jasper (4.2/5) - https://aestech.com.au/tools/jasper/ Vendor: Jasper AI. Pricing: $39mo. Free tier: no. Best for: Marketing teams producing on-brand content at volume. Verdict: undefined Pros: Brand voice & templates; Team & workflow features; SEO integrations. Cons: Pricey for solo users; No meaningful free tier. ### Copy.ai (4.0/5) - https://aestech.com.au/tools/copy-ai/ Vendor: Copy.ai. Pricing: Free / $49mo. Free tier: yes. Best for: Short-form marketing copy and sales workflows. Verdict: undefined Pros: Generous free tier; Lots of templates; GTM workflow automations. Cons: Long-form weaker than rivals; UI can feel busy. ### Sudowrite (4.3/5) - https://aestech.com.au/tools/sudowrite/ Vendor: Sudowrite. Pricing: $19mo. Free tier: no. Best for: Novelists and fiction writers. Verdict: undefined Pros: Purpose-built for fiction; Story bible & character tools; Rewrite/describe helpers. Cons: Niche (fiction only); No free tier. ### Grammarly (4.4/5) - https://aestech.com.au/tools/grammarly/ Vendor: Grammarly. Pricing: Free / $12mo. Free tier: yes. Best for: Real-time grammar, tone, and clarity everywhere. Verdict: undefined Pros: Works across apps & browser; Tone and clarity rewrites; Strong free tier. Cons: Generative features gated to paid; Suggestions can be conservative. ### Rytr (3.9/5) - https://aestech.com.au/tools/rytr/ Vendor: Rytr. Pricing: Free / $9mo. Free tier: yes. Best for: Hobbyists and cheap short-form copy. Verdict: undefined Pros: Very cheap; Simple to use; Decent templates. Cons: Output quality trails premium tools; Weak long-form. ### Wordtune (4.1/5) - https://aestech.com.au/tools/wordtune/ Vendor: AI21 Labs. Pricing: Free / $7mo. Free tier: yes. Best for: Non-native and business writers polishing their own drafts. Verdict: undefined Pros: Excellent sentence-level rewrites; Keeps your voice, not generic AI tone; Browser and doc integrations. Cons: Less suited to long-form generation; Best features are paid. ### QuillBot (4.2/5) - https://aestech.com.au/tools/quillbot/ Vendor: QuillBot. Pricing: Free / $10mo. Free tier: yes. Best for: Students and writers paraphrasing and tightening text. Verdict: undefined Pros: Strong paraphraser with multiple modes; Grammar and summarise tools bundled; Generous free tier. Cons: Free tier word limits; Not a full content generator. ### Anyword (4.1/5) - https://aestech.com.au/tools/anyword/ Vendor: Anyword. Pricing: $39mo. Free tier: no. Best for: Performance marketers optimising copy for conversion. Verdict: undefined Pros: Predictive performance scoring; On-brand, data-led copy; Good for ads and landing pages. Cons: Pricey for casual users; No real free tier. ### Writer (4.3/5) - https://aestech.com.au/tools/writer/ Vendor: Writer. Pricing: Custom. Free tier: no. Best for: Enterprises deploying AI writing with governance and brand rules. Verdict: undefined Pros: Strong brand voice & style enforcement; Enterprise security and governance; Custom models and workflows. Cons: Enterprise-only fit and pricing; Too heavy for individuals. ### Writesonic (4.1/5) - https://aestech.com.au/tools/writesonic/ Vendor: Writesonic. Pricing: Free / $39mo. Free tier: yes. Best for: Marketers producing SEO content and bulk articles. Verdict: undefined Pros: SEO-oriented article workflows; Research and fact-checking features; Decent free trial. Cons: Quality varies on long-form; Credit/word limits. ### Hypotenuse AI (4.0/5) - https://aestech.com.au/tools/hypotenuse/ Vendor: Hypotenuse. Pricing: $29mo. Free tier: no. Best for: Ecommerce teams generating product descriptions at scale. Verdict: undefined Pros: Bulk product-description generation; Ecommerce-specific workflows; Brand voice controls. Cons: Niche focus; No meaningful free tier. ## AI Coding ### GitHub Copilot (4.5/5) - https://aestech.com.au/tools/github-copilot/ Vendor: GitHub. Pricing: $10mo. Free tier: yes. Best for: Developers who want autocomplete-style help in any editor. Verdict: undefined Pros: Deep editor integration; Great inline completions; Affordable individual plan. Cons: Less agentic than newer rivals; Suggestions need review. ### Cursor (4.7/5) - https://aestech.com.au/tools/cursor/ Vendor: Anysphere. Pricing: Free / $20mo. Free tier: yes. Best for: Developers who want agentic, multi-file AI editing. Verdict: undefined Pros: Multi-file, repo-aware edits; Fast, agentic workflows; Strong free tier. Cons: It’s a full editor switch; Heavy use needs the paid plan. ### Windsurf (4.4/5) - https://aestech.com.au/tools/windsurf/ Vendor: Codeium. Pricing: Free / $15mo. Free tier: yes. Best for: Developers wanting agentic editing without the cost. Verdict: undefined Pros: Strong free tier; Agentic "flows"; Fast completions. Cons: Younger ecosystem; Occasional rough edges. ### Tabnine (4.1/5) - https://aestech.com.au/tools/tabnine/ Vendor: Tabnine. Pricing: Free / $9mo. Free tier: yes. Best for: Teams with strict privacy/compliance needs. Verdict: undefined Pros: Privacy & self-hosting options; Trained-on-permissive-code option; Editor-agnostic. Cons: Completions less sharp than top rivals; Enterprise pricing opaque. ### Replit (4.2/5) - https://aestech.com.au/tools/replit/ Vendor: Replit. Pricing: Free / $20mo. Free tier: yes. Best for: Beginners and rapid prototyping in the browser. Verdict: undefined Pros: Zero local setup; AI agent builds full apps; Instant hosting. Cons: Not for large production codebases; Resource limits on lower tiers. ### Amazon Q Developer (4.0/5) - https://aestech.com.au/tools/amazon-q-developer/ Vendor: AWS. Pricing: Free / $19mo. Free tier: yes. Best for: Developers building on AWS. Verdict: undefined Pros: Deep AWS knowledge; Security scanning; Free tier. Cons: Best value only on AWS; Less general than rivals. ### Aider (4.4/5) - https://aestech.com.au/tools/aider/ Vendor: Aider. Pricing: Free (your API key). Free tier: yes. Best for: Terminal-first devs who want control. Verdict: undefined Pros: Free & open source; Git-aware edits; Model-agnostic. Cons: Terminal/CLI only; You pay for model API usage. ### Sourcegraph Cody (4.3/5) - https://aestech.com.au/tools/sourcegraph-cody/ Vendor: Sourcegraph. Pricing: Free / $9mo. Free tier: yes. Best for: Teams working in large, sprawling codebases. Verdict: undefined Pros: Strong repo-wide code search context; Works across many editors; Good for understanding unfamiliar code. Cons: Best value tied to Sourcegraph search; Less agentic than Cursor. ### Qodo (4.2/5) - https://aestech.com.au/tools/qodo/ Vendor: Qodo. Pricing: Free / $19mo. Free tier: yes. Best for: Developers who want AI focused on test coverage and correctness. Verdict: undefined Pros: Test generation and code review focus; Catches edge cases, not just writes code; IDE and PR integrations. Cons: Narrower than a general assistant; Newer brand (formerly Codium). ### JetBrains AI Assistant (4.1/5) - https://aestech.com.au/tools/jetbrains-ai/ Vendor: JetBrains. Pricing: Free / $10mo. Free tier: yes. Best for: Developers already living in JetBrains IDEs. Verdict: undefined Pros: Deeply integrated with JetBrains tooling; Context-aware refactors and completions; Bundled with the IDE workflow. Cons: Only useful inside JetBrains IDEs; Trails Cursor on agentic editing. ### Continue (4.0/5) - https://aestech.com.au/tools/continue/ Vendor: Continue. Pricing: Free / paid teams. Free tier: yes. Best for: Developers who want an open, model-agnostic assistant. Verdict: undefined Pros: Open source and highly customisable; Bring your own model or API key; No vendor lock-in. Cons: More setup than turnkey tools; Polish depends on your config. ### Augment Code (4.2/5) - https://aestech.com.au/tools/augment-code/ Vendor: Augment. Pricing: Free / $30mo. Free tier: yes. Best for: Engineering teams in big, complex repositories. Verdict: undefined Pros: Strong large-codebase context; Agentic, repo-aware changes; Team-oriented features. Cons: Newer entrant; Best value at team scale. ### Bolt (4.3/5) - https://aestech.com.au/tools/bolt/ Vendor: StackBlitz. Pricing: Free / $20mo. Free tier: yes. Best for: Founders and devs prototyping full web apps from a prompt. Verdict: undefined Pros: Generates working full-stack apps fast; Runs entirely in-browser; Easy to iterate and deploy. Cons: Token usage adds up quickly; Complex apps still need real engineering. ### v0 (4.3/5) - https://aestech.com.au/tools/v0/ Vendor: Vercel. Pricing: Free / $20mo. Free tier: yes. Best for: Developers building React/Next UIs and shipping on Vercel. Verdict: undefined Pros: Great React/Next.js output; Tight Vercel deploy path; Good component-level generation. Cons: Best within the React/Vercel stack; Credit-based limits. ### Lovable (4.2/5) - https://aestech.com.au/tools/lovable/ Vendor: Lovable. Pricing: Free / $25mo. Free tier: yes. Best for: Non-developers and founders shipping real apps fast. Verdict: undefined Pros: Very approachable for non-coders; Full-stack apps with auth/db; Fast idea-to-deploy. Cons: Less control than hand-coding; Credit limits on heavy use. ### Devin (4.0/5) - https://aestech.com.au/tools/devin/ Vendor: Cognition. Pricing: From $20mo. Free tier: no. Best for: Teams delegating self-contained tasks to an autonomous agent. Verdict: undefined Pros: Works tasks end-to-end autonomously; Runs in its own environment; Good for parallel, bounded work. Cons: Needs careful task scoping & review; Costlier than assistants. ### Zed (4.2/5) - https://aestech.com.au/tools/zed/ Vendor: Zed Industries. Pricing: Free / paid AI. Free tier: yes. Best for: Developers who want speed and a lightweight AI editor. Verdict: undefined Pros: Extremely fast, native performance; Built-in AI and pair collaboration; Open source core. Cons: Younger ecosystem than VS Code; AI features still maturing. ### Framer (4.5/5) - https://aestech.com.au/tools/framer/ Vendor: Framer. Pricing: Free / $10mo. Free tier: yes. Best for: Designers and startups shipping polished marketing sites fast. Verdict: undefined Pros: Output looks genuinely designed, not template-shaped; AI generation plus a real freeform canvas for refinement; Animations, CMS, and hosting built in. Cons: Not suited to web apps or complex logic; Costs climb once you add CMS scale and team seats. ### Durable (4.0/5) - https://aestech.com.au/tools/durable/ Vendor: Durable. Pricing: $12mo. Free tier: no. Best for: Tradies, local services, and solo businesses that just need to exist online. Verdict: undefined Pros: Generates a complete site from three questions in under a minute; Bundles CRM, invoicing, and basic marketing tools; Zero learning curve, truly non-technical. Cons: Sites look generic next to Framer or custom builds; Limited design control once you want something specific. ## AI Image ### Midjourney (4.6/5) - https://aestech.com.au/tools/midjourney/ Vendor: Midjourney. Pricing: $10mo. Free tier: no. Best for: Designers wanting the best visual quality. Verdict: undefined Pros: Best-in-class aesthetics; Strong style control; Active community. Cons: No free tier; Workflow takes adjusting. ### Adobe Firefly (4.3/5) - https://aestech.com.au/tools/adobe-firefly/ Vendor: Adobe. Pricing: Free / $5mo. Free tier: yes. Best for: Designers needing commercial-safe assets. Verdict: undefined Pros: Trained on licensed content; Photoshop integration; Commercial-use confidence. Cons: Less edgy than Midjourney; Best value inside CC. ### Leonardo AI (4.2/5) - https://aestech.com.au/tools/leonardo-ai/ Vendor: Leonardo.Ai. Pricing: Free / $12mo. Free tier: yes. Best for: Game artists and control-focused creators. Verdict: undefined Pros: Fine-grained controls; Custom model training; Good free credits. Cons: Steeper learning curve; Credit system to manage. ### Ideogram (4.3/5) - https://aestech.com.au/tools/ideogram/ Vendor: Ideogram. Pricing: Free / $8mo. Free tier: yes. Best for: Logos, posters, and images with legible text. Verdict: undefined Pros: Best-in-class text rendering; Good free tier; Strong for typography/logos. Cons: Photoreal slightly behind leaders; Newer, smaller community. ### Recraft (4.3/5) - https://aestech.com.au/tools/recraft/ Vendor: Recraft. Pricing: Free / $12mo. Free tier: yes. Best for: Designers needing vectors and brand consistency. Verdict: undefined Pros: Vector + raster output; Brand style controls; Strong for icons/illustrations. Cons: Less photoreal than Midjourney; Learning curve. ### Krea (4.2/5) - https://aestech.com.au/tools/krea/ Vendor: Krea AI. Pricing: Free / $10mo. Free tier: yes. Best for: Real-time ideation and upscaling. Verdict: undefined Pros: Real-time canvas; Great upscaler/enhancer; Fast workflow. Cons: Credits on free tier; Less known. ### Stability AI (DreamStudio) (4.0/5) - https://aestech.com.au/tools/stability-ai/ Vendor: Stability AI. Pricing: Credits / API. Free tier: no. Best for: Developers and tinkerers who want open-model image generation. Verdict: undefined Pros: Open Stable Diffusion lineage; Flexible API and credit model; Strong for custom pipelines. Cons: Less turnkey than Midjourney; Quality needs prompt/work. ### Flux (Black Forest Labs) (4.3/5) - https://aestech.com.au/tools/flux/ Vendor: Black Forest Labs. Pricing: API / credits. Free tier: no. Best for: Developers and power users who want top-tier open image models. Verdict: undefined Pros: Excellent prompt adherence and quality; Open weights and API options; Great for custom pipelines. Cons: Less turnkey than consumer apps; Best via API/third-party UIs. ### Freepik AI (4.1/5) - https://aestech.com.au/tools/freepik-ai/ Vendor: Freepik. Pricing: Free / $7mo. Free tier: yes. Best for: Designers who want AI generation plus stock assets in one place. Verdict: undefined Pros: Many models under one subscription; Bundled stock + AI generation; Affordable entry price. Cons: Jack-of-all-trades vs specialists; Credit limits on AI. ## AI Video ### Runway (4.4/5) - https://aestech.com.au/tools/runway/ Vendor: Runway. Pricing: Free / $15mo. Free tier: yes. Best for: Filmmakers and motion creators. Verdict: undefined Pros: High-quality generative video; Deep editing toolset; Frequent model updates. Cons: Credits burn fast; Learning curve. ### Synthesia (4.3/5) - https://aestech.com.au/tools/synthesia/ Vendor: Synthesia. Pricing: $18mo. Free tier: no. Best for: Corporate training, explainers, and L&D. Verdict: undefined Pros: Realistic avatars & 140+ languages; No camera or studio needed; Easy templates. Cons: Not for cinematic/creative video; No real free tier. ### HeyGen (4.3/5) - https://aestech.com.au/tools/heygen/ Vendor: HeyGen. Pricing: Free / $24mo. Free tier: yes. Best for: Marketing video and video translation. Verdict: undefined Pros: Excellent video translation/dubbing; Custom avatars; Fast turnaround. Cons: Costs scale with minutes; Avatars still slightly uncanny. ### Descript (4.5/5) - https://aestech.com.au/tools/descript/ Vendor: Descript. Pricing: Free / $24mo. Free tier: yes. Best for: Podcasters and creators editing by text. Verdict: undefined Pros: Edit media like a doc; Filler-word removal & overdub; All-in-one workflow. Cons: Heavy projects can lag; Some features paywalled. ### Pika (4.2/5) - https://aestech.com.au/tools/pika/ Vendor: Pika. Pricing: Free / $10mo. Free tier: yes. Best for: Short, creative social video. Verdict: undefined Pros: Fast and approachable; Fun effects/transforms; Free tier. Cons: Shorter clips; Less control than Runway. ### Kling AI (4.3/5) - https://aestech.com.au/tools/kling/ Vendor: Kuaishou. Pricing: Free / $10mo. Free tier: yes. Best for: Realistic motion and longer clips. Verdict: undefined Pros: Impressive motion realism; Longer clip lengths; Competitive quality. Cons: Queue times; Interface rough in English. ### Luma Dream Machine (4.1/5) - https://aestech.com.au/tools/luma-dream-machine/ Vendor: Luma AI. Pricing: Free / $10mo. Free tier: yes. Best for: Cinematic shots from stills. Verdict: undefined Pros: Great image-to-video; Cinematic camera moves; Easy to start. Cons: Credit limits; Less editing control. ### VEED (4.2/5) - https://aestech.com.au/tools/veed/ Vendor: VEED.IO. Pricing: Free / $18mo. Free tier: yes. Best for: Creators and teams making social and marketing video fast. Verdict: undefined Pros: Easy in-browser editor; AI subtitles, eye-contact, and avatars; Good templates for social formats. Cons: Exports and features gated by plan; Not a pro NLE replacement. ### Captions (4.2/5) - https://aestech.com.au/tools/captions/ Vendor: Captions. Pricing: Free / $10mo. Free tier: yes. Best for: Creators making short-form talking-head and social video. Verdict: undefined Pros: Strong AI captions and editing; Eye-contact and dubbing tools; Mobile-first workflow. Cons: Best for talking-head formats; Higher tiers for full features. ### Pictory (4.0/5) - https://aestech.com.au/tools/pictory/ Vendor: Pictory. Pricing: $23mo. Free tier: no. Best for: Marketers repurposing text and long video into short clips. Verdict: undefined Pros: Text-to-video and blog-to-video; Auto-summarises long video; Easy templated output. Cons: Templated look; No real free tier. ## AI Voice & Audio ### ElevenLabs (4.7/5) - https://aestech.com.au/tools/elevenlabs/ Vendor: ElevenLabs. Pricing: Free / $5mo. Free tier: yes. Best for: Voiceover, audiobooks, and voice cloning. Verdict: undefined Pros: Best-in-class realism; Voice cloning & dubbing; 30+ languages. Cons: Character limits on lower tiers; Cloning needs ethical care. ### Murf (4.1/5) - https://aestech.com.au/tools/murf/ Vendor: Murf AI. Pricing: Free / $19mo. Free tier: yes. Best for: Corporate voiceover and e-learning. Verdict: undefined Pros: Easy studio interface; Lots of business voices; Sync with slides/video. Cons: Less expressive than ElevenLabs; Voice library varies in quality. ### Suno (4.4/5) - https://aestech.com.au/tools/suno/ Vendor: Suno. Pricing: Free / $8mo. Free tier: yes. Best for: Music creation and jingles. Verdict: undefined Pros: Full songs with vocals; Surprisingly catchy output; Fast. Cons: Limited fine editing; Commercial rights tier-gated. ### Play.ht (4.1/5) - https://aestech.com.au/tools/play-ht/ Vendor: PlayAI. Pricing: Free / $19mo. Free tier: yes. Best for: Developers adding voice via API. Verdict: undefined Pros: Solid realism; Strong API; Voice agents. Cons: ElevenLabs edges it on quality; Pricing complexity. ### Udio (4.3/5) - https://aestech.com.au/tools/udio/ Vendor: Udio. Pricing: Free / $10mo. Free tier: yes. Best for: AI music with strong audio quality. Verdict: undefined Pros: Excellent audio fidelity; Good vocal quality; Fast. Cons: Editing limited; Rights tier-gated. ### WellSaid Labs (4.2/5) - https://aestech.com.au/tools/wellsaid/ Vendor: WellSaid Labs. Pricing: $49mo. Free tier: no. Best for: Corporate e-learning and training voiceover at scale. Verdict: undefined Pros: Consistent, professional voices; Clear commercial licensing; Good for e-learning workflows. Cons: Pricier entry than rivals; No free tier. ## AI Productivity ### Notion AI (4.3/5) - https://aestech.com.au/tools/notion-ai/ Vendor: Notion. Pricing: $10mo add-on. Free tier: no. Best for: Teams already living in Notion. Verdict: undefined Pros: In-context with your docs; Q&A over your workspace; Low friction. Cons: Only useful if you use Notion; Add-on cost on top of Notion. ### Otter.ai (4.2/5) - https://aestech.com.au/tools/otter-ai/ Vendor: Otter.ai. Pricing: Free / $17mo. Free tier: yes. Best for: Meeting notes, summaries, and action items. Verdict: undefined Pros: Joins & transcribes meetings; Auto summaries & action items; Good free tier. Cons: Accuracy varies with audio; Integrations gated to paid. ### Motion (4.1/5) - https://aestech.com.au/tools/motion/ Vendor: Motion. Pricing: $19mo. Free tier: no. Best for: Heavy calendar/task jugglers. Verdict: undefined Pros: Auto-schedules tasks into your calendar; Reprioritises automatically; Project + calendar in one. Cons: Pricey; Takes time to trust the automation. ### Fathom (4.5/5) - https://aestech.com.au/tools/fathom/ Vendor: Fathom. Pricing: Free / $19mo. Free tier: yes. Best for: Free, accurate meeting summaries. Verdict: undefined Pros: Genuinely useful free tier; Clean summaries & action items; CRM sync. Cons: Meeting-only scope; Advanced features paid. ### Mem (3.9/5) - https://aestech.com.au/tools/mem/ Vendor: Mem Labs. Pricing: Free / $10mo. Free tier: yes. Best for: Note-takers who hate filing. Verdict: undefined Pros: Auto-organises notes; Fast capture; AI search over notes. Cons: Opinionated workflow; Smaller ecosystem. ### Gamma (4.4/5) - https://aestech.com.au/tools/gamma/ Vendor: Gamma. Pricing: Free / $10mo. Free tier: yes. Best for: Anyone who needs good-looking presentations fast. Verdict: undefined Pros: Great-looking output with little effort; Decks, docs, and web pages from one tool; Easy editing after generation. Cons: Less control than manual design tools; Templated look at scale. ### Fireflies.ai (4.3/5) - https://aestech.com.au/tools/fireflies/ Vendor: Fireflies. Pricing: Free / $10mo. Free tier: yes. Best for: Teams that want searchable meeting notes and action items. Verdict: undefined Pros: Joins and transcribes across major platforms; Searchable transcripts and summaries; CRM and workflow integrations. Cons: Accuracy varies with audio quality; Admin/privacy setup needs care. ### Krisp (4.4/5) - https://aestech.com.au/tools/krisp/ Vendor: Krisp. Pricing: Free / $8mo. Free tier: yes. Best for: Remote workers in noisy environments and on bad connections. Verdict: undefined Pros: Best-in-class background noise removal; Works across any conferencing app; Added meeting notes and transcription. Cons: Core value is the audio cleanup; Notes features trail dedicated tools. ### ClickUp AI (Brain) (4.2/5) - https://aestech.com.au/tools/clickup-ai/ Vendor: ClickUp. Pricing: Free / $7mo + AI. Free tier: yes. Best for: Teams that want AI inside their project and docs tool. Verdict: undefined Pros: AI across tasks, docs, and search; Replaces several point tools; Affordable base plans. Cons: Can feel feature-heavy; AI is a paid add-on. ### Reclaim.ai (4.3/5) - https://aestech.com.au/tools/reclaim/ Vendor: Reclaim. Pricing: Free / $8mo. Free tier: yes. Best for: Busy professionals who want their calendar to defend their time. Verdict: undefined Pros: Smart auto-scheduling around meetings; Protects focus time and habits; Good Google Calendar integration. Cons: Best value tied to Google Calendar; Takes trust to hand over scheduling. ### Sunsama (4.3/5) - https://aestech.com.au/tools/sunsama/ Vendor: Sunsama. Pricing: $16mo. Free tier: no. Best for: Professionals who want intentional daily planning. Verdict: undefined Pros: Thoughtful daily planning ritual; Pulls tasks from many tools; Time-boxing and reflection built in. Cons: Premium price, no free tier; Manual by design (less automation). ### NotebookLM (4.6/5) - https://aestech.com.au/tools/notebooklm/ Vendor: Google. Pricing: Free / $20mo. Free tier: yes. Best for: Researchers and knowledge workers synthesising piles of documents. Verdict: undefined Pros: Answers cite your uploaded sources, so hallucination risk drops sharply; Audio Overviews turn documents into a surprisingly good podcast; Generous free tier covers most individual use. Cons: Confined to sources you upload, it is not a general assistant; Sharing and collaboration remain clumsy for team use. ### Granola (4.5/5) - https://aestech.com.au/tools/granola/ Vendor: Granola. Pricing: $18mo. Free tier: no. Best for: People in back-to-back meetings who hate visible recording bots. Verdict: undefined Pros: No bot joins the call, it transcribes from system audio; Blends your rough typed notes with the full transcript; Clean, fast, genuinely pleasant to use. Cons: No unlimited free tier, only a trial; Mobile and Windows support arrived later and still trail the Mac app. ### Glean (4.3/5) - https://aestech.com.au/tools/glean/ Vendor: Glean. Pricing: Custom. Free tier: no. Best for: Companies of 200 plus seats drowning in scattered internal knowledge. Verdict: undefined Pros: Searches across 100 plus workplace apps with permissions respected; Assistant answers grounded in your company’s own knowledge; Agent builder extends it beyond search into workflows. Cons: Enterprise-only pricing puts it out of reach for small teams; Value depends heavily on connector rollout and adoption. ## AI Chatbots ### Perplexity (4.5/5) - https://aestech.com.au/tools/perplexity/ Vendor: Perplexity AI. Pricing: Free / $20mo. Free tier: yes. Best for: Research and fact-finding with citations. Verdict: undefined Pros: Cited, sourced answers; Fast research workflow; Good free tier. Cons: Not built for long-form creation; Pro features gated. ### Gemini (4.4/5) - https://aestech.com.au/tools/gemini/ Vendor: Google. Pricing: Free / $20mo. Free tier: yes. Best for: Google Workspace users and huge-context tasks. Verdict: undefined Pros: Massive context window; Workspace (Gmail/Docs) integration; Strong multimodal. Cons: Quality varies by task; Best value inside Google’s ecosystem. ### Microsoft Copilot (4.1/5) - https://aestech.com.au/tools/microsoft-copilot/ Vendor: Microsoft. Pricing: Free / $20mo. Free tier: yes. Best for: Microsoft 365 and Windows users. Verdict: undefined Pros: Built into Office & Windows; Enterprise data controls; Free tier available. Cons: Inconsistent across apps; Best value requires M365. ### Grok (4.0/5) - https://aestech.com.au/tools/grok/ Vendor: xAI. Pricing: Free / $30mo. Free tier: yes. Best for: Real-time info and X integration. Verdict: undefined Pros: Real-time data via X; Capable reasoning; Less filtered tone. Cons: Best value tied to X; Quality varies. ### DeepSeek (4.2/5) - https://aestech.com.au/tools/deepseek/ Vendor: DeepSeek. Pricing: Free / low-cost API. Free tier: yes. Best for: Cost-conscious power users and developers. Verdict: undefined Pros: Strong reasoning for the price; Open-weight options; Very cheap API. Cons: Data/privacy considerations; Fewer consumer features. ### Poe (4.1/5) - https://aestech.com.au/tools/poe/ Vendor: Quora. Pricing: Free / $20mo. Free tier: yes. Best for: People who want to compare and switch between models in one place. Verdict: undefined Pros: Access many models in one app; Easy model switching and bots; Single subscription. Cons: Not the cheapest for heavy single-model use; Limits vary by model. ### You.com (4.0/5) - https://aestech.com.au/tools/you-com/ Vendor: You.com. Pricing: Free / $15mo. Free tier: yes. Best for: People who want cited AI search across several models. Verdict: undefined Pros: Cited, source-linked answers; Access to multiple models; Research-oriented modes. Cons: Less polished than Perplexity for some; Best features are paid. ### Mistral (Le Chat) (4.1/5) - https://aestech.com.au/tools/mistral/ Vendor: Mistral AI. Pricing: Free / $15mo. Free tier: yes. Best for: Users who want a capable, EU-based assistant and open models. Verdict: undefined Pros: Fast, capable assistant (Le Chat); Open-weight model heritage; EU data-residency appeal. Cons: Smaller ecosystem than ChatGPT; Fewer built-in tools. ## AI Marketing ### Surfer SEO (4.3/5) - https://aestech.com.au/tools/surfer-seo/ Vendor: Surfer. Pricing: $59mo. Free tier: no. Best for: Content teams optimising for search. Verdict: undefined Pros: Data-driven content briefs; On-page optimisation scoring; AI draft + optimise loop. Cons: Pricey for hobbyists; Can encourage over-optimisation. ### Opus Clip (4.2/5) - https://aestech.com.au/tools/opus-clip/ Vendor: Opus. Pricing: Free / $9mo. Free tier: yes. Best for: Repurposing long video into shorts/reels. Verdict: undefined Pros: Auto-finds the best moments; Captions & reframing; Big time-saver. Cons: Clip picks need review; Watermark on free tier. ### AdCreative.ai (4.0/5) - https://aestech.com.au/tools/adcreative/ Vendor: AdCreative. Pricing: $39mo. Free tier: no. Best for: Performance marketers needing ad creative at volume. Verdict: undefined Pros: Fast ad/banner generation; Conversion-focused; Brand kits. Cons: Pricey; Outputs need polish. ### Buffer AI Assistant (4.1/5) - https://aestech.com.au/tools/buffer-ai/ Vendor: Buffer. Pricing: Free / $6mo. Free tier: yes. Best for: Small teams managing social channels. Verdict: undefined Pros: Cheap & simple; AI post ideas/repurposing; Clean scheduler. Cons: Light analytics; AI is assistive, not magic. ### Frase (4.1/5) - https://aestech.com.au/tools/frase/ Vendor: Frase. Pricing: $15mo. Free tier: no. Best for: SEO writers building optimised briefs and first drafts. Verdict: undefined Pros: Fast SERP research and briefs; Affordable entry price; Content scoring built in. Cons: AI writing weaker than dedicated generators; Add-on pricing for AI words. ### Clearscope (4.4/5) - https://aestech.com.au/tools/clearscope/ Vendor: Clearscope. Pricing: $170mo. Free tier: no. Best for: Content teams that treat SEO as a core channel. Verdict: undefined Pros: Best-in-class content grading; Clean, trusted recommendations; Reliable term coverage data. Cons: Expensive for small sites; Optimisation only, not generation. ### Semrush (4.4/5) - https://aestech.com.au/tools/semrush/ Vendor: Semrush. Pricing: $139mo. Free tier: no. Best for: Marketing teams that want one platform for SEO, ads, and content. Verdict: undefined Pros: Huge feature breadth; Deep keyword and competitor data; AI writing and content tools added. Cons: Expensive; Steep learning curve. ## Security & Compliance ### Vanta (4.6/5) - https://aestech.com.au/tools/vanta/ Vendor: Vanta. Pricing: Custom quote. Free tier: no. Best for: Startups and scale-ups automating ISO 27001, SOC 2, and PCI DSS. Verdict: undefined Pros: Broad framework coverage (ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR); Large integration library for automated evidence collection; Trust Center to share security posture with customers. Cons: Quote-based pricing, not cheap for small teams; You still engage a separate accredited auditor. ### Drata (4.6/5) - https://aestech.com.au/tools/drata/ Vendor: Drata. Pricing: Custom quote. Free tier: no. Best for: Teams wanting continuous control monitoring across many frameworks. Verdict: undefined Pros: Strong continuous monitoring and auto-evidence; 20+ frameworks including ISO 27001 and PCI DSS; Well-regarded auditor network and support. Cons: Premium pricing; Initial setup still takes real effort. ### Secureframe (4.5/5) - https://aestech.com.au/tools/secureframe/ Vendor: Secureframe. Pricing: Custom quote. Free tier: no. Best for: First-time compliance teams who want more guidance. Verdict: undefined Pros: Guided onboarding and dedicated support; ISO 27001, SOC 2, PCI DSS, HIPAA coverage; Clear remediation guidance. Cons: Quote-based pricing; Smaller integration set than the two leaders. ### Sprinto (4.4/5) - https://aestech.com.au/tools/sprinto/ Vendor: Sprinto. Pricing: Custom quote. Free tier: no. Best for: Cloud-native SMBs wanting quick time-to-audit. Verdict: undefined Pros: Fast implementation; Good value versus the market leaders; Solid ISO 27001 and SOC 2 support. Cons: Fewer enterprise features; Newer brand than Vanta/Drata. ### Thoropass (4.3/5) - https://aestech.com.au/tools/thoropass/ Vendor: Thoropass. Pricing: Custom quote. Free tier: no. Best for: Teams that want the software and the audit from one vendor. Verdict: undefined Pros: Combines platform with in-house audit; Predictable, bundled pricing; Good for ISO 27001 and SOC 2. Cons: Less of a pure-play platform; Smaller integration library. ### Hyperproof (4.3/5) - https://aestech.com.au/tools/hyperproof/ Vendor: Hyperproof. Pricing: Custom. Free tier: no. Best for: Mid-market and enterprise teams managing multiple frameworks in parallel. Verdict: undefined Pros: Strong multi-framework control mapping; Good evidence reuse across frameworks; Workflow and task management built in. Cons: Quote-based pricing, no public tier; Heavier than a first-SOC-2 tool needs. ### Scrut Automation (4.4/5) - https://aestech.com.au/tools/scrut/ Vendor: Scrut. Pricing: Custom. Free tier: no. Best for: Startups wanting broad framework coverage without enterprise pricing. Verdict: undefined Pros: Wide framework library out of the box; Aggressive pricing vs incumbents; Responsive onboarding and support. Cons: Smaller brand than Vanta/Drata; Quote-based pricing. ### Anecdotes (4.2/5) - https://aestech.com.au/tools/anecdotes/ Vendor: Anecdotes. Pricing: Custom. Free tier: no. Best for: Enterprise security and GRC teams that need data-grade evidence. Verdict: undefined Pros: Treats compliance evidence as structured data; Strong for large, complex estates; Good cross-framework analytics. Cons: Enterprise-only fit and pricing; Overkill for early-stage teams. ### TrustCloud (4.2/5) - https://aestech.com.au/tools/trustcloud/ Vendor: TrustCloud. Pricing: Free / Custom. Free tier: yes. Best for: Early-stage teams that want to start compliance before they have budget. Verdict: undefined Pros: Real free tier to begin SOC 2 / ISO groundwork; Risk and trust-centre tooling included; Lower entry cost than incumbents. Cons: Smaller integration library than Vanta/Drata; Paid scaling still quote-based. ### Strike Graph (4.2/5) - https://aestech.com.au/tools/strike-graph/ Vendor: Strike Graph. Pricing: Custom. Free tier: no. Best for: Teams that want a lean control set rather than a maximalist checklist. Verdict: undefined Pros: Focus on relevant controls, less busywork; Good auditor collaboration; Multi-framework support. Cons: Quote-based pricing; Less brand recognition than leaders. ### AuditBoard (4.3/5) - https://aestech.com.au/tools/auditboard/ Vendor: AuditBoard. Pricing: Custom. Free tier: no. Best for: Large enterprises unifying internal audit, risk, and compliance. Verdict: undefined Pros: Deep enterprise audit and risk modules; Strong reporting for boards and regulators; Connected risk across the org. Cons: Enterprise-only fit and pricing; Heavy for a first SOC 2. ### Apptega (4.2/5) - https://aestech.com.au/tools/apptega/ Vendor: Apptega. Pricing: Custom. Free tier: no. Best for: MSPs and teams mapping controls across many frameworks at once. Verdict: undefined Pros: Excellent framework crosswalk mapping; Popular with MSPs/MSSPs; Clean reporting. Cons: Quote-based pricing; Less automation than Vanta/Drata. ### Onspring (4.2/5) - https://aestech.com.au/tools/onspring/ Vendor: Onspring. Pricing: Custom. Free tier: no. Best for: Risk and GRC teams that want to build their own workflows. Verdict: undefined Pros: Highly configurable, no-code; Strong risk and audit workflows; Good reporting and dashboards. Cons: Setup effort to tailor it; Enterprise pricing. ### Cypago (4.1/5) - https://aestech.com.au/tools/cypago/ Vendor: Cypago. Pricing: Custom. Free tier: no. Best for: Teams wanting automated evidence without heavy agents. Verdict: undefined Pros: Broad no-code integrations; Good continuous evidence collection; Multi-framework support. Cons: Newer brand; Quote-based pricing. ### SafeBase (4.3/5) - https://aestech.com.au/tools/safebase/ Vendor: SafeBase. Pricing: Custom. Free tier: no. Best for: Sales and security teams speeding up customer security reviews. Verdict: undefined Pros: Polished public/gated trust centre; Cuts security-questionnaire load; NDA and access workflows. Cons: Quote-based pricing; Complements, not replaces, a GRC tool. ### Conveyor (4.2/5) - https://aestech.com.au/tools/conveyor/ Vendor: Conveyor. Pricing: Custom. Free tier: no. Best for: Teams drowning in inbound security questionnaires. Verdict: undefined Pros: AI auto-answers questionnaires; Trust centre included; Big time-saver for sales engineering. Cons: Quote-based pricing; Value scales with questionnaire volume. ## AI Security ### Snyk (4.4/5) - https://aestech.com.au/tools/snyk/ Vendor: Snyk. Pricing: Free / $49mo. Free tier: yes. Best for: Finding and fixing vulnerabilities in open-source dependencies. Verdict: undefined Pros: Deep dependency scanning; AI-powered fix suggestions; Developer-friendly integrations. Cons: Focused on open-source, not proprietary code; Premium pricing at scale. ### GitHub Advanced Security (4.3/5) - https://aestech.com.au/tools/github-advanced-security/ Vendor: GitHub. Pricing: $21/usermo. Free tier: no. Best for: Teams already on GitHub wanting built-in security scanning. Verdict: undefined Pros: Native GitHub integration; CodeQL for deep analysis; Secret scanning built in. Cons: Only works within GitHub; Less useful for non-code assets. ### Checkmarx One (4.2/5) - https://aestech.com.au/tools/checkmarx-one/ Vendor: Checkmarx. Pricing: Custom quote. Free tier: no. Best for: Large teams needing comprehensive application security testing. Verdict: undefined Pros: Multi-language SAST; Strong DevSecOps pipeline integration; AI-powered triage. Cons: Complex setup; Expensive for small teams. ### Lakera (4.3/5) - https://aestech.com.au/tools/lakera/ Vendor: Lakera. Pricing: Custom quote. Free tier: no. Best for: Teams building and deploying LLM-powered applications. Verdict: undefined Pros: Built for AI/LLM security; Prompt injection testing; Jailbreak detection. Cons: Narrower scope than general security tools; Newer vendor. ### Giskard AI (4.1/5) - https://aestech.com.au/tools/giskard-ai/ Vendor: Giskard. Pricing: Free / $49mo. Free tier: yes. Best for: Data science teams wanting to test model robustness and bias. Verdict: undefined Pros: Open-source core; Bias and fairness testing; Automated test generation. Cons: Smaller ecosystem than general security tools; Still maturing. ### IBM watsonx.governance (4.0/5) - https://aestech.com.au/tools/watsonx-governance/ Vendor: IBM. Pricing: Custom quote. Free tier: no. Best for: Large enterprises needing AI model governance and compliance. Verdict: undefined Pros: Enterprise-grade; Model monitoring and drift detection; Regulatory compliance support. Cons: Heavy enterprise pricing and setup; Best for large orgs. ### OneTrust (4.2/5) - https://aestech.com.au/tools/onetrust/ Vendor: OneTrust. Pricing: Custom quote. Free tier: no. Best for: Organisations handling personal data across multiple jurisdictions. Verdict: undefined Pros: Broadest privacy coverage; AI governance features; Regulatory mapping. Cons: Expensive; Complex to implement. ### Privacera (4.1/5) - https://aestech.com.au/tools/privacera/ Vendor: Privacera. Pricing: Custom quote. Free tier: no. Best for: Organisations with large cloud data estates needing automated privacy controls. Verdict: undefined Pros: Automated data classification; Cloud-native; AI-powered policy enforcement. Cons: Focused on cloud data, not app security; Enterprise pricing. ## AI Automation ### Zapier (4.4/5) - https://aestech.com.au/tools/zapier/ Vendor: Zapier. Pricing: Free / $20mo. Free tier: yes. Best for: Teams that want the widest app coverage with zero code. Verdict: undefined Pros: Nearly 8,000 app integrations, more than anyone; Copilot builds Zaps from a plain-English prompt; AI agents and chatbots layered on a proven core. Cons: Task-based pricing gets expensive at volume; Complex multi-step logic is clunkier than Make or n8n. ### Make (4.3/5) - https://aestech.com.au/tools/make/ Vendor: Make (Celonis). Pricing: Free / $9mo. Free tier: yes. Best for: Builders who want complex visual workflows without enterprise pricing. Verdict: undefined Pros: Drag-and-drop canvas makes complex flows legible; Operations pricing is far cheaper than Zapier at volume; Routers, iterators, and error handlers built in. Cons: Steeper learning curve than Zapier; Fewer integrations, and some connectors feel thinner. ### n8n (4.5/5) - https://aestech.com.au/tools/n8n/ Vendor: n8n. Pricing: Free self-hosted / $24mo. Free tier: yes. Best for: Technical teams building AI agent workflows they want to own. Verdict: undefined Pros: Self-hostable, so data never leaves your infrastructure; First-class AI agent nodes and LangChain integration; Execution-based pricing, unlimited steps per workflow. Cons: Non-technical users will struggle without help; Self-hosting means you own uptime and upgrades. ### Lindy (4.1/5) - https://aestech.com.au/tools/lindy/ Vendor: Lindy. Pricing: Free / $50mo. Free tier: yes. Best for: Non-technical operators who want AI employees, not workflows. Verdict: undefined Pros: Agents built in plain English, genuinely no-code; Strong templates for email triage, scheduling, and CRM updates; Agents can trigger and coordinate other agents. Cons: Credit-based pricing is hard to predict at scale; Less control and debuggability than n8n or Make. ### Relevance AI (4.1/5) - https://aestech.com.au/tools/relevance-ai/ Vendor: Relevance AI. Pricing: Free / $19mo. Free tier: yes. Best for: Sales and ops teams building multi-agent AI workforces. Verdict: undefined Pros: Multi-agent teams with a manager agent coordinating work; Bosh, the prebuilt AI sales agent, works out of the box; Australian-founded with regional data storage options. Cons: The interface can overwhelm first-time builders; Credit consumption needs watching on heavier plans. ## AI Customer Support ### Intercom Fin (4.5/5) - https://aestech.com.au/tools/intercom-fin/ Vendor: Intercom. Pricing: $0.99 per resolution. Free tier: no. Best for: Support teams that want the highest resolution rates and will pay for them. Verdict: undefined Pros: Consistently class-leading resolution rates, often 50 to 65 percent; You pay only when Fin actually resolves a conversation; Works over email, chat, SMS, and social, not just the widget. Cons: 99 cents per resolution adds up fast at scale; Best experience assumes you are in the Intercom ecosystem. ### Ada (4.2/5) - https://aestech.com.au/tools/ada/ Vendor: Ada. Pricing: Custom. Free tier: no. Best for: Enterprises automating support across channels, languages, and brands. Verdict: undefined Pros: Strong reasoning engine with measurable automated resolution; Voice, email, chat, and SMS from one platform; Serious enterprise controls, testing, and analytics. Cons: Quote-based pricing with no self-serve entry point; Implementation is a project, not an afternoon. # Ranked buyer guides ## Best AI Writing Tools (2026) - https://aestech.com.au/best/best-ai-writing-tools/ 1. Best Overall: Claude. The most natural long-form writer, with strong reasoning. 2. Best All-Rounder: ChatGPT. The most versatile, with the biggest ecosystem. 3. Best for Teams: Jasper. Brand voice and workflow features for marketing teams. ## Best AI Coding Assistants (2026) - https://aestech.com.au/best/best-ai-coding-assistants/ 1. Best Overall: Cursor. Agentic, repo-aware editing in an AI-first editor. 2. Best Value: Windsurf. Agentic editing with a generous free tier. 3. Best in Your Editor: GitHub Copilot. Reliable inline help in any editor, cheaply. ## Best AI Image Generators (2026) - https://aestech.com.au/best/best-ai-image-generators/ 1. Best Overall: Midjourney. The best pure aesthetics, full stop. 2. Best for Business: Adobe Firefly. Commercial-safe and inside Creative Cloud. 3. Best for Text: Ideogram. The one that renders legible text. ## Best AI Video Generators (2026) - https://aestech.com.au/best/best-ai-video-generators/ 1. Best Overall: Runway. The most complete generative-video toolkit. 2. Best for Training: Synthesia. Avatar videos for L&D in any language. 3. Best for Editing: Descript. Edit video by editing the transcript. ## Best AI Voice Generators (2026) - https://aestech.com.au/best/best-ai-voice-generators/ 1. Best Overall: ElevenLabs. The most realistic voices and cloning. 2. Best for Business: Murf. Smooth corporate voiceover workflow. 3. Best for Music: Suno. Full songs from a prompt. ## Best AI Chatbots & Assistants (2026) - https://aestech.com.au/best/best-ai-chatbots/ 1. Best Overall: Claude. Best for nuanced reasoning and writing. 2. Best for Research: Perplexity. Cited answers, fastest research loop. 3. Best for Google Users: Gemini. Huge context, Workspace integration. ## Best Free AI Tools (2026) - https://aestech.com.au/best/best-free-ai-tools/ 1. Best Free Assistant: Claude. A genuinely useful free tier for writing. 2. Best Free Coder: Windsurf. Agentic coding without paying. 3. Best Free Voice: ElevenLabs. Realistic voices on the free plan. ## Best AI Productivity Tools (2026) - https://aestech.com.au/best/best-ai-productivity-tools/ 1. Best Meeting Notes: Fathom. Accurate summaries on a great free tier. 2. Best in Notion: Notion AI. AI where your docs already live. 3. Best Scheduler: Motion. Auto-builds and defends your calendar. ## Best AI Marketing Tools (2026) - https://aestech.com.au/best/best-ai-marketing-tools/ 1. Best for SEO: Surfer SEO. Content engineered to rank. 2. Best for Copy: Jasper. On-brand content at scale. 3. Best for Social Video: Opus Clip. Long video into viral shorts. ## Best AI Tools for Students (2026) - https://aestech.com.au/best/best-ai-tools-for-students/ 1. Best for Research: Perplexity. Cited answers you can verify. 2. Best for Writing: Claude. Strong, careful long-form help. 3. Best for Editing: Grammarly. Catches errors everywhere you write. ## Best ISO 27001 Compliance Software (2026) - https://aestech.com.au/best/best-iso-27001-compliance-software/ 1. Best Overall: Drata. Continuous monitoring across the most frameworks. 2. Most Popular: Vanta. The market leader, broad integrations. 3. Best for Beginners: Secureframe. Guided, supported first certification. ## Best PCI DSS Compliance Software (2026) - https://aestech.com.au/best/best-pci-dss-compliance-software/ 1. Best Overall: Vanta. Broad PCI DSS coverage and Trust Center. 2. Best for Scale: Drata. Continuous monitoring at enterprise scale. 3. Best Value: Sprinto. Fast, affordable for cloud SMBs. ## Best SOC 2 Compliance Software (2026) - https://aestech.com.au/best/best-soc-2-compliance-software/ 1. Best Overall: Vanta. The most popular SOC 2 platform, broad integrations and a Trust Center buyers recognise. 2. Best for Scale: Drata. Deepest continuous monitoring across the most frameworks. 3. Best Value: Sprinto. Fastest, most affordable route for cloud-native SMBs. ## Best Compliance Automation Software (2026) - https://aestech.com.au/best/best-compliance-automation-software/ 1. Best Overall: Vanta. The most widely adopted platform with the broadest framework set and a Trust Center customers trust. 2. Best for Continuous Monitoring: Drata. Deepest real-time control monitoring and the largest integration catalogue for automated evidence. 3. Best for First-Time Teams: Secureframe. Guided onboarding and clear remediation steps make it the easiest first certification experience. 4. Best Value: Sprinto. Fast implementation and competitive pricing for cloud-native SMBs that need ISO 27001 or SOC 2 without enterprise overhead. ## Best AI Tools for Business (2026) - https://aestech.com.au/best/best-ai-tools-for-business/ 1. Best Assistant: ChatGPT. The most versatile general assistant for the whole team. 2. Best for Meetings: Fathom. Accurate meeting notes and summaries on a strong free tier. 3. Best for Marketing: Jasper. On-brand content at scale for the marketing team. 4. Best for Code: Cursor. Agentic, repo-aware editing for engineering. 5. Best for Compliance: Vanta. Automates the evidence for SOC 2, ISO 27001, and PCI DSS. ## Best AI Security Tools for Compliance (2026) - https://aestech.com.au/best/ai-security-tools/ 1. Best Overall: Drata. Compliance automation with continuous AI-powered monitoring. 2. Best for DevSecOps: Snyk. Developer-first vulnerability scanning with AI fix suggestions. 3. Best for LLM Security: Lakera. Purpose-built security testing for AI applications. ## Best AI App Builders (2026) - https://aestech.com.au/best/best-ai-app-builders/ 1. Best Overall: Bolt. Full-stack apps in the browser on any framework. 2. Best for React/Vercel: v0. Polished React and Next.js output with one-click deploy. 3. Best for Non-Coders: Lovable. Build a real app by chatting, database and auth included. ## Best Trust Center Software (2026) - https://aestech.com.au/best/best-trust-center-software/ 1. Best Overall: SafeBase. The most polished trust centre to deflect security reviews. 2. Best for Questionnaires: Conveyor. AI that drafts answers to inbound security questionnaires. 3. Best Built-In: Vanta. A solid trust centre bundled with full compliance automation. ## Best GRC Software (2026) - https://aestech.com.au/best/best-grc-software/ 1. Best Overall: Drata. Deep continuous monitoring across the most frameworks. 2. Best for Multi-Framework Ops: Hyperproof. Strong evidence reuse for teams running many frameworks. 3. Best for Enterprise Audit: AuditBoard. Connected internal audit, risk, and compliance at scale. ## Best SOC 2 Software for Startups (2026) - https://aestech.com.au/best/best-soc-2-software-for-startups/ 1. Best Overall: Vanta. The safe, fast default with the broadest integrations. 2. Best Monitoring: Drata. Excellent continuous monitoring as you scale. 3. Best Value: Sprinto. Lean, cost-efficient automation for cloud-native startups. ## Best AI Meeting Assistants (2026) - https://aestech.com.au/best/best-ai-meeting-assistants/ 1. Best Overall: Fathom. Accurate summaries on a genuinely useful free tier. 2. Best for Teams: Fireflies.ai. Strong CRM and workflow integrations for sales and ops. 3. Best Transcription UX: Otter.ai. The cleanest individual transcription experience. ## Best AI SEO Tools (2026) - https://aestech.com.au/best/best-ai-seo-tools/ 1. Best Overall: Surfer SEO. Content engineered to rank, with deep on-page data. 2. Best for Quality: Clearscope. Premium, trusted content grading for serious teams. 3. Best Value: Frase. Affordable research and briefs for solo and small teams. ## Best AI Automation Tools (2026) - https://aestech.com.au/best/best-ai-automation-tools/ 1. Best Overall: Zapier. The widest app coverage, the fastest setup, and solid AI steps built in. 2. Best for Developers: n8n. Open source, self-hostable, with code nodes and native AI agent workflows. 3. Best Value: Make. Deep visual workflows and generous operations at the lowest price. ## Best AI Customer Support Tools (2026) - https://aestech.com.au/best/best-ai-customer-support-tools/ 1. Best Overall: Intercom Fin. The strongest resolution rates we saw, with simple per-resolution pricing. 2. Best for Enterprise: Ada. Platform-agnostic AI agent with strong reasoning across chat, email, voice, and SMS. 3. Best Lightweight: Lindy. Build a capable support agent in an afternoon without a helpdesk migration. ## Best AI Note-Takers (2026) - https://aestech.com.au/best/best-ai-note-takers/ 1. Best Overall: Fathom. Accurate summaries, shareable clips, and the most generous free tier in the category. 2. Best No-Bot: Granola. On-device capture with no bot joining the call, and notes that enhance what you type. 3. Best for Teams: Fireflies.ai. Team workspaces, conversation search, and broad CRM and helpdesk integrations. ## Best AI Website Builders (2026) - https://aestech.com.au/best/best-ai-website-builders/ 1. Best Overall: Framer. The best-looking output by a distance, with a real design canvas behind the AI. 2. Best for Small Business: Durable. A complete business site with copy, booking, and CRM in about thirty seconds. 3. Best Full-Stack: Lovable. Prompt your way to a full web app with a database, not just a landing page. # Head-to-head comparisons ## ChatGPT vs Claude - https://aestech.com.au/compare/chatgpt-vs-claude/ Verdict: Pick Claude for writing and careful reasoning; pick ChatGPT if you want the broadest toolset and ecosystem. Many people pay for both. Our pick: Claude. (ChatGPT: Free / $20mo; Claude: Free / $20mo) ## Cursor vs GitHub Copilot - https://aestech.com.au/compare/cursor-vs-github-copilot/ Verdict: Choose Cursor for agentic, repo-wide work; choose Copilot to stay in your editor cheaply for completions. Our pick: Cursor. (Cursor: Free / $20mo; GitHub Copilot: $10mo) ## Midjourney vs Adobe Firefly - https://aestech.com.au/compare/midjourney-vs-adobe-firefly/ Verdict: Midjourney for the best-looking art; Firefly for client/brand work where licensing matters and you live in Adobe. Our pick: Midjourney. (Midjourney: $10mo; Adobe Firefly: Free / $5mo) ## ElevenLabs vs Murf - https://aestech.com.au/compare/elevenlabs-vs-murf/ Verdict: ElevenLabs for the most natural voices and cloning; Murf if you want a tidy studio for corporate narration. Our pick: ElevenLabs. (ElevenLabs: Free / $5mo; Murf: Free / $19mo) ## ChatGPT vs Gemini - https://aestech.com.au/compare/chatgpt-vs-gemini/ Verdict: In Google Workspace? Gemini’s integration wins. Otherwise ChatGPT’s ecosystem and tooling edge it. Our pick: ChatGPT. (ChatGPT: Free / $20mo; Gemini: Free / $20mo) ## Windsurf vs Cursor - https://aestech.com.au/compare/windsurf-vs-cursor/ Verdict: Cursor for the most polished experience; Windsurf if you want agentic editing on a tighter budget. Our pick: Cursor. (Windsurf: Free / $15mo; Cursor: Free / $20mo) ## Runway vs Pika - https://aestech.com.au/compare/runway-vs-pika/ Verdict: Runway for serious production; Pika for quick, playful social video. Our pick: Runway. (Runway: Free / $15mo; Pika: Free / $10mo) ## Suno vs Udio - https://aestech.com.au/compare/suno-vs-udio/ Verdict: Try both free, Suno for hooks, Udio for fidelity. It’s genuinely a taste call. Our pick: Suno. (Suno: Free / $8mo; Udio: Free / $10mo) ## Synthesia vs HeyGen - https://aestech.com.au/compare/synthesia-vs-heygen/ Verdict: Synthesia for structured training video; HeyGen for marketing and best-in-class video translation. Our pick: HeyGen. (Synthesia: $18mo; HeyGen: Free / $24mo) ## Jasper vs Copy.ai - https://aestech.com.au/compare/jasper-vs-copy-ai/ Verdict: Jasper for a polished brand-content platform; Copy.ai if you want a free start and GTM workflows. Our pick: Jasper. (Jasper: $39mo; Copy.ai: Free / $49mo) ## Vanta vs Drata - https://aestech.com.au/compare/vanta-vs-drata/ Verdict: Both are excellent. Vanta edges it on ecosystem and brand trust; Drata edges it on continuous monitoring and framework breadth. Get quotes from both. Our pick: Drata. (Vanta: Custom quote; Drata: Custom quote) ## Vanta vs Secureframe - https://aestech.com.au/compare/vanta-vs-secureframe/ Verdict: Choose Vanta if you want the biggest ecosystem and to move quickly; choose Secureframe if you want a guiding hand through your first certification. Our pick: Vanta. (Vanta: Custom quote; Secureframe: Custom quote) ## Drata vs Secureframe - https://aestech.com.au/compare/drata-vs-secureframe/ Verdict: Drata for breadth and continuous monitoring as you scale; Secureframe for guidance on a first certification. Our pick: Drata. (Drata: Custom quote; Secureframe: Custom quote) ## Vanta vs Sprinto - https://aestech.com.au/compare/vanta-vs-sprinto/ Verdict: Vanta when you want the broadest ecosystem and enterprise credibility; Sprinto when you are a cloud-native SMB that wants to certify quickly and cheaply. Get a quote from both. Our pick: Vanta. (Vanta: Custom quote; Sprinto: Custom quote) ## Drata vs Sprinto - https://aestech.com.au/compare/drata-vs-sprinto/ Verdict: Drata if you will run several frameworks and need monitoring depth as you grow; Sprinto if you want the quickest, most affordable path to a first certification on a cloud stack. Our pick: Drata. (Drata: Custom quote; Sprinto: Custom quote) ## Jasper vs ChatGPT - https://aestech.com.au/compare/jasper-vs-chatgpt/ Verdict: ChatGPT for raw versatility and value; Jasper when a marketing team needs consistent brand voice, templates, and collaboration without prompt engineering every time. Our pick: ChatGPT. (Jasper: $39mo; ChatGPT: Free / $20mo) ## Claude vs Gemini - https://aestech.com.au/compare/claude-vs-gemini/ Verdict: Claude for the best writing and careful reasoning; Gemini if you live in Google Workspace or need the biggest context and native multimodal. Our pick: Claude. (Claude: Free / $20mo; Gemini: Free / $20mo) ## Perplexity vs ChatGPT - https://aestech.com.au/compare/perplexity-vs-chatgpt/ Verdict: Perplexity when you need fast, verifiable, cited research; ChatGPT when you need one tool that also writes, codes, and generates images. Our pick: ChatGPT. (Perplexity: Free / $20mo; ChatGPT: Free / $20mo) ## Midjourney vs Leonardo AI - https://aestech.com.au/compare/midjourney-vs-leonardo-ai/ Verdict: Midjourney for the highest aesthetic ceiling; Leonardo AI when you want a free start, repeatable control, and production asset pipelines. Our pick: Midjourney. (Midjourney: $10mo; Leonardo AI: Free / $12mo) ## ElevenLabs vs Play.ht - https://aestech.com.au/compare/elevenlabs-vs-play-ht/ Verdict: ElevenLabs when realism and cloning quality matter most; Play.ht if you want a solid voiceover workflow at a competitive price. Our pick: ElevenLabs. (ElevenLabs: Free / $5mo; Play.ht: Free / $19mo) ## Jasper vs Grammarly - https://aestech.com.au/compare/jasper-vs-grammarly/ Verdict: Grammarly to make all your writing cleaner everywhere you type; Jasper to produce on-brand marketing content at scale. They complement more than they compete. Our pick: Grammarly. (Jasper: $39mo; Grammarly: Free / $12mo) ## Surfer SEO vs Jasper - https://aestech.com.au/compare/surfer-seo-vs-jasper/ Verdict: Choose Surfer SEO when the bottleneck is search performance, content gaps, and AI-answer visibility. Choose Jasper when the bottleneck is producing on-brand marketing assets at scale. Our pick: Surfer SEO. (Surfer SEO: $59mo; Jasper: $39mo) ## ChatGPT vs Grammarly - https://aestech.com.au/compare/chatgpt-vs-grammarly/ Verdict: Use ChatGPT when you need ideas, drafts, restructuring, or analysis. Use Grammarly when you already have text and need cleaner writing everywhere you type. Our pick: ChatGPT. (ChatGPT: Free / $20mo; Grammarly: Free / $12mo) ## Claude vs Perplexity - https://aestech.com.au/compare/claude-vs-perplexity/ Verdict: Choose Claude when you need to think, draft, and refine. Choose Perplexity when the first requirement is finding and checking sources quickly. Our pick: Claude. (Claude: Free / $20mo; Perplexity: Free / $20mo) ## GitHub Copilot vs Windsurf - https://aestech.com.au/compare/github-copilot-vs-windsurf/ Verdict: Choose Copilot if GitHub and existing IDE habits matter most. Choose Windsurf if you want an AI-first editor experience with a generous free tier. Our pick: GitHub Copilot. (GitHub Copilot: $10mo; Windsurf: Free / $15mo) ## Cursor vs Claude - https://aestech.com.au/compare/cursor-vs-claude/ Verdict: Choose Cursor when you want AI directly changing code across files. Choose Claude when you want deeper reasoning, planning, and long-context discussion before or around implementation. Our pick: Cursor. (Cursor: Free / $20mo; Claude: Free / $20mo) ## Vanta vs Thoropass - https://aestech.com.au/compare/vanta-vs-thoropass/ Verdict: Pick Vanta for the widest integrations and the safest brand choice; pick Thoropass if you want the audit handled in the same place as the software. Our pick: Vanta. (Vanta: Custom quote; Thoropass: Custom quote) ## Drata vs Thoropass - https://aestech.com.au/compare/drata-vs-thoropass/ Verdict: Drata for best-in-class continuous monitoring with your chosen auditor; Thoropass to collapse software and audit into one vendor. Our pick: Drata. (Drata: Custom quote; Thoropass: Custom quote) ## Sprinto vs Thoropass - https://aestech.com.au/compare/sprinto-vs-thoropass/ Verdict: Sprinto if cost-efficient automation with your own auditor suits you; Thoropass if a single bundled software-plus-audit path is worth more than shopping around. Our pick: Sprinto. (Sprinto: Custom quote; Thoropass: Custom quote) ## Vanta vs Hyperproof - https://aestech.com.au/compare/vanta-vs-hyperproof/ Verdict: Vanta to get certified quickly with minimal lift; Hyperproof once you’re operating several overlapping frameworks and want to reuse evidence across them. Our pick: Vanta. (Vanta: Custom quote; Hyperproof: Custom) ## Sourcegraph Cody vs GitHub Copilot - https://aestech.com.au/compare/sourcegraph-cody-vs-github-copilot/ Verdict: Cody when understanding a big codebase is the hard part; Copilot when you mainly want fast, reliable inline help. Our pick: GitHub Copilot. (Sourcegraph Cody: Free / $9mo; GitHub Copilot: $10mo) ## Qodo vs GitHub Copilot - https://aestech.com.au/compare/qodo-vs-github-copilot/ Verdict: Not really either/or, Copilot to write faster, Qodo to keep what you write tested and reviewed. Our pick: GitHub Copilot. (Qodo: Free / $19mo; GitHub Copilot: $10mo) ## Wordtune vs Grammarly - https://aestech.com.au/compare/wordtune-vs-grammarly/ Verdict: Wordtune if your sentences are correct but clunky; Grammarly if you want a safety net against mistakes across everything you type. Our pick: Grammarly. (Wordtune: Free / $7mo; Grammarly: Free / $12mo) ## Fireflies vs Otter.ai - https://aestech.com.au/compare/fireflies-vs-otter-ai/ Verdict: Fireflies for team and CRM-connected workflows; Otter for the smoothest individual transcription experience. Our pick: Fireflies.ai. (Fireflies.ai: Free / $10mo; Otter.ai: Free / $17mo) ## Thoropass vs Secureframe - https://aestech.com.au/compare/thoropass-vs-secureframe/ Verdict: Thoropass to keep software and audit under one roof; Secureframe if you want a strong platform and the freedom to choose your own auditor. Our pick: Secureframe. (Thoropass: Custom quote; Secureframe: Custom quote) ## Scrut vs Sprinto - https://aestech.com.au/compare/scrut-vs-sprinto/ Verdict: Scrut if you want the widest framework coverage for the money; Sprinto for a lean, fast path to your first SOC 2 or ISO. Our pick: Sprinto. (Scrut Automation: Custom; Sprinto: Custom quote) ## TrustCloud vs Vanta - https://aestech.com.au/compare/trustcloud-vs-vanta/ Verdict: TrustCloud to begin groundwork before you have budget; Vanta when you want the broadest integrations and the most recognised badge for buyers. Our pick: Vanta. (TrustCloud: Free / Custom; Vanta: Custom quote) ## Wordtune vs QuillBot - https://aestech.com.au/compare/wordtune-vs-quillbot/ Verdict: Wordtune for keeping your professional voice while improving flow; QuillBot for heavier paraphrasing and a broader student toolkit. Our pick: Wordtune. (Wordtune: Free / $7mo; QuillBot: Free / $10mo) ## VEED vs Descript - https://aestech.com.au/compare/veed-vs-descript/ Verdict: VEED for fast templated social video; Descript if editing by transcript and podcast workflows fit how you work. Our pick: Descript. (VEED: Free / $18mo; Descript: Free / $24mo) ## Frase vs Surfer SEO - https://aestech.com.au/compare/frase-vs-surfer-seo/ Verdict: Frase for affordable briefs and research; Surfer when you want deeper optimisation data and can justify the spend. Our pick: Surfer SEO. (Frase: $15mo; Surfer SEO: $59mo) ## Apptega vs Vanta - https://aestech.com.au/compare/apptega-vs-vanta/ Verdict: Apptega if you manage many frameworks or clients and value crosswalks; Vanta if you want the most hands-off path to your own certification. Our pick: Vanta. (Apptega: Custom; Vanta: Custom quote) ## Onspring vs AuditBoard - https://aestech.com.au/compare/onspring-vs-auditboard/ Verdict: Onspring when you want to configure GRC to your exact process; AuditBoard when you want a ready-made, audit-centric enterprise suite. Our pick: AuditBoard. (Onspring: Custom; AuditBoard: Custom) ## Bolt vs v0 - https://aestech.com.au/compare/bolt-vs-v0/ Verdict: Bolt for framework-flexible full-stack prototyping; v0 if you’re building React/Next and shipping on Vercel. Our pick: Bolt. (Bolt: Free / $20mo; v0: Free / $20mo) ## v0 vs Lovable - https://aestech.com.au/compare/v0-vs-lovable/ Verdict: v0 for developers wanting great React UI; Lovable for non-technical builders who want a working app from a conversation. Our pick: Lovable. (v0: Free / $20mo; Lovable: Free / $25mo) ## Anyword vs Jasper - https://aestech.com.au/compare/anyword-vs-jasper/ Verdict: Anyword if optimising copy for conversion is the priority; Jasper if brand consistency and team workflow matter more. Our pick: Jasper. (Anyword: $39mo; Jasper: $39mo) ## ClickUp AI vs Notion AI - https://aestech.com.au/compare/clickup-ai-vs-notion-ai/ Verdict: Pick the host tool first: ClickUp if you live in projects and tasks, Notion if you live in docs and wikis. The AI is strongest where its app is. Our pick: Notion AI. (ClickUp AI (Brain): Free / $7mo + AI; Notion AI: $10mo add-on) ## Semrush vs Surfer SEO - https://aestech.com.au/compare/semrush-vs-surfer-seo/ Verdict: Semrush for breadth across research and marketing; Surfer for focused, affordable on-page optimisation. They complement more than compete. Our pick: Semrush. (Semrush: $139mo; Surfer SEO: $59mo) ## SafeBase vs Conveyor - https://aestech.com.au/compare/safebase-vs-conveyor/ Verdict: SafeBase if a great trust centre to deflect reviews is the priority; Conveyor if AI answering inbound questionnaires saves you the most time. Our pick: SafeBase. (SafeBase: Custom; Conveyor: Custom) ## Devin vs Cursor - https://aestech.com.au/compare/devin-vs-cursor/ Verdict: Devin to delegate well-scoped tasks end-to-end; Cursor for fast, interactive coding where you stay in control. Our pick: Cursor. (Devin: From $20mo; Cursor: Free / $20mo) ## Zed vs Cursor - https://aestech.com.au/compare/zed-vs-cursor/ Verdict: Zed if a blazing-fast native editor matters most; Cursor if you want the most capable agentic AI tooling today. Our pick: Cursor. (Zed: Free / paid AI; Cursor: Free / $20mo) ## Writesonic vs Jasper - https://aestech.com.au/compare/writesonic-vs-jasper/ Verdict: Writesonic for affordable SEO output; Jasper when brand consistency and team workflow justify the spend. Our pick: Jasper. (Writesonic: Free / $39mo; Jasper: $39mo) ## Flux vs Midjourney - https://aestech.com.au/compare/flux-vs-midjourney/ Verdict: Flux when you want open models, control, or to build generation into a product; Midjourney for the easiest path to beautiful images. Our pick: Midjourney. (Flux (Black Forest Labs): API / credits; Midjourney: $10mo) ## Captions vs VEED - https://aestech.com.au/compare/captions-vs-veed/ Verdict: Captions if you mainly shoot talking-head clips; VEED for broader, template-driven video editing. Our pick: VEED. (Captions: Free / $10mo; VEED: Free / $18mo) ## Mistral vs ChatGPT - https://aestech.com.au/compare/mistral-vs-chatgpt/ Verdict: ChatGPT for the broadest toolset; Mistral if speed, EU data residency, or open-model alignment matter to you. Our pick: ChatGPT. (Mistral (Le Chat): Free / $15mo; ChatGPT: Free / $20mo) ## Zapier vs Make - https://aestech.com.au/compare/zapier-vs-make/ Verdict: Pick Zapier if you want the widest app coverage and the fastest path from idea to working automation. Pick Make if your workflows branch, loop, or transform data, and you want more operations for less money. Our pick: Zapier. (Zapier: Free / $20mo; Make: Free / $9mo) ## Zapier vs n8n - https://aestech.com.au/compare/zapier-vs-n8n/ Verdict: Zapier wins for business users who need reliable automations without touching code. n8n wins if you have technical skills, want to self-host for data control, or your task volume would make per-task pricing painful. Our pick: n8n. (Zapier: Free / $20mo; n8n: Free self-hosted / $24mo) ## Make vs n8n - https://aestech.com.au/compare/make-vs-n8n/ Verdict: Make is the better pick for non-developers who want deep workflows in a friendly canvas at a low price. n8n is the better pick for technical teams that want code-level control, AI agent nodes, and ownership of their data. Our pick: n8n. (Make: Free / $9mo; n8n: Free self-hosted / $24mo) ## Intercom Fin vs Ada - https://aestech.com.au/compare/intercom-fin-vs-ada/ Verdict: If you already use Intercom, Fin is the obvious pick and the per-resolution pricing keeps risk low. Choose Ada if you run a different helpdesk stack or want an enterprise-grade agent across more channels. Our pick: Intercom Fin. (Intercom Fin: $0.99 per resolution; Ada: Custom) ## NotebookLM vs Perplexity - https://aestech.com.au/compare/notebooklm-vs-perplexity/ Verdict: They complement more than they compete. Pick NotebookLM to interrogate your own PDFs, notes, and transcripts without hallucinated outside facts. Pick Perplexity when the answer lives on the open web and you need citations. Our pick: Perplexity. (NotebookLM: Free / $20mo; Perplexity: Free / $20mo) ## Granola vs Fathom - https://aestech.com.au/compare/granola-vs-fathom/ Verdict: Choose Granola if bots in meetings feel intrusive and you want polished notes that build on what you type. Choose Fathom if you want full recordings, shareable clips, and a free tier that covers most solo users. Our pick: Fathom. (Granola: $18mo; Fathom: Free / $19mo) ## Framer vs v0 - https://aestech.com.au/compare/framer-vs-v0/ Verdict: Pick Framer to design and launch a beautiful marketing site without code. Pick v0 if the end goal is production React components inside a codebase you control. Our pick: Framer. (Framer: Free / $10mo; v0: Free / $20mo) ## Lindy vs Relevance AI - https://aestech.com.au/compare/lindy-vs-relevance-ai/ Verdict: Lindy is the faster win for individuals and small teams automating inbox and calendar work. Relevance AI suits teams building a coordinated set of agents around a revenue or ops process. Our pick: Lindy. (Lindy: Free / $50mo; Relevance AI: Free / $19mo) # Alternatives ## ChatGPT alternatives - https://aestech.com.au/alternatives/chatgpt/ Why switch: Can be generic without good prompting; Usage limits on the free tier. - Claude: 4.8/5, Free / $20mo, best for Long-form writing, analysis, and careful reasoning. - Grammarly: 4.4/5, Free / $12mo, best for Real-time grammar, tone, and clarity everywhere. - Sudowrite: 4.3/5, $19mo, best for Novelists and fiction writers. - Writer: 4.3/5, Custom, best for Enterprises deploying AI writing with governance and brand rules. - Jasper: 4.2/5, $39mo, best for Marketing teams producing on-brand content at volume. ## Claude alternatives - https://aestech.com.au/alternatives/claude/ Why switch: Smaller plugin ecosystem than ChatGPT; Image generation not built in. - ChatGPT: 4.7/5, Free / $20mo, best for All-round writing, brainstorming, and everyday tasks. - Grammarly: 4.4/5, Free / $12mo, best for Real-time grammar, tone, and clarity everywhere. - Sudowrite: 4.3/5, $19mo, best for Novelists and fiction writers. - Writer: 4.3/5, Custom, best for Enterprises deploying AI writing with governance and brand rules. - Jasper: 4.2/5, $39mo, best for Marketing teams producing on-brand content at volume. ## Jasper alternatives - https://aestech.com.au/alternatives/jasper/ Why switch: Pricey for solo users; No meaningful free tier. - Claude: 4.8/5, Free / $20mo, best for Long-form writing, analysis, and careful reasoning. - ChatGPT: 4.7/5, Free / $20mo, best for All-round writing, brainstorming, and everyday tasks. - Grammarly: 4.4/5, Free / $12mo, best for Real-time grammar, tone, and clarity everywhere. - Sudowrite: 4.3/5, $19mo, best for Novelists and fiction writers. - Writer: 4.3/5, Custom, best for Enterprises deploying AI writing with governance and brand rules. ## Copy.ai alternatives - https://aestech.com.au/alternatives/copy-ai/ Why switch: Long-form weaker than rivals; UI can feel busy. - Claude: 4.8/5, Free / $20mo, best for Long-form writing, analysis, and careful reasoning. - ChatGPT: 4.7/5, Free / $20mo, best for All-round writing, brainstorming, and everyday tasks. - Grammarly: 4.4/5, Free / $12mo, best for Real-time grammar, tone, and clarity everywhere. - Sudowrite: 4.3/5, $19mo, best for Novelists and fiction writers. - Writer: 4.3/5, Custom, best for Enterprises deploying AI writing with governance and brand rules. ## Sudowrite alternatives - https://aestech.com.au/alternatives/sudowrite/ Why switch: Niche (fiction only); No free tier. - Claude: 4.8/5, Free / $20mo, best for Long-form writing, analysis, and careful reasoning. - ChatGPT: 4.7/5, Free / $20mo, best for All-round writing, brainstorming, and everyday tasks. - Grammarly: 4.4/5, Free / $12mo, best for Real-time grammar, tone, and clarity everywhere. - Writer: 4.3/5, Custom, best for Enterprises deploying AI writing with governance and brand rules. - Jasper: 4.2/5, $39mo, best for Marketing teams producing on-brand content at volume. ## GitHub Copilot alternatives - https://aestech.com.au/alternatives/github-copilot/ Why switch: Less agentic than newer rivals; Suggestions need review. - Cursor: 4.7/5, Free / $20mo, best for Developers who want agentic, multi-file AI editing. - Framer: 4.5/5, Free / $10mo, best for Designers and startups shipping polished marketing sites fast. - Windsurf: 4.4/5, Free / $15mo, best for Developers wanting agentic editing without the cost. - Aider: 4.4/5, Free (your API key), best for Terminal-first devs who want control. - Sourcegraph Cody: 4.3/5, Free / $9mo, best for Teams working in large, sprawling codebases. ## Cursor alternatives - https://aestech.com.au/alternatives/cursor/ Why switch: It’s a full editor switch; Heavy use needs the paid plan. - GitHub Copilot: 4.5/5, $10mo, best for Developers who want autocomplete-style help in any editor. - Framer: 4.5/5, Free / $10mo, best for Designers and startups shipping polished marketing sites fast. - Windsurf: 4.4/5, Free / $15mo, best for Developers wanting agentic editing without the cost. - Aider: 4.4/5, Free (your API key), best for Terminal-first devs who want control. - Sourcegraph Cody: 4.3/5, Free / $9mo, best for Teams working in large, sprawling codebases. ## Windsurf alternatives - https://aestech.com.au/alternatives/windsurf/ Why switch: Younger ecosystem; Occasional rough edges. - Cursor: 4.7/5, Free / $20mo, best for Developers who want agentic, multi-file AI editing. - GitHub Copilot: 4.5/5, $10mo, best for Developers who want autocomplete-style help in any editor. - Framer: 4.5/5, Free / $10mo, best for Designers and startups shipping polished marketing sites fast. - Aider: 4.4/5, Free (your API key), best for Terminal-first devs who want control. - Sourcegraph Cody: 4.3/5, Free / $9mo, best for Teams working in large, sprawling codebases. ## Tabnine alternatives - https://aestech.com.au/alternatives/tabnine/ Why switch: Completions less sharp than top rivals; Enterprise pricing opaque. - Cursor: 4.7/5, Free / $20mo, best for Developers who want agentic, multi-file AI editing. - GitHub Copilot: 4.5/5, $10mo, best for Developers who want autocomplete-style help in any editor. - Framer: 4.5/5, Free / $10mo, best for Designers and startups shipping polished marketing sites fast. - Windsurf: 4.4/5, Free / $15mo, best for Developers wanting agentic editing without the cost. - Aider: 4.4/5, Free (your API key), best for Terminal-first devs who want control. ## Replit alternatives - https://aestech.com.au/alternatives/replit/ Why switch: Not for large production codebases; Resource limits on lower tiers. - Cursor: 4.7/5, Free / $20mo, best for Developers who want agentic, multi-file AI editing. - GitHub Copilot: 4.5/5, $10mo, best for Developers who want autocomplete-style help in any editor. - Framer: 4.5/5, Free / $10mo, best for Designers and startups shipping polished marketing sites fast. - Windsurf: 4.4/5, Free / $15mo, best for Developers wanting agentic editing without the cost. - Aider: 4.4/5, Free (your API key), best for Terminal-first devs who want control. ## Midjourney alternatives - https://aestech.com.au/alternatives/midjourney/ Why switch: No free tier; Workflow takes adjusting. - Adobe Firefly: 4.3/5, Free / $5mo, best for Designers needing commercial-safe assets. - Ideogram: 4.3/5, Free / $8mo, best for Logos, posters, and images with legible text. - Recraft: 4.3/5, Free / $12mo, best for Designers needing vectors and brand consistency. - Flux (Black Forest Labs): 4.3/5, API / credits, best for Developers and power users who want top-tier open image models. - Leonardo AI: 4.2/5, Free / $12mo, best for Game artists and control-focused creators. ## Adobe Firefly alternatives - https://aestech.com.au/alternatives/adobe-firefly/ Why switch: Less edgy than Midjourney; Best value inside CC. - Midjourney: 4.6/5, $10mo, best for Designers wanting the best visual quality. - Ideogram: 4.3/5, Free / $8mo, best for Logos, posters, and images with legible text. - Recraft: 4.3/5, Free / $12mo, best for Designers needing vectors and brand consistency. - Flux (Black Forest Labs): 4.3/5, API / credits, best for Developers and power users who want top-tier open image models. - Leonardo AI: 4.2/5, Free / $12mo, best for Game artists and control-focused creators. ## Leonardo AI alternatives - https://aestech.com.au/alternatives/leonardo-ai/ Why switch: Steeper learning curve; Credit system to manage. - Midjourney: 4.6/5, $10mo, best for Designers wanting the best visual quality. - Adobe Firefly: 4.3/5, Free / $5mo, best for Designers needing commercial-safe assets. - Ideogram: 4.3/5, Free / $8mo, best for Logos, posters, and images with legible text. - Recraft: 4.3/5, Free / $12mo, best for Designers needing vectors and brand consistency. - Flux (Black Forest Labs): 4.3/5, API / credits, best for Developers and power users who want top-tier open image models. ## Ideogram alternatives - https://aestech.com.au/alternatives/ideogram/ Why switch: Photoreal slightly behind leaders; Newer, smaller community. - Midjourney: 4.6/5, $10mo, best for Designers wanting the best visual quality. - Adobe Firefly: 4.3/5, Free / $5mo, best for Designers needing commercial-safe assets. - Recraft: 4.3/5, Free / $12mo, best for Designers needing vectors and brand consistency. - Flux (Black Forest Labs): 4.3/5, API / credits, best for Developers and power users who want top-tier open image models. - Leonardo AI: 4.2/5, Free / $12mo, best for Game artists and control-focused creators. ## Runway alternatives - https://aestech.com.au/alternatives/runway/ Why switch: Credits burn fast; Learning curve. - Descript: 4.5/5, Free / $24mo, best for Podcasters and creators editing by text. - Synthesia: 4.3/5, $18mo, best for Corporate training, explainers, and L&D. - HeyGen: 4.3/5, Free / $24mo, best for Marketing video and video translation. - Kling AI: 4.3/5, Free / $10mo, best for Realistic motion and longer clips. - Pika: 4.2/5, Free / $10mo, best for Short, creative social video. ## Synthesia alternatives - https://aestech.com.au/alternatives/synthesia/ Why switch: Not for cinematic/creative video; No real free tier. - Descript: 4.5/5, Free / $24mo, best for Podcasters and creators editing by text. - Runway: 4.4/5, Free / $15mo, best for Filmmakers and motion creators. - HeyGen: 4.3/5, Free / $24mo, best for Marketing video and video translation. - Kling AI: 4.3/5, Free / $10mo, best for Realistic motion and longer clips. - Pika: 4.2/5, Free / $10mo, best for Short, creative social video. ## HeyGen alternatives - https://aestech.com.au/alternatives/heygen/ Why switch: Costs scale with minutes; Avatars still slightly uncanny. - Descript: 4.5/5, Free / $24mo, best for Podcasters and creators editing by text. - Runway: 4.4/5, Free / $15mo, best for Filmmakers and motion creators. - Synthesia: 4.3/5, $18mo, best for Corporate training, explainers, and L&D. - Kling AI: 4.3/5, Free / $10mo, best for Realistic motion and longer clips. - Pika: 4.2/5, Free / $10mo, best for Short, creative social video. ## Descript alternatives - https://aestech.com.au/alternatives/descript/ Why switch: Heavy projects can lag; Some features paywalled. - Runway: 4.4/5, Free / $15mo, best for Filmmakers and motion creators. - Synthesia: 4.3/5, $18mo, best for Corporate training, explainers, and L&D. - HeyGen: 4.3/5, Free / $24mo, best for Marketing video and video translation. - Kling AI: 4.3/5, Free / $10mo, best for Realistic motion and longer clips. - Pika: 4.2/5, Free / $10mo, best for Short, creative social video. ## ElevenLabs alternatives - https://aestech.com.au/alternatives/elevenlabs/ Why switch: Character limits on lower tiers; Cloning needs ethical care. - Suno: 4.4/5, Free / $8mo, best for Music creation and jingles. - Udio: 4.3/5, Free / $10mo, best for AI music with strong audio quality. - WellSaid Labs: 4.2/5, $49mo, best for Corporate e-learning and training voiceover at scale. - Murf: 4.1/5, Free / $19mo, best for Corporate voiceover and e-learning. - Play.ht: 4.1/5, Free / $19mo, best for Developers adding voice via API. ## Murf alternatives - https://aestech.com.au/alternatives/murf/ Why switch: Less expressive than ElevenLabs; Voice library varies in quality. - ElevenLabs: 4.7/5, Free / $5mo, best for Voiceover, audiobooks, and voice cloning. - Suno: 4.4/5, Free / $8mo, best for Music creation and jingles. - Udio: 4.3/5, Free / $10mo, best for AI music with strong audio quality. - WellSaid Labs: 4.2/5, $49mo, best for Corporate e-learning and training voiceover at scale. - Play.ht: 4.1/5, Free / $19mo, best for Developers adding voice via API. ## Suno alternatives - https://aestech.com.au/alternatives/suno/ Why switch: Limited fine editing; Commercial rights tier-gated. - ElevenLabs: 4.7/5, Free / $5mo, best for Voiceover, audiobooks, and voice cloning. - Udio: 4.3/5, Free / $10mo, best for AI music with strong audio quality. - WellSaid Labs: 4.2/5, $49mo, best for Corporate e-learning and training voiceover at scale. - Murf: 4.1/5, Free / $19mo, best for Corporate voiceover and e-learning. - Play.ht: 4.1/5, Free / $19mo, best for Developers adding voice via API. ## Notion AI alternatives - https://aestech.com.au/alternatives/notion-ai/ Why switch: Only useful if you use Notion; Add-on cost on top of Notion. - NotebookLM: 4.6/5, Free / $20mo, best for Researchers and knowledge workers synthesising piles of documents. - Fathom: 4.5/5, Free / $19mo, best for Free, accurate meeting summaries. - Granola: 4.5/5, $18mo, best for People in back-to-back meetings who hate visible recording bots. - Gamma: 4.4/5, Free / $10mo, best for Anyone who needs good-looking presentations fast. - Krisp: 4.4/5, Free / $8mo, best for Remote workers in noisy environments and on bad connections. ## Otter.ai alternatives - https://aestech.com.au/alternatives/otter-ai/ Why switch: Accuracy varies with audio; Integrations gated to paid. - NotebookLM: 4.6/5, Free / $20mo, best for Researchers and knowledge workers synthesising piles of documents. - Fathom: 4.5/5, Free / $19mo, best for Free, accurate meeting summaries. - Granola: 4.5/5, $18mo, best for People in back-to-back meetings who hate visible recording bots. - Gamma: 4.4/5, Free / $10mo, best for Anyone who needs good-looking presentations fast. - Krisp: 4.4/5, Free / $8mo, best for Remote workers in noisy environments and on bad connections. ## Motion alternatives - https://aestech.com.au/alternatives/motion/ Why switch: Pricey; Takes time to trust the automation. - NotebookLM: 4.6/5, Free / $20mo, best for Researchers and knowledge workers synthesising piles of documents. - Fathom: 4.5/5, Free / $19mo, best for Free, accurate meeting summaries. - Granola: 4.5/5, $18mo, best for People in back-to-back meetings who hate visible recording bots. - Gamma: 4.4/5, Free / $10mo, best for Anyone who needs good-looking presentations fast. - Krisp: 4.4/5, Free / $8mo, best for Remote workers in noisy environments and on bad connections. ## Perplexity alternatives - https://aestech.com.au/alternatives/perplexity/ Why switch: Not built for long-form creation; Pro features gated. - Gemini: 4.4/5, Free / $20mo, best for Google Workspace users and huge-context tasks. - DeepSeek: 4.2/5, Free / low-cost API, best for Cost-conscious power users and developers. - Microsoft Copilot: 4.1/5, Free / $20mo, best for Microsoft 365 and Windows users. - Poe: 4.1/5, Free / $20mo, best for People who want to compare and switch between models in one place. - Mistral (Le Chat): 4.1/5, Free / $15mo, best for Users who want a capable, EU-based assistant and open models. ## Gemini alternatives - https://aestech.com.au/alternatives/gemini/ Why switch: Quality varies by task; Best value inside Google’s ecosystem. - Perplexity: 4.5/5, Free / $20mo, best for Research and fact-finding with citations. - DeepSeek: 4.2/5, Free / low-cost API, best for Cost-conscious power users and developers. - Microsoft Copilot: 4.1/5, Free / $20mo, best for Microsoft 365 and Windows users. - Poe: 4.1/5, Free / $20mo, best for People who want to compare and switch between models in one place. - Mistral (Le Chat): 4.1/5, Free / $15mo, best for Users who want a capable, EU-based assistant and open models. ## Microsoft Copilot alternatives - https://aestech.com.au/alternatives/microsoft-copilot/ Why switch: Inconsistent across apps; Best value requires M365. - Perplexity: 4.5/5, Free / $20mo, best for Research and fact-finding with citations. - Gemini: 4.4/5, Free / $20mo, best for Google Workspace users and huge-context tasks. - DeepSeek: 4.2/5, Free / low-cost API, best for Cost-conscious power users and developers. - Poe: 4.1/5, Free / $20mo, best for People who want to compare and switch between models in one place. - Mistral (Le Chat): 4.1/5, Free / $15mo, best for Users who want a capable, EU-based assistant and open models. ## Surfer SEO alternatives - https://aestech.com.au/alternatives/surfer-seo/ Why switch: Pricey for hobbyists; Can encourage over-optimisation. - Clearscope: 4.4/5, $170mo, best for Content teams that treat SEO as a core channel. - Semrush: 4.4/5, $139mo, best for Marketing teams that want one platform for SEO, ads, and content. - Opus Clip: 4.2/5, Free / $9mo, best for Repurposing long video into shorts/reels. - Buffer AI Assistant: 4.1/5, Free / $6mo, best for Small teams managing social channels. - Frase: 4.1/5, $15mo, best for SEO writers building optimised briefs and first drafts. ## Opus Clip alternatives - https://aestech.com.au/alternatives/opus-clip/ Why switch: Clip picks need review; Watermark on free tier. - Clearscope: 4.4/5, $170mo, best for Content teams that treat SEO as a core channel. - Semrush: 4.4/5, $139mo, best for Marketing teams that want one platform for SEO, ads, and content. - Surfer SEO: 4.3/5, $59mo, best for Content teams optimising for search. - Buffer AI Assistant: 4.1/5, Free / $6mo, best for Small teams managing social channels. - Frase: 4.1/5, $15mo, best for SEO writers building optimised briefs and first drafts. ## Grammarly alternatives - https://aestech.com.au/alternatives/grammarly/ Why switch: Generative features gated to paid; Suggestions can be conservative. - Claude: 4.8/5, Free / $20mo, best for Long-form writing, analysis, and careful reasoning. - ChatGPT: 4.7/5, Free / $20mo, best for All-round writing, brainstorming, and everyday tasks. - Sudowrite: 4.3/5, $19mo, best for Novelists and fiction writers. - Writer: 4.3/5, Custom, best for Enterprises deploying AI writing with governance and brand rules. - Jasper: 4.2/5, $39mo, best for Marketing teams producing on-brand content at volume. ## Rytr alternatives - https://aestech.com.au/alternatives/rytr/ Why switch: Output quality trails premium tools; Weak long-form. - Claude: 4.8/5, Free / $20mo, best for Long-form writing, analysis, and careful reasoning. - ChatGPT: 4.7/5, Free / $20mo, best for All-round writing, brainstorming, and everyday tasks. - Grammarly: 4.4/5, Free / $12mo, best for Real-time grammar, tone, and clarity everywhere. - Sudowrite: 4.3/5, $19mo, best for Novelists and fiction writers. - Writer: 4.3/5, Custom, best for Enterprises deploying AI writing with governance and brand rules. ## Amazon Q Developer alternatives - https://aestech.com.au/alternatives/amazon-q-developer/ Why switch: Best value only on AWS; Less general than rivals. - Cursor: 4.7/5, Free / $20mo, best for Developers who want agentic, multi-file AI editing. - GitHub Copilot: 4.5/5, $10mo, best for Developers who want autocomplete-style help in any editor. - Framer: 4.5/5, Free / $10mo, best for Designers and startups shipping polished marketing sites fast. - Windsurf: 4.4/5, Free / $15mo, best for Developers wanting agentic editing without the cost. - Aider: 4.4/5, Free (your API key), best for Terminal-first devs who want control. ## Aider alternatives - https://aestech.com.au/alternatives/aider/ Why switch: Terminal/CLI only; You pay for model API usage. - Cursor: 4.7/5, Free / $20mo, best for Developers who want agentic, multi-file AI editing. - GitHub Copilot: 4.5/5, $10mo, best for Developers who want autocomplete-style help in any editor. - Framer: 4.5/5, Free / $10mo, best for Designers and startups shipping polished marketing sites fast. - Windsurf: 4.4/5, Free / $15mo, best for Developers wanting agentic editing without the cost. - Sourcegraph Cody: 4.3/5, Free / $9mo, best for Teams working in large, sprawling codebases. ## Recraft alternatives - https://aestech.com.au/alternatives/recraft/ Why switch: Less photoreal than Midjourney; Learning curve. - Midjourney: 4.6/5, $10mo, best for Designers wanting the best visual quality. - Adobe Firefly: 4.3/5, Free / $5mo, best for Designers needing commercial-safe assets. - Ideogram: 4.3/5, Free / $8mo, best for Logos, posters, and images with legible text. - Flux (Black Forest Labs): 4.3/5, API / credits, best for Developers and power users who want top-tier open image models. - Leonardo AI: 4.2/5, Free / $12mo, best for Game artists and control-focused creators. ## Krea alternatives - https://aestech.com.au/alternatives/krea/ Why switch: Credits on free tier; Less known. - Midjourney: 4.6/5, $10mo, best for Designers wanting the best visual quality. - Adobe Firefly: 4.3/5, Free / $5mo, best for Designers needing commercial-safe assets. - Ideogram: 4.3/5, Free / $8mo, best for Logos, posters, and images with legible text. - Recraft: 4.3/5, Free / $12mo, best for Designers needing vectors and brand consistency. - Flux (Black Forest Labs): 4.3/5, API / credits, best for Developers and power users who want top-tier open image models. ## Pika alternatives - https://aestech.com.au/alternatives/pika/ Why switch: Shorter clips; Less control than Runway. - Descript: 4.5/5, Free / $24mo, best for Podcasters and creators editing by text. - Runway: 4.4/5, Free / $15mo, best for Filmmakers and motion creators. - Synthesia: 4.3/5, $18mo, best for Corporate training, explainers, and L&D. - HeyGen: 4.3/5, Free / $24mo, best for Marketing video and video translation. - Kling AI: 4.3/5, Free / $10mo, best for Realistic motion and longer clips. ## Kling AI alternatives - https://aestech.com.au/alternatives/kling/ Why switch: Queue times; Interface rough in English. - Descript: 4.5/5, Free / $24mo, best for Podcasters and creators editing by text. - Runway: 4.4/5, Free / $15mo, best for Filmmakers and motion creators. - Synthesia: 4.3/5, $18mo, best for Corporate training, explainers, and L&D. - HeyGen: 4.3/5, Free / $24mo, best for Marketing video and video translation. - Pika: 4.2/5, Free / $10mo, best for Short, creative social video. ## Luma Dream Machine alternatives - https://aestech.com.au/alternatives/luma-dream-machine/ Why switch: Credit limits; Less editing control. - Descript: 4.5/5, Free / $24mo, best for Podcasters and creators editing by text. - Runway: 4.4/5, Free / $15mo, best for Filmmakers and motion creators. - Synthesia: 4.3/5, $18mo, best for Corporate training, explainers, and L&D. - HeyGen: 4.3/5, Free / $24mo, best for Marketing video and video translation. - Kling AI: 4.3/5, Free / $10mo, best for Realistic motion and longer clips. ## Play.ht alternatives - https://aestech.com.au/alternatives/play-ht/ Why switch: ElevenLabs edges it on quality; Pricing complexity. - ElevenLabs: 4.7/5, Free / $5mo, best for Voiceover, audiobooks, and voice cloning. - Suno: 4.4/5, Free / $8mo, best for Music creation and jingles. - Udio: 4.3/5, Free / $10mo, best for AI music with strong audio quality. - WellSaid Labs: 4.2/5, $49mo, best for Corporate e-learning and training voiceover at scale. - Murf: 4.1/5, Free / $19mo, best for Corporate voiceover and e-learning. ## Udio alternatives - https://aestech.com.au/alternatives/udio/ Why switch: Editing limited; Rights tier-gated. - ElevenLabs: 4.7/5, Free / $5mo, best for Voiceover, audiobooks, and voice cloning. - Suno: 4.4/5, Free / $8mo, best for Music creation and jingles. - WellSaid Labs: 4.2/5, $49mo, best for Corporate e-learning and training voiceover at scale. - Murf: 4.1/5, Free / $19mo, best for Corporate voiceover and e-learning. - Play.ht: 4.1/5, Free / $19mo, best for Developers adding voice via API. ## Fathom alternatives - https://aestech.com.au/alternatives/fathom/ Why switch: Meeting-only scope; Advanced features paid. - NotebookLM: 4.6/5, Free / $20mo, best for Researchers and knowledge workers synthesising piles of documents. - Granola: 4.5/5, $18mo, best for People in back-to-back meetings who hate visible recording bots. - Gamma: 4.4/5, Free / $10mo, best for Anyone who needs good-looking presentations fast. - Krisp: 4.4/5, Free / $8mo, best for Remote workers in noisy environments and on bad connections. - Notion AI: 4.3/5, $10mo add-on, best for Teams already living in Notion. ## Mem alternatives - https://aestech.com.au/alternatives/mem/ Why switch: Opinionated workflow; Smaller ecosystem. - NotebookLM: 4.6/5, Free / $20mo, best for Researchers and knowledge workers synthesising piles of documents. - Fathom: 4.5/5, Free / $19mo, best for Free, accurate meeting summaries. - Granola: 4.5/5, $18mo, best for People in back-to-back meetings who hate visible recording bots. - Gamma: 4.4/5, Free / $10mo, best for Anyone who needs good-looking presentations fast. - Krisp: 4.4/5, Free / $8mo, best for Remote workers in noisy environments and on bad connections. ## Grok alternatives - https://aestech.com.au/alternatives/grok/ Why switch: Best value tied to X; Quality varies. - Perplexity: 4.5/5, Free / $20mo, best for Research and fact-finding with citations. - Gemini: 4.4/5, Free / $20mo, best for Google Workspace users and huge-context tasks. - DeepSeek: 4.2/5, Free / low-cost API, best for Cost-conscious power users and developers. - Microsoft Copilot: 4.1/5, Free / $20mo, best for Microsoft 365 and Windows users. - Poe: 4.1/5, Free / $20mo, best for People who want to compare and switch between models in one place. ## DeepSeek alternatives - https://aestech.com.au/alternatives/deepseek/ Why switch: Data/privacy considerations; Fewer consumer features. - Perplexity: 4.5/5, Free / $20mo, best for Research and fact-finding with citations. - Gemini: 4.4/5, Free / $20mo, best for Google Workspace users and huge-context tasks. - Microsoft Copilot: 4.1/5, Free / $20mo, best for Microsoft 365 and Windows users. - Poe: 4.1/5, Free / $20mo, best for People who want to compare and switch between models in one place. - Mistral (Le Chat): 4.1/5, Free / $15mo, best for Users who want a capable, EU-based assistant and open models. ## AdCreative.ai alternatives - https://aestech.com.au/alternatives/adcreative/ Why switch: Pricey; Outputs need polish. - Clearscope: 4.4/5, $170mo, best for Content teams that treat SEO as a core channel. - Semrush: 4.4/5, $139mo, best for Marketing teams that want one platform for SEO, ads, and content. - Surfer SEO: 4.3/5, $59mo, best for Content teams optimising for search. - Opus Clip: 4.2/5, Free / $9mo, best for Repurposing long video into shorts/reels. - Buffer AI Assistant: 4.1/5, Free / $6mo, best for Small teams managing social channels. ## Buffer AI Assistant alternatives - https://aestech.com.au/alternatives/buffer-ai/ Why switch: Light analytics; AI is assistive, not magic. - Clearscope: 4.4/5, $170mo, best for Content teams that treat SEO as a core channel. - Semrush: 4.4/5, $139mo, best for Marketing teams that want one platform for SEO, ads, and content. - Surfer SEO: 4.3/5, $59mo, best for Content teams optimising for search. - Opus Clip: 4.2/5, Free / $9mo, best for Repurposing long video into shorts/reels. - Frase: 4.1/5, $15mo, best for SEO writers building optimised briefs and first drafts. ## Vanta alternatives - https://aestech.com.au/alternatives/vanta/ Why switch: Quote-based pricing, not cheap for small teams; You still engage a separate accredited auditor. - Drata: 4.6/5, Custom quote, best for Teams wanting continuous control monitoring across many frameworks. - Secureframe: 4.5/5, Custom quote, best for First-time compliance teams who want more guidance. - Sprinto: 4.4/5, Custom quote, best for Cloud-native SMBs wanting quick time-to-audit. - Scrut Automation: 4.4/5, Custom, best for Startups wanting broad framework coverage without enterprise pricing. - Thoropass: 4.3/5, Custom quote, best for Teams that want the software and the audit from one vendor. ## Drata alternatives - https://aestech.com.au/alternatives/drata/ Why switch: Premium pricing; Initial setup still takes real effort. - Vanta: 4.6/5, Custom quote, best for Startups and scale-ups automating ISO 27001, SOC 2, and PCI DSS. - Secureframe: 4.5/5, Custom quote, best for First-time compliance teams who want more guidance. - Sprinto: 4.4/5, Custom quote, best for Cloud-native SMBs wanting quick time-to-audit. - Scrut Automation: 4.4/5, Custom, best for Startups wanting broad framework coverage without enterprise pricing. - Thoropass: 4.3/5, Custom quote, best for Teams that want the software and the audit from one vendor. ## Secureframe alternatives - https://aestech.com.au/alternatives/secureframe/ Why switch: Quote-based pricing; Smaller integration set than the two leaders. - Vanta: 4.6/5, Custom quote, best for Startups and scale-ups automating ISO 27001, SOC 2, and PCI DSS. - Drata: 4.6/5, Custom quote, best for Teams wanting continuous control monitoring across many frameworks. - Sprinto: 4.4/5, Custom quote, best for Cloud-native SMBs wanting quick time-to-audit. - Scrut Automation: 4.4/5, Custom, best for Startups wanting broad framework coverage without enterprise pricing. - Thoropass: 4.3/5, Custom quote, best for Teams that want the software and the audit from one vendor. ## Sprinto alternatives - https://aestech.com.au/alternatives/sprinto/ Why switch: Fewer enterprise features; Newer brand than Vanta/Drata. - Vanta: 4.6/5, Custom quote, best for Startups and scale-ups automating ISO 27001, SOC 2, and PCI DSS. - Drata: 4.6/5, Custom quote, best for Teams wanting continuous control monitoring across many frameworks. - Secureframe: 4.5/5, Custom quote, best for First-time compliance teams who want more guidance. - Scrut Automation: 4.4/5, Custom, best for Startups wanting broad framework coverage without enterprise pricing. - Thoropass: 4.3/5, Custom quote, best for Teams that want the software and the audit from one vendor. ## Thoropass alternatives - https://aestech.com.au/alternatives/thoropass/ Why switch: Less of a pure-play platform; Smaller integration library. - Vanta: 4.6/5, Custom quote, best for Startups and scale-ups automating ISO 27001, SOC 2, and PCI DSS. - Drata: 4.6/5, Custom quote, best for Teams wanting continuous control monitoring across many frameworks. - Secureframe: 4.5/5, Custom quote, best for First-time compliance teams who want more guidance. - Sprinto: 4.4/5, Custom quote, best for Cloud-native SMBs wanting quick time-to-audit. - Scrut Automation: 4.4/5, Custom, best for Startups wanting broad framework coverage without enterprise pricing. ## Snyk alternatives - https://aestech.com.au/alternatives/snyk/ Why switch: Focused on open-source, not proprietary code; Premium pricing at scale. - GitHub Advanced Security: 4.3/5, $21/usermo, best for Teams already on GitHub wanting built-in security scanning. - Lakera: 4.3/5, Custom quote, best for Teams building and deploying LLM-powered applications. - Checkmarx One: 4.2/5, Custom quote, best for Large teams needing comprehensive application security testing. - OneTrust: 4.2/5, Custom quote, best for Organisations handling personal data across multiple jurisdictions. - Giskard AI: 4.1/5, Free / $49mo, best for Data science teams wanting to test model robustness and bias. ## GitHub Advanced Security alternatives - https://aestech.com.au/alternatives/github-advanced-security/ Why switch: Only works within GitHub; Less useful for non-code assets. - Snyk: 4.4/5, Free / $49mo, best for Finding and fixing vulnerabilities in open-source dependencies. - Lakera: 4.3/5, Custom quote, best for Teams building and deploying LLM-powered applications. - Checkmarx One: 4.2/5, Custom quote, best for Large teams needing comprehensive application security testing. - OneTrust: 4.2/5, Custom quote, best for Organisations handling personal data across multiple jurisdictions. - Giskard AI: 4.1/5, Free / $49mo, best for Data science teams wanting to test model robustness and bias. ## Checkmarx One alternatives - https://aestech.com.au/alternatives/checkmarx-one/ Why switch: Complex setup; Expensive for small teams. - Snyk: 4.4/5, Free / $49mo, best for Finding and fixing vulnerabilities in open-source dependencies. - GitHub Advanced Security: 4.3/5, $21/usermo, best for Teams already on GitHub wanting built-in security scanning. - Lakera: 4.3/5, Custom quote, best for Teams building and deploying LLM-powered applications. - OneTrust: 4.2/5, Custom quote, best for Organisations handling personal data across multiple jurisdictions. - Giskard AI: 4.1/5, Free / $49mo, best for Data science teams wanting to test model robustness and bias. ## Lakera alternatives - https://aestech.com.au/alternatives/lakera/ Why switch: Narrower scope than general security tools; Newer vendor. - Snyk: 4.4/5, Free / $49mo, best for Finding and fixing vulnerabilities in open-source dependencies. - GitHub Advanced Security: 4.3/5, $21/usermo, best for Teams already on GitHub wanting built-in security scanning. - Checkmarx One: 4.2/5, Custom quote, best for Large teams needing comprehensive application security testing. - OneTrust: 4.2/5, Custom quote, best for Organisations handling personal data across multiple jurisdictions. - Giskard AI: 4.1/5, Free / $49mo, best for Data science teams wanting to test model robustness and bias. ## Giskard AI alternatives - https://aestech.com.au/alternatives/giskard-ai/ Why switch: Smaller ecosystem than general security tools; Still maturing. - Snyk: 4.4/5, Free / $49mo, best for Finding and fixing vulnerabilities in open-source dependencies. - GitHub Advanced Security: 4.3/5, $21/usermo, best for Teams already on GitHub wanting built-in security scanning. - Lakera: 4.3/5, Custom quote, best for Teams building and deploying LLM-powered applications. - Checkmarx One: 4.2/5, Custom quote, best for Large teams needing comprehensive application security testing. - OneTrust: 4.2/5, Custom quote, best for Organisations handling personal data across multiple jurisdictions. ## IBM watsonx.governance alternatives - https://aestech.com.au/alternatives/watsonx-governance/ Why switch: Heavy enterprise pricing and setup; Best for large orgs. - Snyk: 4.4/5, Free / $49mo, best for Finding and fixing vulnerabilities in open-source dependencies. - GitHub Advanced Security: 4.3/5, $21/usermo, best for Teams already on GitHub wanting built-in security scanning. - Lakera: 4.3/5, Custom quote, best for Teams building and deploying LLM-powered applications. - Checkmarx One: 4.2/5, Custom quote, best for Large teams needing comprehensive application security testing. - OneTrust: 4.2/5, Custom quote, best for Organisations handling personal data across multiple jurisdictions. ## OneTrust alternatives - https://aestech.com.au/alternatives/onetrust/ Why switch: Expensive; Complex to implement. - Snyk: 4.4/5, Free / $49mo, best for Finding and fixing vulnerabilities in open-source dependencies. - GitHub Advanced Security: 4.3/5, $21/usermo, best for Teams already on GitHub wanting built-in security scanning. - Lakera: 4.3/5, Custom quote, best for Teams building and deploying LLM-powered applications. - Checkmarx One: 4.2/5, Custom quote, best for Large teams needing comprehensive application security testing. - Giskard AI: 4.1/5, Free / $49mo, best for Data science teams wanting to test model robustness and bias. ## Privacera alternatives - https://aestech.com.au/alternatives/privacera/ Why switch: Focused on cloud data, not app security; Enterprise pricing. - Snyk: 4.4/5, Free / $49mo, best for Finding and fixing vulnerabilities in open-source dependencies. - GitHub Advanced Security: 4.3/5, $21/usermo, best for Teams already on GitHub wanting built-in security scanning. - Lakera: 4.3/5, Custom quote, best for Teams building and deploying LLM-powered applications. - Checkmarx One: 4.2/5, Custom quote, best for Large teams needing comprehensive application security testing. - OneTrust: 4.2/5, Custom quote, best for Organisations handling personal data across multiple jurisdictions. ## Hyperproof alternatives - https://aestech.com.au/alternatives/hyperproof/ Why switch: Quote-based pricing, no public tier; Heavier than a first-SOC-2 tool needs. - Vanta: 4.6/5, Custom quote, best for Startups and scale-ups automating ISO 27001, SOC 2, and PCI DSS. - Drata: 4.6/5, Custom quote, best for Teams wanting continuous control monitoring across many frameworks. - Secureframe: 4.5/5, Custom quote, best for First-time compliance teams who want more guidance. - Sprinto: 4.4/5, Custom quote, best for Cloud-native SMBs wanting quick time-to-audit. - Scrut Automation: 4.4/5, Custom, best for Startups wanting broad framework coverage without enterprise pricing. ## Scrut Automation alternatives - https://aestech.com.au/alternatives/scrut/ Why switch: Smaller brand than Vanta/Drata; Quote-based pricing. - Vanta: 4.6/5, Custom quote, best for Startups and scale-ups automating ISO 27001, SOC 2, and PCI DSS. - Drata: 4.6/5, Custom quote, best for Teams wanting continuous control monitoring across many frameworks. - Secureframe: 4.5/5, Custom quote, best for First-time compliance teams who want more guidance. - Sprinto: 4.4/5, Custom quote, best for Cloud-native SMBs wanting quick time-to-audit. - Thoropass: 4.3/5, Custom quote, best for Teams that want the software and the audit from one vendor. ## Anecdotes alternatives - https://aestech.com.au/alternatives/anecdotes/ Why switch: Enterprise-only fit and pricing; Overkill for early-stage teams. - Vanta: 4.6/5, Custom quote, best for Startups and scale-ups automating ISO 27001, SOC 2, and PCI DSS. - Drata: 4.6/5, Custom quote, best for Teams wanting continuous control monitoring across many frameworks. - Secureframe: 4.5/5, Custom quote, best for First-time compliance teams who want more guidance. - Sprinto: 4.4/5, Custom quote, best for Cloud-native SMBs wanting quick time-to-audit. - Scrut Automation: 4.4/5, Custom, best for Startups wanting broad framework coverage without enterprise pricing. ## Sourcegraph Cody alternatives - https://aestech.com.au/alternatives/sourcegraph-cody/ Why switch: Best value tied to Sourcegraph search; Less agentic than Cursor. - Cursor: 4.7/5, Free / $20mo, best for Developers who want agentic, multi-file AI editing. - GitHub Copilot: 4.5/5, $10mo, best for Developers who want autocomplete-style help in any editor. - Framer: 4.5/5, Free / $10mo, best for Designers and startups shipping polished marketing sites fast. - Windsurf: 4.4/5, Free / $15mo, best for Developers wanting agentic editing without the cost. - Aider: 4.4/5, Free (your API key), best for Terminal-first devs who want control. ## Qodo alternatives - https://aestech.com.au/alternatives/qodo/ Why switch: Narrower than a general assistant; Newer brand (formerly Codium). - Cursor: 4.7/5, Free / $20mo, best for Developers who want agentic, multi-file AI editing. - GitHub Copilot: 4.5/5, $10mo, best for Developers who want autocomplete-style help in any editor. - Framer: 4.5/5, Free / $10mo, best for Designers and startups shipping polished marketing sites fast. - Windsurf: 4.4/5, Free / $15mo, best for Developers wanting agentic editing without the cost. - Aider: 4.4/5, Free (your API key), best for Terminal-first devs who want control. ## JetBrains AI Assistant alternatives - https://aestech.com.au/alternatives/jetbrains-ai/ Why switch: Only useful inside JetBrains IDEs; Trails Cursor on agentic editing. - Cursor: 4.7/5, Free / $20mo, best for Developers who want agentic, multi-file AI editing. - GitHub Copilot: 4.5/5, $10mo, best for Developers who want autocomplete-style help in any editor. - Framer: 4.5/5, Free / $10mo, best for Designers and startups shipping polished marketing sites fast. - Windsurf: 4.4/5, Free / $15mo, best for Developers wanting agentic editing without the cost. - Aider: 4.4/5, Free (your API key), best for Terminal-first devs who want control. ## Wordtune alternatives - https://aestech.com.au/alternatives/wordtune/ Why switch: Less suited to long-form generation; Best features are paid. - Claude: 4.8/5, Free / $20mo, best for Long-form writing, analysis, and careful reasoning. - ChatGPT: 4.7/5, Free / $20mo, best for All-round writing, brainstorming, and everyday tasks. - Grammarly: 4.4/5, Free / $12mo, best for Real-time grammar, tone, and clarity everywhere. - Sudowrite: 4.3/5, $19mo, best for Novelists and fiction writers. - Writer: 4.3/5, Custom, best for Enterprises deploying AI writing with governance and brand rules. ## QuillBot alternatives - https://aestech.com.au/alternatives/quillbot/ Why switch: Free tier word limits; Not a full content generator. - Claude: 4.8/5, Free / $20mo, best for Long-form writing, analysis, and careful reasoning. - ChatGPT: 4.7/5, Free / $20mo, best for All-round writing, brainstorming, and everyday tasks. - Grammarly: 4.4/5, Free / $12mo, best for Real-time grammar, tone, and clarity everywhere. - Sudowrite: 4.3/5, $19mo, best for Novelists and fiction writers. - Writer: 4.3/5, Custom, best for Enterprises deploying AI writing with governance and brand rules. ## Gamma alternatives - https://aestech.com.au/alternatives/gamma/ Why switch: Less control than manual design tools; Templated look at scale. - NotebookLM: 4.6/5, Free / $20mo, best for Researchers and knowledge workers synthesising piles of documents. - Fathom: 4.5/5, Free / $19mo, best for Free, accurate meeting summaries. - Granola: 4.5/5, $18mo, best for People in back-to-back meetings who hate visible recording bots. - Krisp: 4.4/5, Free / $8mo, best for Remote workers in noisy environments and on bad connections. - Notion AI: 4.3/5, $10mo add-on, best for Teams already living in Notion. ## Fireflies.ai alternatives - https://aestech.com.au/alternatives/fireflies/ Why switch: Accuracy varies with audio quality; Admin/privacy setup needs care. - NotebookLM: 4.6/5, Free / $20mo, best for Researchers and knowledge workers synthesising piles of documents. - Fathom: 4.5/5, Free / $19mo, best for Free, accurate meeting summaries. - Granola: 4.5/5, $18mo, best for People in back-to-back meetings who hate visible recording bots. - Gamma: 4.4/5, Free / $10mo, best for Anyone who needs good-looking presentations fast. - Krisp: 4.4/5, Free / $8mo, best for Remote workers in noisy environments and on bad connections. ## Krisp alternatives - https://aestech.com.au/alternatives/krisp/ Why switch: Core value is the audio cleanup; Notes features trail dedicated tools. - NotebookLM: 4.6/5, Free / $20mo, best for Researchers and knowledge workers synthesising piles of documents. - Fathom: 4.5/5, Free / $19mo, best for Free, accurate meeting summaries. - Granola: 4.5/5, $18mo, best for People in back-to-back meetings who hate visible recording bots. - Gamma: 4.4/5, Free / $10mo, best for Anyone who needs good-looking presentations fast. - Notion AI: 4.3/5, $10mo add-on, best for Teams already living in Notion. ## VEED alternatives - https://aestech.com.au/alternatives/veed/ Why switch: Exports and features gated by plan; Not a pro NLE replacement. - Descript: 4.5/5, Free / $24mo, best for Podcasters and creators editing by text. - Runway: 4.4/5, Free / $15mo, best for Filmmakers and motion creators. - Synthesia: 4.3/5, $18mo, best for Corporate training, explainers, and L&D. - HeyGen: 4.3/5, Free / $24mo, best for Marketing video and video translation. - Kling AI: 4.3/5, Free / $10mo, best for Realistic motion and longer clips. ## TrustCloud alternatives - https://aestech.com.au/alternatives/trustcloud/ Why switch: Smaller integration library than Vanta/Drata; Paid scaling still quote-based. - Vanta: 4.6/5, Custom quote, best for Startups and scale-ups automating ISO 27001, SOC 2, and PCI DSS. - Drata: 4.6/5, Custom quote, best for Teams wanting continuous control monitoring across many frameworks. - Secureframe: 4.5/5, Custom quote, best for First-time compliance teams who want more guidance. - Sprinto: 4.4/5, Custom quote, best for Cloud-native SMBs wanting quick time-to-audit. - Scrut Automation: 4.4/5, Custom, best for Startups wanting broad framework coverage without enterprise pricing. ## Strike Graph alternatives - https://aestech.com.au/alternatives/strike-graph/ Why switch: Quote-based pricing; Less brand recognition than leaders. - Vanta: 4.6/5, Custom quote, best for Startups and scale-ups automating ISO 27001, SOC 2, and PCI DSS. - Drata: 4.6/5, Custom quote, best for Teams wanting continuous control monitoring across many frameworks. - Secureframe: 4.5/5, Custom quote, best for First-time compliance teams who want more guidance. - Sprinto: 4.4/5, Custom quote, best for Cloud-native SMBs wanting quick time-to-audit. - Scrut Automation: 4.4/5, Custom, best for Startups wanting broad framework coverage without enterprise pricing. ## AuditBoard alternatives - https://aestech.com.au/alternatives/auditboard/ Why switch: Enterprise-only fit and pricing; Heavy for a first SOC 2. - Vanta: 4.6/5, Custom quote, best for Startups and scale-ups automating ISO 27001, SOC 2, and PCI DSS. - Drata: 4.6/5, Custom quote, best for Teams wanting continuous control monitoring across many frameworks. - Secureframe: 4.5/5, Custom quote, best for First-time compliance teams who want more guidance. - Sprinto: 4.4/5, Custom quote, best for Cloud-native SMBs wanting quick time-to-audit. - Scrut Automation: 4.4/5, Custom, best for Startups wanting broad framework coverage without enterprise pricing. ## Continue alternatives - https://aestech.com.au/alternatives/continue/ Why switch: More setup than turnkey tools; Polish depends on your config. - Cursor: 4.7/5, Free / $20mo, best for Developers who want agentic, multi-file AI editing. - GitHub Copilot: 4.5/5, $10mo, best for Developers who want autocomplete-style help in any editor. - Framer: 4.5/5, Free / $10mo, best for Designers and startups shipping polished marketing sites fast. - Windsurf: 4.4/5, Free / $15mo, best for Developers wanting agentic editing without the cost. - Aider: 4.4/5, Free (your API key), best for Terminal-first devs who want control. ## Augment Code alternatives - https://aestech.com.au/alternatives/augment-code/ Why switch: Newer entrant; Best value at team scale. - Cursor: 4.7/5, Free / $20mo, best for Developers who want agentic, multi-file AI editing. - GitHub Copilot: 4.5/5, $10mo, best for Developers who want autocomplete-style help in any editor. - Framer: 4.5/5, Free / $10mo, best for Designers and startups shipping polished marketing sites fast. - Windsurf: 4.4/5, Free / $15mo, best for Developers wanting agentic editing without the cost. - Aider: 4.4/5, Free (your API key), best for Terminal-first devs who want control. ## Frase alternatives - https://aestech.com.au/alternatives/frase/ Why switch: AI writing weaker than dedicated generators; Add-on pricing for AI words. - Clearscope: 4.4/5, $170mo, best for Content teams that treat SEO as a core channel. - Semrush: 4.4/5, $139mo, best for Marketing teams that want one platform for SEO, ads, and content. - Surfer SEO: 4.3/5, $59mo, best for Content teams optimising for search. - Opus Clip: 4.2/5, Free / $9mo, best for Repurposing long video into shorts/reels. - Buffer AI Assistant: 4.1/5, Free / $6mo, best for Small teams managing social channels. ## Clearscope alternatives - https://aestech.com.au/alternatives/clearscope/ Why switch: Expensive for small sites; Optimisation only, not generation. - Semrush: 4.4/5, $139mo, best for Marketing teams that want one platform for SEO, ads, and content. - Surfer SEO: 4.3/5, $59mo, best for Content teams optimising for search. - Opus Clip: 4.2/5, Free / $9mo, best for Repurposing long video into shorts/reels. - Buffer AI Assistant: 4.1/5, Free / $6mo, best for Small teams managing social channels. - Frase: 4.1/5, $15mo, best for SEO writers building optimised briefs and first drafts. ## WellSaid Labs alternatives - https://aestech.com.au/alternatives/wellsaid/ Why switch: Pricier entry than rivals; No free tier. - ElevenLabs: 4.7/5, Free / $5mo, best for Voiceover, audiobooks, and voice cloning. - Suno: 4.4/5, Free / $8mo, best for Music creation and jingles. - Udio: 4.3/5, Free / $10mo, best for AI music with strong audio quality. - Murf: 4.1/5, Free / $19mo, best for Corporate voiceover and e-learning. - Play.ht: 4.1/5, Free / $19mo, best for Developers adding voice via API. ## Stability AI (DreamStudio) alternatives - https://aestech.com.au/alternatives/stability-ai/ Why switch: Less turnkey than Midjourney; Quality needs prompt/work. - Midjourney: 4.6/5, $10mo, best for Designers wanting the best visual quality. - Adobe Firefly: 4.3/5, Free / $5mo, best for Designers needing commercial-safe assets. - Ideogram: 4.3/5, Free / $8mo, best for Logos, posters, and images with legible text. - Recraft: 4.3/5, Free / $12mo, best for Designers needing vectors and brand consistency. - Flux (Black Forest Labs): 4.3/5, API / credits, best for Developers and power users who want top-tier open image models. ## Poe alternatives - https://aestech.com.au/alternatives/poe/ Why switch: Not the cheapest for heavy single-model use; Limits vary by model. - Perplexity: 4.5/5, Free / $20mo, best for Research and fact-finding with citations. - Gemini: 4.4/5, Free / $20mo, best for Google Workspace users and huge-context tasks. - DeepSeek: 4.2/5, Free / low-cost API, best for Cost-conscious power users and developers. - Microsoft Copilot: 4.1/5, Free / $20mo, best for Microsoft 365 and Windows users. - Mistral (Le Chat): 4.1/5, Free / $15mo, best for Users who want a capable, EU-based assistant and open models. ## Apptega alternatives - https://aestech.com.au/alternatives/apptega/ Why switch: Quote-based pricing; Less automation than Vanta/Drata. - Vanta: 4.6/5, Custom quote, best for Startups and scale-ups automating ISO 27001, SOC 2, and PCI DSS. - Drata: 4.6/5, Custom quote, best for Teams wanting continuous control monitoring across many frameworks. - Secureframe: 4.5/5, Custom quote, best for First-time compliance teams who want more guidance. - Sprinto: 4.4/5, Custom quote, best for Cloud-native SMBs wanting quick time-to-audit. - Scrut Automation: 4.4/5, Custom, best for Startups wanting broad framework coverage without enterprise pricing. ## Onspring alternatives - https://aestech.com.au/alternatives/onspring/ Why switch: Setup effort to tailor it; Enterprise pricing. - Vanta: 4.6/5, Custom quote, best for Startups and scale-ups automating ISO 27001, SOC 2, and PCI DSS. - Drata: 4.6/5, Custom quote, best for Teams wanting continuous control monitoring across many frameworks. - Secureframe: 4.5/5, Custom quote, best for First-time compliance teams who want more guidance. - Sprinto: 4.4/5, Custom quote, best for Cloud-native SMBs wanting quick time-to-audit. - Scrut Automation: 4.4/5, Custom, best for Startups wanting broad framework coverage without enterprise pricing. ## Cypago alternatives - https://aestech.com.au/alternatives/cypago/ Why switch: Newer brand; Quote-based pricing. - Vanta: 4.6/5, Custom quote, best for Startups and scale-ups automating ISO 27001, SOC 2, and PCI DSS. - Drata: 4.6/5, Custom quote, best for Teams wanting continuous control monitoring across many frameworks. - Secureframe: 4.5/5, Custom quote, best for First-time compliance teams who want more guidance. - Sprinto: 4.4/5, Custom quote, best for Cloud-native SMBs wanting quick time-to-audit. - Scrut Automation: 4.4/5, Custom, best for Startups wanting broad framework coverage without enterprise pricing. ## Bolt alternatives - https://aestech.com.au/alternatives/bolt/ Why switch: Token usage adds up quickly; Complex apps still need real engineering. - Cursor: 4.7/5, Free / $20mo, best for Developers who want agentic, multi-file AI editing. - GitHub Copilot: 4.5/5, $10mo, best for Developers who want autocomplete-style help in any editor. - Framer: 4.5/5, Free / $10mo, best for Designers and startups shipping polished marketing sites fast. - Windsurf: 4.4/5, Free / $15mo, best for Developers wanting agentic editing without the cost. - Aider: 4.4/5, Free (your API key), best for Terminal-first devs who want control. ## v0 alternatives - https://aestech.com.au/alternatives/v0/ Why switch: Best within the React/Vercel stack; Credit-based limits. - Cursor: 4.7/5, Free / $20mo, best for Developers who want agentic, multi-file AI editing. - GitHub Copilot: 4.5/5, $10mo, best for Developers who want autocomplete-style help in any editor. - Framer: 4.5/5, Free / $10mo, best for Designers and startups shipping polished marketing sites fast. - Windsurf: 4.4/5, Free / $15mo, best for Developers wanting agentic editing without the cost. - Aider: 4.4/5, Free (your API key), best for Terminal-first devs who want control. ## Lovable alternatives - https://aestech.com.au/alternatives/lovable/ Why switch: Less control than hand-coding; Credit limits on heavy use. - Cursor: 4.7/5, Free / $20mo, best for Developers who want agentic, multi-file AI editing. - GitHub Copilot: 4.5/5, $10mo, best for Developers who want autocomplete-style help in any editor. - Framer: 4.5/5, Free / $10mo, best for Designers and startups shipping polished marketing sites fast. - Windsurf: 4.4/5, Free / $15mo, best for Developers wanting agentic editing without the cost. - Aider: 4.4/5, Free (your API key), best for Terminal-first devs who want control. ## Anyword alternatives - https://aestech.com.au/alternatives/anyword/ Why switch: Pricey for casual users; No real free tier. - Claude: 4.8/5, Free / $20mo, best for Long-form writing, analysis, and careful reasoning. - ChatGPT: 4.7/5, Free / $20mo, best for All-round writing, brainstorming, and everyday tasks. - Grammarly: 4.4/5, Free / $12mo, best for Real-time grammar, tone, and clarity everywhere. - Sudowrite: 4.3/5, $19mo, best for Novelists and fiction writers. - Writer: 4.3/5, Custom, best for Enterprises deploying AI writing with governance and brand rules. ## Writer alternatives - https://aestech.com.au/alternatives/writer/ Why switch: Enterprise-only fit and pricing; Too heavy for individuals. - Claude: 4.8/5, Free / $20mo, best for Long-form writing, analysis, and careful reasoning. - ChatGPT: 4.7/5, Free / $20mo, best for All-round writing, brainstorming, and everyday tasks. - Grammarly: 4.4/5, Free / $12mo, best for Real-time grammar, tone, and clarity everywhere. - Sudowrite: 4.3/5, $19mo, best for Novelists and fiction writers. - Jasper: 4.2/5, $39mo, best for Marketing teams producing on-brand content at volume. ## Semrush alternatives - https://aestech.com.au/alternatives/semrush/ Why switch: Expensive; Steep learning curve. - Clearscope: 4.4/5, $170mo, best for Content teams that treat SEO as a core channel. - Surfer SEO: 4.3/5, $59mo, best for Content teams optimising for search. - Opus Clip: 4.2/5, Free / $9mo, best for Repurposing long video into shorts/reels. - Buffer AI Assistant: 4.1/5, Free / $6mo, best for Small teams managing social channels. - Frase: 4.1/5, $15mo, best for SEO writers building optimised briefs and first drafts. ## ClickUp AI (Brain) alternatives - https://aestech.com.au/alternatives/clickup-ai/ Why switch: Can feel feature-heavy; AI is a paid add-on. - NotebookLM: 4.6/5, Free / $20mo, best for Researchers and knowledge workers synthesising piles of documents. - Fathom: 4.5/5, Free / $19mo, best for Free, accurate meeting summaries. - Granola: 4.5/5, $18mo, best for People in back-to-back meetings who hate visible recording bots. - Gamma: 4.4/5, Free / $10mo, best for Anyone who needs good-looking presentations fast. - Krisp: 4.4/5, Free / $8mo, best for Remote workers in noisy environments and on bad connections. ## Reclaim.ai alternatives - https://aestech.com.au/alternatives/reclaim/ Why switch: Best value tied to Google Calendar; Takes trust to hand over scheduling. - NotebookLM: 4.6/5, Free / $20mo, best for Researchers and knowledge workers synthesising piles of documents. - Fathom: 4.5/5, Free / $19mo, best for Free, accurate meeting summaries. - Granola: 4.5/5, $18mo, best for People in back-to-back meetings who hate visible recording bots. - Gamma: 4.4/5, Free / $10mo, best for Anyone who needs good-looking presentations fast. - Krisp: 4.4/5, Free / $8mo, best for Remote workers in noisy environments and on bad connections. ## You.com alternatives - https://aestech.com.au/alternatives/you-com/ Why switch: Less polished than Perplexity for some; Best features are paid. - Perplexity: 4.5/5, Free / $20mo, best for Research and fact-finding with citations. - Gemini: 4.4/5, Free / $20mo, best for Google Workspace users and huge-context tasks. - DeepSeek: 4.2/5, Free / low-cost API, best for Cost-conscious power users and developers. - Microsoft Copilot: 4.1/5, Free / $20mo, best for Microsoft 365 and Windows users. - Poe: 4.1/5, Free / $20mo, best for People who want to compare and switch between models in one place. ## SafeBase alternatives - https://aestech.com.au/alternatives/safebase/ Why switch: Quote-based pricing; Complements, not replaces, a GRC tool. - Vanta: 4.6/5, Custom quote, best for Startups and scale-ups automating ISO 27001, SOC 2, and PCI DSS. - Drata: 4.6/5, Custom quote, best for Teams wanting continuous control monitoring across many frameworks. - Secureframe: 4.5/5, Custom quote, best for First-time compliance teams who want more guidance. - Sprinto: 4.4/5, Custom quote, best for Cloud-native SMBs wanting quick time-to-audit. - Scrut Automation: 4.4/5, Custom, best for Startups wanting broad framework coverage without enterprise pricing. ## Conveyor alternatives - https://aestech.com.au/alternatives/conveyor/ Why switch: Quote-based pricing; Value scales with questionnaire volume. - Vanta: 4.6/5, Custom quote, best for Startups and scale-ups automating ISO 27001, SOC 2, and PCI DSS. - Drata: 4.6/5, Custom quote, best for Teams wanting continuous control monitoring across many frameworks. - Secureframe: 4.5/5, Custom quote, best for First-time compliance teams who want more guidance. - Sprinto: 4.4/5, Custom quote, best for Cloud-native SMBs wanting quick time-to-audit. - Scrut Automation: 4.4/5, Custom, best for Startups wanting broad framework coverage without enterprise pricing. ## Devin alternatives - https://aestech.com.au/alternatives/devin/ Why switch: Needs careful task scoping & review; Costlier than assistants. - Cursor: 4.7/5, Free / $20mo, best for Developers who want agentic, multi-file AI editing. - GitHub Copilot: 4.5/5, $10mo, best for Developers who want autocomplete-style help in any editor. - Framer: 4.5/5, Free / $10mo, best for Designers and startups shipping polished marketing sites fast. - Windsurf: 4.4/5, Free / $15mo, best for Developers wanting agentic editing without the cost. - Aider: 4.4/5, Free (your API key), best for Terminal-first devs who want control. ## Zed alternatives - https://aestech.com.au/alternatives/zed/ Why switch: Younger ecosystem than VS Code; AI features still maturing. - Cursor: 4.7/5, Free / $20mo, best for Developers who want agentic, multi-file AI editing. - GitHub Copilot: 4.5/5, $10mo, best for Developers who want autocomplete-style help in any editor. - Framer: 4.5/5, Free / $10mo, best for Designers and startups shipping polished marketing sites fast. - Windsurf: 4.4/5, Free / $15mo, best for Developers wanting agentic editing without the cost. - Aider: 4.4/5, Free (your API key), best for Terminal-first devs who want control. ## Writesonic alternatives - https://aestech.com.au/alternatives/writesonic/ Why switch: Quality varies on long-form; Credit/word limits. - Claude: 4.8/5, Free / $20mo, best for Long-form writing, analysis, and careful reasoning. - ChatGPT: 4.7/5, Free / $20mo, best for All-round writing, brainstorming, and everyday tasks. - Grammarly: 4.4/5, Free / $12mo, best for Real-time grammar, tone, and clarity everywhere. - Sudowrite: 4.3/5, $19mo, best for Novelists and fiction writers. - Writer: 4.3/5, Custom, best for Enterprises deploying AI writing with governance and brand rules. ## Hypotenuse AI alternatives - https://aestech.com.au/alternatives/hypotenuse/ Why switch: Niche focus; No meaningful free tier. - Claude: 4.8/5, Free / $20mo, best for Long-form writing, analysis, and careful reasoning. - ChatGPT: 4.7/5, Free / $20mo, best for All-round writing, brainstorming, and everyday tasks. - Grammarly: 4.4/5, Free / $12mo, best for Real-time grammar, tone, and clarity everywhere. - Sudowrite: 4.3/5, $19mo, best for Novelists and fiction writers. - Writer: 4.3/5, Custom, best for Enterprises deploying AI writing with governance and brand rules. ## Flux (Black Forest Labs) alternatives - https://aestech.com.au/alternatives/flux/ Why switch: Less turnkey than consumer apps; Best via API/third-party UIs. - Midjourney: 4.6/5, $10mo, best for Designers wanting the best visual quality. - Adobe Firefly: 4.3/5, Free / $5mo, best for Designers needing commercial-safe assets. - Ideogram: 4.3/5, Free / $8mo, best for Logos, posters, and images with legible text. - Recraft: 4.3/5, Free / $12mo, best for Designers needing vectors and brand consistency. - Leonardo AI: 4.2/5, Free / $12mo, best for Game artists and control-focused creators. ## Freepik AI alternatives - https://aestech.com.au/alternatives/freepik-ai/ Why switch: Jack-of-all-trades vs specialists; Credit limits on AI. - Midjourney: 4.6/5, $10mo, best for Designers wanting the best visual quality. - Adobe Firefly: 4.3/5, Free / $5mo, best for Designers needing commercial-safe assets. - Ideogram: 4.3/5, Free / $8mo, best for Logos, posters, and images with legible text. - Recraft: 4.3/5, Free / $12mo, best for Designers needing vectors and brand consistency. - Flux (Black Forest Labs): 4.3/5, API / credits, best for Developers and power users who want top-tier open image models. ## Captions alternatives - https://aestech.com.au/alternatives/captions/ Why switch: Best for talking-head formats; Higher tiers for full features. - Descript: 4.5/5, Free / $24mo, best for Podcasters and creators editing by text. - Runway: 4.4/5, Free / $15mo, best for Filmmakers and motion creators. - Synthesia: 4.3/5, $18mo, best for Corporate training, explainers, and L&D. - HeyGen: 4.3/5, Free / $24mo, best for Marketing video and video translation. - Kling AI: 4.3/5, Free / $10mo, best for Realistic motion and longer clips. ## Pictory alternatives - https://aestech.com.au/alternatives/pictory/ Why switch: Templated look; No real free tier. - Descript: 4.5/5, Free / $24mo, best for Podcasters and creators editing by text. - Runway: 4.4/5, Free / $15mo, best for Filmmakers and motion creators. - Synthesia: 4.3/5, $18mo, best for Corporate training, explainers, and L&D. - HeyGen: 4.3/5, Free / $24mo, best for Marketing video and video translation. - Kling AI: 4.3/5, Free / $10mo, best for Realistic motion and longer clips. ## Mistral (Le Chat) alternatives - https://aestech.com.au/alternatives/mistral/ Why switch: Smaller ecosystem than ChatGPT; Fewer built-in tools. - Perplexity: 4.5/5, Free / $20mo, best for Research and fact-finding with citations. - Gemini: 4.4/5, Free / $20mo, best for Google Workspace users and huge-context tasks. - DeepSeek: 4.2/5, Free / low-cost API, best for Cost-conscious power users and developers. - Microsoft Copilot: 4.1/5, Free / $20mo, best for Microsoft 365 and Windows users. - Poe: 4.1/5, Free / $20mo, best for People who want to compare and switch between models in one place. ## Sunsama alternatives - https://aestech.com.au/alternatives/sunsama/ Why switch: Premium price, no free tier; Manual by design (less automation). - NotebookLM: 4.6/5, Free / $20mo, best for Researchers and knowledge workers synthesising piles of documents. - Fathom: 4.5/5, Free / $19mo, best for Free, accurate meeting summaries. - Granola: 4.5/5, $18mo, best for People in back-to-back meetings who hate visible recording bots. - Gamma: 4.4/5, Free / $10mo, best for Anyone who needs good-looking presentations fast. - Krisp: 4.4/5, Free / $8mo, best for Remote workers in noisy environments and on bad connections. ## Zapier alternatives - https://aestech.com.au/alternatives/zapier/ Why switch: Task-based pricing gets expensive at volume; Complex multi-step logic is clunkier than Make or n8n. - n8n: 4.5/5, Free self-hosted / $24mo, best for Technical teams building AI agent workflows they want to own. - Make: 4.3/5, Free / $9mo, best for Builders who want complex visual workflows without enterprise pricing. - Lindy: 4.1/5, Free / $50mo, best for Non-technical operators who want AI employees, not workflows. - Relevance AI: 4.1/5, Free / $19mo, best for Sales and ops teams building multi-agent AI workforces. ## Make alternatives - https://aestech.com.au/alternatives/make/ Why switch: Steeper learning curve than Zapier; Fewer integrations, and some connectors feel thinner. - n8n: 4.5/5, Free self-hosted / $24mo, best for Technical teams building AI agent workflows they want to own. - Zapier: 4.4/5, Free / $20mo, best for Teams that want the widest app coverage with zero code. - Lindy: 4.1/5, Free / $50mo, best for Non-technical operators who want AI employees, not workflows. - Relevance AI: 4.1/5, Free / $19mo, best for Sales and ops teams building multi-agent AI workforces. ## n8n alternatives - https://aestech.com.au/alternatives/n8n/ Why switch: Non-technical users will struggle without help; Self-hosting means you own uptime and upgrades. - Zapier: 4.4/5, Free / $20mo, best for Teams that want the widest app coverage with zero code. - Make: 4.3/5, Free / $9mo, best for Builders who want complex visual workflows without enterprise pricing. - Lindy: 4.1/5, Free / $50mo, best for Non-technical operators who want AI employees, not workflows. - Relevance AI: 4.1/5, Free / $19mo, best for Sales and ops teams building multi-agent AI workforces. ## Lindy alternatives - https://aestech.com.au/alternatives/lindy/ Why switch: Credit-based pricing is hard to predict at scale; Less control and debuggability than n8n or Make. - n8n: 4.5/5, Free self-hosted / $24mo, best for Technical teams building AI agent workflows they want to own. - Zapier: 4.4/5, Free / $20mo, best for Teams that want the widest app coverage with zero code. - Make: 4.3/5, Free / $9mo, best for Builders who want complex visual workflows without enterprise pricing. - Relevance AI: 4.1/5, Free / $19mo, best for Sales and ops teams building multi-agent AI workforces. ## Relevance AI alternatives - https://aestech.com.au/alternatives/relevance-ai/ Why switch: The interface can overwhelm first-time builders; Credit consumption needs watching on heavier plans. - n8n: 4.5/5, Free self-hosted / $24mo, best for Technical teams building AI agent workflows they want to own. - Zapier: 4.4/5, Free / $20mo, best for Teams that want the widest app coverage with zero code. - Make: 4.3/5, Free / $9mo, best for Builders who want complex visual workflows without enterprise pricing. - Lindy: 4.1/5, Free / $50mo, best for Non-technical operators who want AI employees, not workflows. ## NotebookLM alternatives - https://aestech.com.au/alternatives/notebooklm/ Why switch: Confined to sources you upload, it is not a general assistant; Sharing and collaboration remain clumsy for team use. - Fathom: 4.5/5, Free / $19mo, best for Free, accurate meeting summaries. - Granola: 4.5/5, $18mo, best for People in back-to-back meetings who hate visible recording bots. - Gamma: 4.4/5, Free / $10mo, best for Anyone who needs good-looking presentations fast. - Krisp: 4.4/5, Free / $8mo, best for Remote workers in noisy environments and on bad connections. - Notion AI: 4.3/5, $10mo add-on, best for Teams already living in Notion. ## Granola alternatives - https://aestech.com.au/alternatives/granola/ Why switch: No unlimited free tier, only a trial; Mobile and Windows support arrived later and still trail the Mac app. - NotebookLM: 4.6/5, Free / $20mo, best for Researchers and knowledge workers synthesising piles of documents. - Fathom: 4.5/5, Free / $19mo, best for Free, accurate meeting summaries. - Gamma: 4.4/5, Free / $10mo, best for Anyone who needs good-looking presentations fast. - Krisp: 4.4/5, Free / $8mo, best for Remote workers in noisy environments and on bad connections. - Notion AI: 4.3/5, $10mo add-on, best for Teams already living in Notion. ## Glean alternatives - https://aestech.com.au/alternatives/glean/ Why switch: Enterprise-only pricing puts it out of reach for small teams; Value depends heavily on connector rollout and adoption. - NotebookLM: 4.6/5, Free / $20mo, best for Researchers and knowledge workers synthesising piles of documents. - Fathom: 4.5/5, Free / $19mo, best for Free, accurate meeting summaries. - Granola: 4.5/5, $18mo, best for People in back-to-back meetings who hate visible recording bots. - Gamma: 4.4/5, Free / $10mo, best for Anyone who needs good-looking presentations fast. - Krisp: 4.4/5, Free / $8mo, best for Remote workers in noisy environments and on bad connections. ## Framer alternatives - https://aestech.com.au/alternatives/framer/ Why switch: Not suited to web apps or complex logic; Costs climb once you add CMS scale and team seats. - Cursor: 4.7/5, Free / $20mo, best for Developers who want agentic, multi-file AI editing. - GitHub Copilot: 4.5/5, $10mo, best for Developers who want autocomplete-style help in any editor. - Windsurf: 4.4/5, Free / $15mo, best for Developers wanting agentic editing without the cost. - Aider: 4.4/5, Free (your API key), best for Terminal-first devs who want control. - Sourcegraph Cody: 4.3/5, Free / $9mo, best for Teams working in large, sprawling codebases. ## Durable alternatives - https://aestech.com.au/alternatives/durable/ Why switch: Sites look generic next to Framer or custom builds; Limited design control once you want something specific. - Cursor: 4.7/5, Free / $20mo, best for Developers who want agentic, multi-file AI editing. - GitHub Copilot: 4.5/5, $10mo, best for Developers who want autocomplete-style help in any editor. - Framer: 4.5/5, Free / $10mo, best for Designers and startups shipping polished marketing sites fast. - Windsurf: 4.4/5, Free / $15mo, best for Developers wanting agentic editing without the cost. - Aider: 4.4/5, Free (your API key), best for Terminal-first devs who want control. # Pricing guides ## ChatGPT Pricing: Free, Plus, Pro, Business, and Enterprise - https://aestech.com.au/pricing/chatgpt-pricing/ Tool: ChatGPT. Checked: 2026-06-18. Pricing model: Free plan, paid individual plans, business plans, usage-based Codex, and custom enterprise pricing. Verdict: Most buyers should start with Free or Plus, then move to Pro or Business only when advanced reasoning, Codex usage, admin controls, or team context are clearly needed. Best first move: Plus for regular individual use; Business ChatGPT and Codex when a team needs workspace controls and shared administration.. Watch out: Usage limits, model access, ads, memory, context, and business controls differ by plan. Confirm the current checkout price and limits before buying. - Free: $0. For light everyday use and testing. - Go: Check live price. For expanded access above Free. - Plus: Check live price. The default paid plan for most serious individual users. - Pro: From live checkout. For power users who need maximum individual usage. - Business and Enterprise: Business or custom pricing. For teams that need workspace administration or enterprise controls. ## Claude Pricing: Which Plan Should You Choose? - https://aestech.com.au/pricing/claude-pricing/ Tool: Claude. Checked: 2026-06-18. Pricing model: Free, per-user subscriptions, high-usage Max plans, and team seats. Verdict: Most individual buyers should start with Pro, then move to Max only when usage limits block real work every week. Best first move: Pro for serious solo use; Team standard seats for small business rollout.. Watch out: Usage limits still apply, and taxes may be added. Max is powerful but easy to overbuy if Claude is not already central to your workflow. - Free: $0. Best for light testing and occasional chats. - Pro: $17/mo annual or $20/mo monthly. The default paid plan for regular individual use. - Max: From $100/mo. For users who hit Pro limits often. - Team: $20/mo per seat annual or $25/mo monthly. For teams of 5 to 150 seats. ## Jasper Pricing: Pro vs Business - https://aestech.com.au/pricing/jasper-pricing/ Tool: Jasper. Checked: 2026-06-18. Pricing model: Per-seat Pro plan plus custom Business pricing. Verdict: Jasper makes sense when brand governance and repeatable marketing workflows matter more than the cheapest possible writing assistant. Best first move: Pro for a small marketing team; Business when you need advanced agents, governance, API access, and account support.. Watch out: Solo users may get better value from a general assistant unless Jasper brand controls are used every week. - Pro: $69/mo per seat. Self-serve plan for governed marketing content. - Business: Custom pricing. For larger teams with governance and scale requirements. ## Cursor Pricing: Hobby, Pro, Teams, and Enterprise - https://aestech.com.au/pricing/cursor-pricing/ Tool: Cursor. Checked: 2026-06-18. Pricing model: Free Hobby plan, $20/mo individual Pro, $40/user/mo Teams, and custom Enterprise. Verdict: Cursor Pro is the obvious first paid step for individual developers, while Teams is the cleaner choice once billing, shared context, SSO, and privacy controls matter. Best first move: Pro for solo developers; Teams for engineering groups collaborating in Cursor.. Watch out: Every plan includes some model usage, and on-demand usage can bill in arrears after included usage is consumed. Enterprise is the safer path for invoicing, pooled usage, SCIM, audit logs, and access controls. - Hobby: Free. For trying Cursor without a card. - Individual Pro: $20/mo. For individual developers using Cursor regularly. - Teams: $40/user/mo. For professional teams collaborating in Cursor. - Enterprise: Custom pricing. For larger organisations with governance and procurement needs. ## GitHub Copilot Pricing: Free, Pro, Pro+, Max, Business, and Enterprise - https://aestech.com.au/pricing/github-copilot-pricing/ Tool: GitHub Copilot. Checked: 2026-06-18. Pricing model: Free individual tier, paid individual plans, AI credit add-ons, Business, and Enterprise. Verdict: Copilot is the low-friction choice when developers already live in GitHub and want AI assistance across IDEs, CLI, GitHub, and mobile. Best first move: Free for occasional coding help; Pro for regular individual developers; Business or Enterprise for managed company rollout.. Watch out: Heavy agent usage depends on AI credits, budgets, and admin limits. Organisation plans add policy management, license management, and stronger controls that individual plans do not provide. - Free: $0. Limited individual access. - Pro: Paid individual plan. For regular individual developers. - Pro+ and Max: Higher-usage individual plans. For heavier agent-driven workflows. - Business: Organisation pricing. For teams that need managed access. - Enterprise: Enterprise pricing. For companies needing deeper GitHub.com and organisation knowledge integration. ## Surfer SEO Pricing: Discovery, Standard, Pro, Peace of Mind, and Enterprise - https://aestech.com.au/pricing/surfer-seo-pricing/ Tool: Surfer SEO. Checked: 2026-06-18. Pricing model: Annual plans from $49/mo to $999/mo, with Standard, Pro, Peace of Mind, and Enterprise tiers. Verdict: Surfer is worth paying for when content teams have a repeatable publishing calendar and need structured SEO or AI-search optimisation, not just occasional keyword checks. Best first move: Discovery for testing; Standard for a focused team; Pro when AI visibility tracking and brand workspaces become important.. Watch out: Plan value depends on document limits, AI visibility tracking, brand workspaces, internal linking, API access, and support needs. Check whether annual billing fits your cash flow. - Discovery: $49/mo billed yearly. For starting small and proving the workflow. - Standard: $99/mo billed yearly. For teams building a steady content workflow. - Pro: $182/mo billed yearly. The recommended tier for teams that need more authority and AI visibility work. - Peace of Mind: $299/mo billed yearly. For higher-scale content operations. - Enterprise: $999/mo. For advisory-led strategy and enterprise controls. ## Vanta Pricing: What to Know Before You Book a Demo - https://aestech.com.au/pricing/vanta-pricing/ Tool: Vanta. Checked: 2026-06-18. Pricing model: Personalised quote by plan, framework scope, and company needs. Verdict: Vanta is usually worth pricing when customer trust is blocking sales or a SOC 2, ISO 27001, or PCI DSS program is already planned. Best first move: Plus is the likely starting point for many SaaS teams because it adds questionnaire automation and access management over Essentials.. Watch out: Ask what is included versus add-on. Questionnaire automation, risk, Trust Center depth, and extra frameworks can change the quote materially. - Essentials: Personalised quote. Fastest path to one compliance framework. - Plus: Personalised quote. Compliance foundation plus early security trust workflows. - Professional: Personalised quote. For scaling compliance, risk, and reporting. - Enterprise: Personalised quote. For flexible, advanced trust programs. ## Secureframe Pricing: Fundamentals, Complete, and Defense - https://aestech.com.au/pricing/secureframe-pricing/ Tool: Secureframe. Checked: 2026-06-18. Pricing model: Quote-based packages. Verdict: Secureframe is best priced against Vanta and Drata when you want guided onboarding and a structured path through first-time compliance. Best first move: Fundamentals for a first certification; Complete when third-party risk, access reviews, and advanced questionnaire automation matter.. Watch out: Secureframe publishes package names and feature groups, not fixed prices. Confirm framework count, add-ons, and auditor support before comparing quotes. - Fundamentals: Get a quote. Built to get compliant fast. - Complete: Get a quote. For scaling compliance and trust operations. - Defense: Get a quote. For CMMC and defense contractor requirements. ## Sprinto Pricing: What Buyers Can Confirm Publicly - https://aestech.com.au/pricing/sprinto-pricing/ Tool: Sprinto. Checked: 2026-06-18. Pricing model: Sales-led quote after demo. Verdict: Sprinto is worth pricing when you are a cloud-native startup or SMB that wants fast compliance automation without enterprise overhead. Best first move: Use the demo to scope only the frameworks and trust workflows you need now, then compare the quote with Vanta, Drata, and Secureframe.. Watch out: Because public pricing is limited, insist on a written quote that separates platform, framework, onboarding, support, and renewal assumptions. - Compliance automation scope: Book a demo. For SOC 2, ISO 27001, PCI DSS, HIPAA, GDPR, and related programs. - Trust operations scope: Book a demo. For teams expanding beyond first certification. ## ElevenLabs Pricing: Free, Starter, Creator, Pro, Scale, and Business - https://aestech.com.au/pricing/elevenlabs-pricing/ Tool: ElevenLabs. Checked: 2026-06-29. Pricing model: Free tier plus credit-based monthly subscriptions; higher tiers add commercial use, professional voice cloning, and more concurrency. Verdict: Hobbyists start Free or Starter; creators publishing commercially want Creator; teams and apps move to Pro and up for volume, cloning, and API headroom. Best first move: Creator for most serious individual creators; Pro and above when you need higher quotas, professional voice cloning at scale, or API throughput.. Watch out: Plans are metered by credits/characters and can be consumed fast at high quality. Commercial rights and professional voice cloning are gated to paid tiers. Confirm the current quota and price at checkout. - Free: $0. Try it out, with attribution. - Starter: $5/mo. Low-cost entry with commercial use. - Creator: $22/mo. For regular commercial creators. - Pro: $99/mo. For heavy creators and small teams. - Scale: $330/mo. For teams scaling output. - Business: $1,320/mo. For high-volume production. ## Drata Pricing: How Quote-Based Compliance Automation Is Priced - https://aestech.com.au/pricing/drata-pricing/ Tool: Drata. Checked: 2026-06-29. Pricing model: Custom annual contracts. Drivers: number and type of frameworks (SOC 2, ISO 27001, etc.), headcount/scope, and optional modules. Verdict: Expect an annual platform fee that scales with frameworks and company size; get competing quotes from Vanta and Secureframe to anchor the number. Best first move: A single-framework (e.g. SOC 2) starter scope for your first audit, then expand frameworks as you grow, each one typically adds to the contract.. Watch out: No public pricing means the quote is negotiable. Multi-year deals and added frameworks change the figure materially. Always benchmark against at least one competitor quote. - Core platform: Custom. Annual contract, scoped to your first framework. - Additional frameworks: Custom add-on. Each extra framework typically increases the contract. - Add-on modules: Custom add-on. Optional capabilities. ## Synthesia Pricing: Free, Starter, Creator, and Enterprise - https://aestech.com.au/pricing/synthesia-pricing/ Tool: Synthesia. Checked: 2026-06-29. Pricing model: Free trial allowance plus paid tiers metered by video minutes; enterprise adds seats, brand controls, and custom avatars. Verdict: Individuals and small teams fit Starter or Creator by minutes needed; orgs wanting custom avatars, SSO, and many seats go Enterprise. Best first move: Creator for regular individual production; Enterprise once you need multiple seats, brand kit/governance, or personal avatars.. Watch out: Plans are capped by video minutes per year/month and avatar access differs by tier. Custom/personal avatars and team controls are typically enterprise features. Confirm current minute limits at checkout. - Free: $0. Trial allowance to evaluate. - Starter: from ~$18/mo. Entry tier for light use. - Creator: from ~$64/mo. For regular content creators. - Enterprise: Custom. For teams and brand governance. ## Descript Pricing: Free, Hobbyist, Creator, and Business - https://aestech.com.au/pricing/descript-pricing/ Tool: Descript. Checked: 2026-06-29. Pricing model: Free tier plus per-seat monthly/annual plans; higher tiers add transcription hours, watermark-free/higher-res export, and advanced AI features. Verdict: Casual editors start Free or Hobbyist; regular podcasters and video creators want Creator; teams needing more seats and controls go Business. Best first move: Creator for most serious individual creators; Business when you need multiple seats and admin controls.. Watch out: Transcription hours, export quality, and AI features (e.g. Overdub) differ by tier, and annual billing is cheaper than monthly. Confirm current limits and price at checkout. - Free: $0. Try the workflow. - Hobbyist: from ~$16/mo. Light personal use. - Creator: from ~$24/mo. For regular creators. - Business: from ~$40/mo. For teams. ## Murf Pricing: Free, Creator, Business, and Enterprise - https://aestech.com.au/pricing/murf-pricing/ Tool: Murf. Checked: 2026-06-29. Pricing model: Free tier plus per-seat plans metered by voice-generation hours; higher tiers add commercial use, more voices, and team features. Verdict: Try Free, then Creator for individual commercial voiceover; Business for teams and more hours; Enterprise for scale and controls. Best first move: Creator for solo creators needing commercial rights; Business once you have multiple users or higher volume.. Watch out: Plans are capped by generation hours and voice/feature access varies by tier. Annual billing is cheaper. Confirm current hours and price at checkout. - Free: $0. Evaluate with limits. - Creator: from ~$19/mo. For individual creators. - Business: from ~$66/mo. For teams. - Enterprise: Custom. For scale and governance. ## HeyGen Pricing: Free, Creator, Team, and Enterprise - https://aestech.com.au/pricing/heygen-pricing/ Tool: HeyGen. Checked: 2026-06-29. Pricing model: Free tier plus per-seat plans metered by video credits/minutes; higher tiers add HD export, more avatars, and team seats. Verdict: Test on Free, then Creator for individual avatar video; Team for collaboration and more minutes; Enterprise for scale and brand controls. Best first move: Creator for most individual creators; Team once you need shared seats and higher volume.. Watch out: Plans are capped by credits/minutes; watermark and export quality differ by tier, and custom avatars may need higher plans. Confirm current limits at checkout. - Free: $0. Evaluate with watermark/limits. - Creator: from ~$24/mo. For individual creators. - Team: from ~$69/mo per seat. For collaborating teams. - Enterprise: Custom. For scale and governance. ## OpusClip Pricing: Free, Starter, and Pro - https://aestech.com.au/pricing/opusclip-pricing/ Tool: Opus Clip. Checked: 2026-06-29. Pricing model: Free tier plus paid plans metered by processing minutes; paid tiers remove the watermark and raise limits. Verdict: Try Free, then Starter for light repurposing, Pro for regular short-form output and watermark-free, higher-volume clipping. Best first move: Pro for creators consistently turning long videos into shorts; Starter for occasional use.. Watch out: Plans are capped by processing minutes and the free tier watermarks output. Annual billing is cheaper. Confirm current minute limits at checkout. - Free: $0. Evaluate with watermark. - Starter: from ~$9/mo. Light repurposing. - Pro: from ~$19/mo. For regular short-form creators. ## Thoropass Pricing: How the Software-Plus-Audit Bundle Is Priced - https://aestech.com.au/pricing/thoropass-pricing/ Tool: Thoropass. Checked: 2026-06-29. Pricing model: Custom quotes that often combine platform plus audit. Drivers: frameworks (SOC 2, ISO 27001, etc.), company size/scope, and audit type. Verdict: Expect a bundled annual figure covering software and audit; compare it against platform-only quotes (Vanta/Drata) plus a separate auditor fee. Best first move: A single-framework bundle (e.g. SOC 2 Type I or II) for your first cycle, then expand frameworks as you grow.. Watch out: Because the audit may be bundled, compare like-for-like: platform-only competitors quote software, with the auditor billed separately. Always benchmark the all-in cost. - Software + audit bundle: Custom. Annual, scoped to your frameworks. - Additional frameworks: Custom add-on. Each framework adds to the contract. ## Midjourney Pricing: Basic, Standard, Pro, and Mega - https://aestech.com.au/pricing/midjourney-pricing/ Tool: Midjourney. Checked: 2026-06-29. Pricing model: Subscription tiers metered by fast-GPU hours; higher tiers add unlimited relaxed generation, more concurrency, and stealth mode. Verdict: Hobbyists pick Basic; regular creators want Standard for unlimited relax time; heavy or private users go Pro or Mega. Best first move: Standard for most regular users (unlimited relaxed generations); Pro/Mega for heavy volume or stealth (private) generation.. Watch out: Fast-GPU hours are the real meter, run out and you wait in relax mode or buy more. Stealth/private images require Pro or above. Confirm current hours and price at checkout. - Basic: $10/mo. Entry tier. - Standard: $30/mo. Best for regular creators. - Pro: $60/mo. Heavy use + privacy. - Mega: $120/mo. Highest volume. ## Perplexity Pricing: Free, Pro, and Enterprise - https://aestech.com.au/pricing/perplexity-pricing/ Tool: Perplexity. Checked: 2026-06-29. Pricing model: Free tier plus flat-rate Pro subscription; Enterprise is custom with admin and security controls. Verdict: The free tier suits casual search; Pro is the pick for daily research with more Pro searches, model choice, and file uploads. Best first move: Pro for regular researchers and knowledge workers; Enterprise when you need team controls and security.. Watch out: The main gates are daily Pro-search limits and model access. Confirm the current Pro price and limits at checkout, and whether annual billing is discounted. - Free: $0. Capable everyday search. - Pro: $20/mo. For daily research. - Enterprise: Custom. For teams. ## Runway Pricing: Free, Standard, Pro, and Unlimited - https://aestech.com.au/pricing/runway-pricing/ Tool: Runway. Checked: 2026-06-29. Pricing model: Free trial credits plus per-seat plans metered by credits; upper tiers add more credits, higher resolution, and unlimited relaxed generation. Verdict: Test on Free, then Standard for regular creators, Pro for heavier output, Unlimited for high-volume production without credit anxiety. Best first move: Standard for most individual creators; Pro/Unlimited once credit limits start constraining your output.. Watch out: Credits are consumed per generation and burn fast at high resolution/length. Unlimited mode is relaxed-speed. Confirm current credit allotments at checkout. - Free: $0. Trial credits to evaluate. - Standard: from ~$15/mo. For regular creators. - Pro: from ~$35/mo. For heavier output. - Unlimited: from ~$95/mo. High-volume production. ## Leonardo.Ai Pricing: Free, Apprentice, Artisan, and Maestro - https://aestech.com.au/pricing/leonardo-ai-pricing/ Tool: Leonardo AI. Checked: 2026-06-29. Pricing model: Free daily tokens plus monthly paid plans with larger token pools, faster generation, and added features. Verdict: Free daily tokens suit hobbyists; Apprentice and Artisan fit regular creators; Maestro is for high-volume and team use. Best first move: Artisan for serious individual creators; Apprentice for lighter use; Maestro for heavy/team output.. Watch out: Tokens are the meter and reset by plan; higher resolution and upscales cost more tokens. Confirm current token amounts and price at checkout. - Free: $0. Daily token allowance. - Apprentice: from ~$12/mo. For light creators. - Artisan: from ~$30/mo. For regular creators. - Maestro: from ~$60/mo. High volume / teams. ## Notion AI Pricing: How It’s Billed Across Notion’s Plans - https://aestech.com.au/pricing/notion-ai-pricing/ Tool: Notion AI. Checked: 2026-06-29. Pricing model: AI is included with higher Notion plans (Business/Enterprise) and sold as a per-member add-on on Free/Plus. Billed per seat alongside Notion itself. Verdict: If you already pay for Notion Business, AI is included; on Free/Plus, weigh the per-member AI add-on against upgrading the base plan. Best first move: Business if your team wants Notion plus AI together; the AI add-on on Plus if only a few members need AI.. Watch out: AI bundling has changed over time, confirm whether AI is included in your plan or an add-on, and the current per-member price, at checkout. - Free: $0 (+AI add-on). Personal use. - Plus: from ~$10/seat/mo (+AI add-on). Small teams. - Business: from ~$20/seat/mo. AI typically included. - Enterprise: Custom. Org-wide. ## Google Gemini Pricing: Free, Google AI Pro, and AI Ultra - https://aestech.com.au/pricing/gemini-pricing/ Tool: Gemini. Checked: 2026-06-29. Pricing model: Free tier plus consumer subscriptions (Google AI Pro, AI Ultra); Workspace customers access Gemini through business plans. Verdict: The free app suits most; Google AI Pro is the upgrade for advanced models and higher limits, AI Ultra for power users and the largest allowances. Best first move: Google AI Pro for regular advanced use; AI Ultra for heavy users; Workspace plans for business deployment.. Watch out: Plan names and bundled storage/features have changed over time, and business access differs from consumer. Confirm the current plan, price, and model access at checkout. - Free: $0. Gemini app access. - Google AI Pro: from ~$20/mo. Advanced individual use. - Google AI Ultra: Premium tier. Power users. - Workspace: Business plans. For organisations. ## Microsoft Copilot Pricing: Free, Copilot Pro, and Microsoft 365 Copilot - https://aestech.com.au/pricing/microsoft-copilot-pricing/ Tool: Microsoft Copilot. Checked: 2026-06-29. Pricing model: Free tier; Copilot Pro for individuals; Microsoft 365 Copilot as a per-user/month add-on to eligible business 365 plans. Verdict: Casual users use Free; individuals wanting priority and Office integration take Copilot Pro; businesses add Microsoft 365 Copilot per user. Best first move: Copilot Pro for individuals in Microsoft apps; Microsoft 365 Copilot for organisations wanting Copilot across Word, Excel, Outlook, and Teams.. Watch out: Microsoft 365 Copilot requires eligible business 365 licensing and is billed per user on top of it. Confirm prerequisites and current price at checkout. - Free: $0. General Copilot. - Copilot Pro: from ~$20/mo. For individuals. - Microsoft 365 Copilot: from ~$30/user/mo. Business add-on. ## Adobe Firefly Pricing: Free, Standard, and Pro - https://aestech.com.au/pricing/adobe-firefly-pricing/ Tool: Adobe Firefly. Checked: 2026-06-29. Pricing model: Free monthly credits plus standalone Firefly plans metered by generative credits; also included (with credits) in Creative Cloud plans. Verdict: Try the free credits; Standard suits regular creators; Pro for higher volume, or just use the credits bundled with your Creative Cloud plan. Best first move: Standard for regular standalone use; if you already pay for Creative Cloud, use its included Firefly credits first.. Watch out: Generative credits are the meter and can run out mid-month; commercial-safe generation is the selling point. Confirm current credit amounts and price at checkout. - Free: $0. Limited monthly credits. - Firefly Standard: from ~$10/mo. Regular creators. - Firefly Pro: from ~$30/mo. Higher volume. ## Grammarly Pricing: Free, Pro, and Business - https://aestech.com.au/pricing/grammarly-pricing/ Tool: Grammarly. Checked: 2026-06-29. Pricing model: Free tier plus paid Pro (individual) and Business (per-seat) plans; higher tiers add advanced suggestions, generative AI, and team controls. Verdict: Free covers core correctness; Pro adds advanced rewriting and generative AI; Business adds seats, style guides, and admin. Best first move: Pro for individuals wanting advanced help and AI; Business for teams needing shared style and admin controls.. Watch out: Generative-AI prompt allowances and advanced features differ by tier, and Business is billed per seat (often with a minimum). Confirm current price at checkout. - Free: $0. Core writing help. - Pro: from ~$12/mo. For individuals. - Business: from ~$15/seat/mo. For teams. ## Zapier Pricing: Free, Pro, Team, and Enterprise - https://aestech.com.au/pricing/zapier-pricing/ Tool: Zapier. Checked: 2026-07-03. Pricing model: Free tier plus task-metered monthly subscriptions; Team adds shared workspaces and Enterprise adds governance on custom pricing. Verdict: Start Free to prove one or two automations, move to Pro when you need multi-step Zaps and premium apps, and only go Team when several people share automations and billing. Best first move: Pro for most individuals and small businesses; Team once shared folders, shared app connections, and central billing matter.. Watch out: Every action in a Zap consumes a task, so a busy multi-step Zap can burn through a monthly quota far faster than expected. Overage handling and task tiers change the effective price, so confirm the current task allowance at checkout. - Free: $0. For testing whether Zapier fits the workflow. - Pro: from ~$20/mo billed annually. The default paid plan for serious solo automation. - Team: from ~$69/mo billed annually. For groups sharing automations. - Enterprise: Custom pricing. For organisations that need governance. ## Make Pricing: Free, Core, Pro, Teams, and Enterprise - https://aestech.com.au/pricing/make-pricing/ Tool: Make. Checked: 2026-07-03. Pricing model: Free tier plus operations-metered monthly plans; higher tiers add faster scheduling intervals, advanced features, and team permissions. Verdict: Make is the strong value pick for complex visual automations: paid plans start cheap, and operations often stretch further than Zapier tasks for multi-step scenarios. Best first move: Core for most individuals moving off the free plan; Pro when you need faster scheduling and more headroom; Teams once multiple builders share scenarios.. Watch out: Every module execution in a scenario consumes an operation, and polling triggers consume operations even when nothing new is found. A frequently scheduled scenario can quietly drain the monthly quota. - Free: $0. A genuinely usable free tier for light automation. - Core: from ~$9/mo billed annually. The cheap first paid step. - Pro: from ~$16/mo billed annually. For heavier individual or small-business use. - Teams and Enterprise: from ~$29/mo billed annually, Enterprise custom. For shared automation work and governance. ## n8n Pricing: Free Self-Hosted vs Cloud Starter, Pro, and Enterprise - https://aestech.com.au/pricing/n8n-pricing/ Tool: n8n. Checked: 2026-07-03. Pricing model: Free self-hosted community edition plus execution-metered cloud subscriptions; Enterprise adds SSO, environments, and advanced governance. Verdict: Self-host for free if you have the technical capacity to run and secure it; pay for Cloud when you want managed hosting, and note that executions, not steps, are the meter. Best first move: Self-hosted Community for technical teams on a budget; Cloud Starter for a managed entry point; Pro when execution volume and concurrency grow.. Watch out: Cloud plans meter full workflow executions rather than individual steps, which is generous for complex workflows, but active workflow limits and concurrency caps on lower tiers can bite before the execution quota does. - Community (self-hosted): $0. Run it on your own infrastructure. - Cloud Starter: from ~$24/mo. Managed hosting for individuals and small teams. - Cloud Pro: from ~$60/mo. For growing execution volume. - Enterprise: Custom pricing. For organisations with governance needs, cloud or self-hosted. ## Bolt Pricing: Free, Pro, and Teams - https://aestech.com.au/pricing/bolt-pricing/ Tool: Bolt. Checked: 2026-07-03. Pricing model: Free daily token allowance plus subscription tiers metered by monthly tokens; larger Pro tiers and Teams plans raise the token bucket. Verdict: The free tier is for evaluation only; regular builders should start on the entry Pro tier and upgrade the token bucket only after a month of real usage data. Best first move: Pro at the entry tier for most individual builders; a larger Pro tier once you regularly run out mid-project; Teams when collaborators share billing.. Watch out: Tokens are consumed by every AI interaction, and large projects burn tokens faster because more code context is processed per message. Late-month token exhaustion mid-feature is the classic complaint, so size the tier to your project scale. - Free: $0. For evaluating the workflow. - Pro: from ~$20/mo. The standard individual plan. - Pro (higher tiers): from ~$50/mo. For heavy builders who exhaust the entry bucket. - Teams: from ~$30/mo per member. For collaborating teams. ## v0 Pricing: Free, Premium, Team, and Enterprise - https://aestech.com.au/pricing/v0-pricing/ Tool: v0. Checked: 2026-07-03. Pricing model: Free monthly credit allowance plus credit-metered subscriptions; Team adds shared projects and billing, Enterprise adds governance on custom pricing. Verdict: Free is fine for occasional UI generation; Premium is the pick for regular front-end work, and Teams should buy seats only for the people actually generating. Best first move: Premium for individual designers and developers using v0 weekly; Team once shared projects and central billing matter.. Watch out: Credits are consumed per generation and larger or more complex generations cost more credits, so heavy iteration on big components drains the allowance quickly. Unused monthly credits typically do not roll over, so confirm current credit mechanics at checkout. - Free: $0. For occasional generation and evaluation. - Premium: from ~$20/mo. The standard individual plan. - Team: from ~$30/mo per user. For teams generating UI together. - Enterprise: Custom pricing. For organisations with security and procurement needs. ## Lovable Pricing: Free, Pro, Business, and Enterprise - https://aestech.com.au/pricing/lovable-pricing/ Tool: Lovable. Checked: 2026-07-03. Pricing model: Free daily message allowance plus subscription tiers metered by monthly credits; higher tiers raise the credit bucket and add team features. Verdict: Free suits a quick taste of AI app building; Pro at the entry credit tier is the sensible start for real projects, with Business reserved for teams that need shared workspaces. Best first move: Pro at the entry credit tier for most individual builders; Business when a team collaborates on the same apps under one bill.. Watch out: Every AI message consumes credits, including follow-up fixes and small tweaks, so conversational trial-and-error building drains the allowance faster than planned, deliberate prompts. Size the credit tier to your prompting style. - Free: $0. For evaluating the builder. - Pro: from ~$25/mo. The standard individual plan. - Business: from ~$50/mo. For teams building together. - Enterprise: Custom pricing. For organisations with security and scale requirements. # AI tool stacks by use case ## Small Business AI Stack - https://aestech.com.au/stacks/small-business-ai-stack/ Audience: Owners and operators who need one practical toolset for writing, meetings, social, and basic automation. Outcome: Save admin time without creating a complicated software bill. Buying posture: Start free, then add paid plans only where the tool earns weekly use. Decision rule: Choose this stack when time saved matters more than deep customisation. Upgrade individual tools only after they become part of the weekly operating rhythm. - General assistant: ChatGPT. Best all-rounder for drafting, brainstorming, spreadsheets, and day-to-day problem solving. - Writing quality: Grammarly. Keeps email, proposals, and web copy clean everywhere the team writes. - Meetings: Fathom. Captures summaries and action items without adding another paid seat immediately. - Social scheduling: Buffer AI Assistant. Turns one idea into multiple social posts and keeps publishing lightweight. ## SaaS Startup AI Stack - https://aestech.com.au/stacks/saas-startup-ai-stack/ Audience: Founders and lean teams balancing product velocity, customer proof, security, and sales content. Outcome: Move faster while building the trust assets buyers ask for. Buying posture: Expect a mix of $20/mo seats, developer tools, and quote-based compliance software. Decision rule: Choose this stack when customer trust and product velocity are the same problem. If certification is already in motion, compare Vanta, Drata, Secureframe, and Sprinto before buying. - Product and docs: Claude. Strong for long-form specs, customer research synthesis, help docs, and careful reasoning. - Engineering: Cursor. Repo-aware editing helps small engineering teams ship multi-file changes faster. - Meeting memory: Fathom. Turns sales, onboarding, and customer interviews into searchable summaries. - Security scanning: Snyk. Catches dependency and container issues before they become procurement blockers. - Compliance automation: Vanta. Creates the evidence engine for SOC 2, ISO 27001, and customer security reviews. ## Content Growth AI Stack - https://aestech.com.au/stacks/content-growth-ai-stack/ Audience: Marketing teams publishing articles, landing pages, social clips, and conversion copy. Outcome: Ship more useful content while protecting brand voice and search quality. Buying posture: Budget for at least one premium writing workflow and one SEO or repurposing tool. Decision rule: Choose this stack when publishing quality and distribution matter more than raw output volume. Use one assistant for drafting, but keep separate tools for research, optimisation, and repurposing. - Research and briefs: Perplexity. Fast cited research for briefs, fact checks, and competitive scanning. - Long-form writing: Claude. Best fit for nuanced drafts, rewrites, and editorial development. - Brand workflow: Jasper. Useful when a team needs repeatable brand voice, templates, and collaboration. - SEO optimisation: Surfer SEO. Turns search intent and SERP patterns into concrete content improvements. - Video repurposing: Opus Clip. Turns webinars, interviews, and long videos into social-ready short clips. ## Compliance-Ready AI Stack - https://aestech.com.au/stacks/compliance-ready-ai-stack/ Audience: Teams using AI in regulated, enterprise, or security-sensitive environments. Outcome: Adopt AI while keeping evidence, controls, and risk reviews close at hand. Buying posture: Expect quote-based compliance tooling plus developer/security tools for the technical controls. Decision rule: Choose this stack when proof matters as much as productivity. Start with the compliance system of record, then add AI-specific testing where models touch customer or sensitive data. - Controlled assistant: Microsoft Copilot. Fits Microsoft 365 environments where enterprise data controls matter. - Compliance system: Drata. Strong multi-framework monitoring for SOC 2, ISO 27001, PCI DSS, and related programs. - Application security: Snyk. Supports technical vulnerability management with developer-friendly scanning. - LLM security testing: Lakera. Adds AI-specific testing for prompt injection, jailbreaks, and model abuse scenarios. - Privacy governance: OneTrust. Broad privacy and AI governance coverage for regulated data environments. ## Accounting Firm AI Stack - https://aestech.com.au/stacks/accounting-firm-ai-stack/ Audience: Accounting, bookkeeping, and advisory firms that need faster client communication, meeting capture, document drafting, and controlled productivity. Outcome: Reduce admin load while keeping client data and review discipline front and centre. Buying posture: Start with tools that fit existing Microsoft, meeting, and document workflows before adding specialised automation. Decision rule: Choose this stack when client trust is the constraint. Keep human review mandatory for advice, tax positions, and final client deliverables. - Controlled productivity: Microsoft Copilot. Fits Microsoft 365 environments where email, documents, spreadsheets, and permission boundaries are already in place. - Client meeting notes: Fathom. Captures summaries, decisions, and follow-up tasks from client calls without manual note taking. - Research and drafting: Claude. Strong for careful long-form drafting, client memos, and turning rough notes into structured explanations. - Writing QA: Grammarly. Keeps client-facing emails, proposals, and reports clear before they leave the firm. - Trust operations: Secureframe. Useful when the firm needs to show stronger internal control discipline to larger clients. ## Agency AI Stack - https://aestech.com.au/stacks/agency-ai-stack/ Audience: Creative, content, SEO, and performance agencies that need faster production without losing brand control. Outcome: Increase campaign output while keeping strategy, source quality, and client review visible. Buying posture: Budget for one brand workflow, one SEO workflow, one visual workflow, and one meeting-memory tool. Decision rule: Choose this stack when an agency needs more throughput but still sells taste, judgment, and client-ready craft. Use AI for variants, not as a substitute for strategy. - Brand copy workflow: Jasper. Gives teams brand voice, repeatable templates, and collaboration features for client content production. - SEO planning: Surfer SEO. Turns search intent and competitive patterns into concrete article and landing-page improvements. - Visual concepts: Midjourney. Fast, high-quality concept imagery for moodboards, campaign directions, and creative exploration. - Video repurposing: Opus Clip. Turns webinars, interviews, and long-form client videos into short clips for social distribution. - Client calls: Fathom. Keeps scope, approvals, and action items searchable after every client conversation. ## Consulting Firm AI Stack - https://aestech.com.au/stacks/consulting-firm-ai-stack/ Audience: Consultants and boutique advisory teams producing research, workshops, proposals, reports, and board-ready summaries. Outcome: Move from discovery to polished recommendations faster without losing analytical depth. Buying posture: Prioritise research quality, long-form synthesis, meeting capture, and polished client communication. Decision rule: Choose this stack when the bottleneck is synthesis and client communication. Keep final recommendations owned by the consultant, not the model. - Deep synthesis: Claude. Excellent for turning long notes, transcripts, and outlines into structured analysis and recommendations. - Research scan: Perplexity. Useful for cited research, market scans, and fast verification before a consultant goes deeper. - Workshop capture: Fathom. Records decisions, objections, and next steps from client workshops and sales calls. - Document polish: Grammarly. Catches clarity and tone problems before proposals and reports reach executives. - Office workflow: Microsoft Copilot. Works inside the documents, inboxes, and slide workflows many clients already use. ## Ecommerce AI Stack - https://aestech.com.au/stacks/ecommerce-ai-stack/ Audience: Online stores, marketplace sellers, and ecommerce marketers producing product copy, ads, images, email, and social content. Outcome: Ship more product and campaign assets while keeping offers clear and conversion-focused. Buying posture: Start with product copy and ad creative, then add image and social workflows once the team has repeatable campaigns. Decision rule: Choose this stack when asset production slows campaigns. Keep product claims, discounts, and compliance-sensitive statements reviewed before launch. - Product copy: ChatGPT. Flexible for product descriptions, FAQs, email drafts, merchandising ideas, and campaign brainstorming. - Ad creative: AdCreative.ai. Built for generating and testing performance ad variants across campaigns. - Image generation: Adobe Firefly. Useful for commercial-safe image workflows and Creative Cloud teams. - Social scheduling: Buffer AI Assistant. Repurposes product launches and campaign ideas into social posts across channels. - Copy QA: Grammarly. Keeps product pages, emails, and support copy clean before publishing. ## Law Firm AI Stack - https://aestech.com.au/stacks/law-firm-ai-stack/ Audience: Small and mid-sized law firms using AI for drafting support, meeting notes, internal knowledge work, and careful client communication. Outcome: Save non-billable time while keeping confidentiality, review, and professional judgment intact. Buying posture: Use controlled workplace tools first, then add writing and meeting workflows with clear review rules. Decision rule: Choose this stack only with clear internal rules. Do not enter sensitive client material into tools unless data handling, privilege, confidentiality, and review obligations are understood. - Controlled workspace: Microsoft Copilot. Keeps AI assistance close to Microsoft 365 permissions, documents, email, and calendar workflows. - Drafting support: Claude. Strong for careful summarisation, rewriting, issue spotting, and turning notes into structured drafts. - Client calls: Fathom. Captures meeting summaries and action items so follow-up work is less manual. - Client communication: Grammarly. Improves clarity, tone, and consistency in emails, letters, and web copy. - Privacy governance: OneTrust. Relevant for firms with heavier privacy, data governance, or client assurance obligations. ## Developer Security AI Stack - https://aestech.com.au/stacks/developer-security-ai-stack/ Audience: Engineering and security teams that want AI coding speed without losing vulnerability management, dependency control, or model-risk visibility. Outcome: Ship faster while catching security issues before they reach customers or auditors. Buying posture: Budget for an AI editor, code security scanning, dependency scanning, and AI-specific testing if LLM features ship to users. Decision rule: Choose this stack when engineering velocity and security assurance both matter. AI-written code should go through the same review, testing, and security gates as human-written code. - AI code editor: Cursor. Repo-aware editing helps teams make coordinated code changes while still reviewing diffs. - Inline coding assistant: GitHub Copilot. Reliable autocomplete-style support across common developer workflows. - Dependency security: Snyk. Finds vulnerable dependencies, containers, and code issues before release. - Code security platform: GitHub Advanced Security. Adds code scanning, secret scanning, and security controls inside GitHub workflows. - LLM app testing: Lakera. Tests AI applications for prompt injection, jailbreaks, and model abuse risks. # ISO 27001 (ISO/IEC 27001:2022) ## Management-system requirements, clauses 4 to 10 ### Clause 4: Context of the organization - https://aestech.com.au/iso-27001/requirements/context-of-the-organization/ Set the foundations: understand your context and interested parties, define the ISMS scope, and establish the ISMS itself. - 4.1 Understanding the organization and its context: Determine the external and internal issues relevant to your purpose that affect the ISMS’s ability to achieve its intended outcomes. - 4.2 Needs and expectations of interested parties: Identify the interested parties relevant to the ISMS, their relevant requirements, and which of those you will address (including legal, regulatory and contractual obligations). - 4.3 Determining the scope of the ISMS: Determine the boundaries and applicability of the ISMS, considering 4.1, 4.2, and the interfaces and dependencies with other organisations. The scope must be documented. - 4.4 Information security management system: Establish, implement, maintain and continually improve the ISMS, including the processes needed and their interactions. ### Clause 5: Leadership - https://aestech.com.au/iso-27001/requirements/leadership/ Top management must own the ISMS: demonstrate commitment, set the policy, and assign roles and authorities. - 5.1 Leadership and commitment: Top management must demonstrate leadership by aligning the policy and objectives to strategy, integrating the ISMS into business processes, providing resources, communicating its importance, ensuring it achieves its outcomes, and promoting continual improvement. - 5.2 Policy: Establish an information security policy appropriate to the organisation that includes (or frames) objectives and commitments to satisfy requirements and continually improve. It must be documented, communicated internally, and available to interested parties as appropriate. - 5.3 Roles, responsibilities and authorities: Assign and communicate responsibilities and authorities for ISMS-relevant roles, including for ensuring conformance to the standard and reporting ISMS performance to top management. ### Clause 6: Planning - https://aestech.com.au/iso-27001/requirements/planning/ The risk-based core: address risks and opportunities, run risk assessment and treatment, set objectives, and plan changes. - 6.1.1 Actions to address risks and opportunities (general): Considering your context and interested parties, determine the risks and opportunities to be addressed so the ISMS can achieve its outcomes, prevent undesired effects, and improve. Plan actions and how to integrate and evaluate them. - 6.1.2 Information security risk assessment: Define and apply a risk assessment process with risk acceptance and assessment criteria, that is repeatable and consistent, identifies risks to confidentiality/integrity/availability and their owners, and analyses, evaluates and prioritises them. Retain documented information about the process. - 6.1.3 Information security risk treatment: Define a risk treatment process: select treatment options, determine the necessary controls, compare them against Annex A to confirm none are missed, produce a Statement of Applicability (controls applied, justification, implementation status, and exclusion justifications), formulate a risk treatment plan, and obtain risk owners’ approval and acceptance of residual risk. - 6.2 Information security objectives and planning: Set measurable information security objectives at relevant functions and levels, consistent with the policy, monitored, communicated, updated, and documented. Plan what will be done, the resources, who is responsible, when, and how results are evaluated. - 6.3 Planning of changes: When changes to the ISMS are needed, carry them out in a planned manner. ### Clause 7: Support - https://aestech.com.au/iso-27001/requirements/support/ Provide the resources, competence, awareness, communication, and documented information the ISMS needs to run. - 7.1 Resources: Determine and provide the resources needed to establish, implement, maintain and improve the ISMS. - 7.2 Competence: Determine the competence needed for people whose work affects information security, ensure they are competent, act to close gaps, and retain evidence of competence. - 7.3 Awareness: People doing work under your control must be aware of the policy, their contribution to the ISMS, and the implications of not conforming. - 7.4 Communication: Determine the internal and external communications relevant to the ISMS: what, when, with whom, and how. - 7.5 Documented information: Maintain the documented information required by the standard and that you need for effectiveness; control its creation and updating (identification, format, review and approval) and its availability, protection, distribution, storage, change control, retention and disposition, including documents of external origin. ### Clause 8: Operation - https://aestech.com.au/iso-27001/requirements/operation/ Run the plan: control your processes, and actually perform risk assessment and treatment. - 8.1 Operational planning and control: Plan, implement and control the processes needed to meet requirements and the Clause 6 actions, establish process criteria, control changes, and control externally provided processes. Keep enough documented information to have confidence processes ran as planned. - 8.2 Information security risk assessment: Perform risk assessments at planned intervals or when significant changes occur, and retain the results. - 8.3 Information security risk treatment: Implement the risk treatment plan and retain the results. ### Clause 9: Performance evaluation - https://aestech.com.au/iso-27001/requirements/performance-evaluation/ Check it works: monitor and measure, run internal audits, and hold management reviews. - 9.1 Monitoring, measurement, analysis and evaluation: Determine what to monitor and measure, the methods, when, and by whom, then analyse and evaluate the results to assess information security performance and ISMS effectiveness. Keep documented evidence. - 9.2 Internal audit: Conduct internal audits at planned intervals to confirm the ISMS conforms to your own requirements and the standard and is effectively implemented. Run an audit programme (frequency, methods, responsibilities, reporting), use objective and impartial auditors, and report results to management. - 9.3 Management review: Top management must review the ISMS at planned intervals, considering prior actions, changes in issues and interested parties, performance feedback (nonconformities, monitoring, audits, objectives), interested-party feedback, risk assessment and treatment status, and improvement opportunities. Results must include decisions on improvements and any ISMS changes. ### Clause 10: Improvement - https://aestech.com.au/iso-27001/requirements/improvement/ Keep getting better: continually improve, and handle nonconformities with corrective action. - 10.1 Continual improvement: Continually improve the suitability, adequacy and effectiveness of the ISMS. - 10.2 Nonconformity and corrective action: When a nonconformity occurs, react to control and correct it and deal with the consequences; evaluate whether to eliminate the cause (review it, find the cause, check for similar issues); implement action, review its effectiveness, and change the ISMS if needed. Keep evidence of the nonconformity, actions, and results. ## Annex A controls (93 controls) ### A.5 Organizational controls - https://aestech.com.au/iso-27001/controls/organizational/ - A.5.1 Policies for information security: Define, approve, publish and communicate information security policies, have relevant staff and interested parties acknowledge them, and review them at planned intervals and after significant changes. - A.5.2 Information security roles and responsibilities: Define and allocate security responsibilities according to the organisation’s needs. - A.5.3 Segregation of duties: Separate conflicting duties and areas of responsibility to reduce fraud and error. - A.5.4 Management responsibilities: Require all personnel to apply security per established policies and procedures. - A.5.5 Contact with authorities: Maintain contact with relevant authorities (regulators, law enforcement). - A.5.6 Contact with special interest groups: Maintain contact with security forums and professional associations. - A.5.7 Threat intelligence: Collect and analyse information about threats to produce actionable threat intelligence. - A.5.8 Information security in project management: Integrate security into project management regardless of project type. - A.5.9 Inventory of information and other associated assets: Develop and maintain an inventory of information and associated assets, with owners. - A.5.10 Acceptable use of information and other associated assets: Document and implement rules for acceptable use and handling of assets. - A.5.11 Return of assets: Ensure personnel return all assets on termination or change of role. - A.5.12 Classification of information: Classify information based on its confidentiality, integrity and availability needs plus the requirements of interested parties such as regulators, customers and partners. - A.5.13 Labelling of information: Develop and implement procedures to label information per the classification scheme. - A.5.14 Information transfer: Put rules, procedures and agreements in place for transferring information internally and externally. - A.5.15 Access control: Establish and implement access control rules based on business and security requirements. - A.5.16 Identity management: Manage the full lifecycle of identities. - A.5.17 Authentication information: Control allocation and management of authentication information (passwords, keys). - A.5.18 Access rights: Provision, review, modify and remove access rights per the access control policy. - A.5.19 Information security in supplier relationships: Define and implement processes to manage security risks from supplier use. - A.5.20 Addressing information security within supplier agreements: Establish relevant security requirements in agreements with suppliers. - A.5.21 Managing information security in the ICT supply chain: Manage security risks across the ICT product and service supply chain. - A.5.22 Monitoring, review and change management of supplier services: Regularly monitor, review, audit and manage changes to supplier service delivery. - A.5.23 Information security for use of cloud services: Establish processes for acquisition, use, management and exit of cloud services. - A.5.24 Information security incident management planning and preparation: Plan and prepare for incidents by defining processes, roles and responsibilities. - A.5.25 Assessment and decision on information security events: Assess security events and decide whether to classify them as incidents. - A.5.26 Response to information security incidents: Respond to incidents per documented procedures. - A.5.27 Learning from information security incidents: Use knowledge from incidents to strengthen controls. - A.5.28 Collection of evidence: Establish procedures for identification, collection and preservation of evidence. - A.5.29 Information security during disruption: Plan how to maintain security at an appropriate level during disruption. - A.5.30 ICT readiness for business continuity: Plan, implement, maintain and test ICT readiness based on continuity objectives. - A.5.31 Legal, statutory, regulatory and contractual requirements: Identify and meet relevant legal and contractual security obligations. - A.5.32 Intellectual property rights: Implement procedures to protect intellectual property rights. - A.5.33 Protection of records: Protect records from loss, destruction, falsification and unauthorised access. - A.5.34 Privacy and protection of PII: Identify and meet requirements for the protection of personal data. - A.5.35 Independent review of information security: Have the security approach reviewed independently at planned intervals. - A.5.36 Compliance with policies, rules and standards: Regularly review compliance with your own security policies and standards. - A.5.37 Documented operating procedures: Document operating procedures and make them available to those who need them. ### A.6 People controls - https://aestech.com.au/iso-27001/controls/people/ - A.6.1 Screening: Perform background verification checks before people join and repeat them periodically, proportionate to role risk. - A.6.2 Terms and conditions of employment: State security responsibilities in employment contracts. - A.6.3 Information security awareness, education and training: Provide regular awareness training relevant to roles. - A.6.4 Disciplinary process: Establish and communicate a process for handling security violations. - A.6.5 Responsibilities after termination or change of employment: Define and enforce security duties that remain after a role ends. - A.6.6 Confidentiality or non-disclosure agreements: Identify, document and review NDA requirements. - A.6.7 Remote working: Implement security measures for staff working remotely. - A.6.8 Information security event reporting: Provide a mechanism for personnel to report security events promptly. ### A.7 Physical controls - https://aestech.com.au/iso-27001/controls/physical/ - A.7.1 Physical security perimeters: Define and use security perimeters to protect areas with information assets. - A.7.2 Physical entry: Protect secure areas with appropriate entry controls. - A.7.3 Securing offices, rooms and facilities: Design and apply physical security for offices and rooms. - A.7.4 Physical security monitoring: Continuously monitor premises for unauthorised physical access. - A.7.5 Protecting against physical and environmental threats: Design protection against fire, flood, and other threats. - A.7.6 Working in secure areas: Implement measures for working within secure areas. - A.7.7 Clear desk and clear screen: Apply clear-desk and clear-screen rules. - A.7.8 Equipment siting and protection: Site and protect equipment to reduce risk. - A.7.9 Security of assets off-premises: Protect assets used outside the organisation’s premises. - A.7.10 Storage media: Manage media through acquisition, use, transport and disposal. - A.7.11 Supporting utilities: Protect facilities from failure of supporting utilities (power, cooling). - A.7.12 Cabling security: Protect power and telecom cabling from interception/damage. - A.7.13 Equipment maintenance: Maintain equipment correctly to ensure availability and integrity. - A.7.14 Secure disposal or re-use of equipment: Verify storage media is wiped or destroyed before disposal or re-use. ### A.8 Technological controls - https://aestech.com.au/iso-27001/controls/technological/ - A.8.1 User endpoint devices: Protect information on user endpoint devices. - A.8.2 Privileged access rights: Restrict and manage allocation and use of privileged access. - A.8.3 Information access restriction: Restrict access to information per the access control policy. - A.8.4 Access to source code: Manage read/write access to source code and tools appropriately. - A.8.5 Secure authentication: Implement secure authentication technologies and procedures. - A.8.6 Capacity management: Monitor and tune resource use to meet capacity needs. - A.8.7 Protection against malware: Implement malware protection supported by user awareness. - A.8.8 Management of technical vulnerabilities: Obtain vulnerability information and take action to address exposure. - A.8.9 Configuration management: Establish, document, implement, monitor and review configurations. - A.8.10 Information deletion: Delete information when no longer required. - A.8.11 Data masking: Use data masking per policy and business requirements. - A.8.12 Data leakage prevention: Apply DLP measures to systems and networks handling sensitive data. - A.8.13 Information backup: Maintain and test backups per an agreed policy. - A.8.14 Redundancy of information processing facilities: Implement redundancy to meet availability requirements. - A.8.15 Logging: Produce, store and protect logs of activities and events. - A.8.16 Monitoring activities: Monitor networks, systems and applications for anomalous behaviour. - A.8.17 Clock synchronization: Synchronise clocks to an approved time source. - A.8.18 Use of privileged utility programs: Restrict and tightly control utility programs that can override controls. - A.8.19 Installation of software on operational systems: Manage secure installation of software on operational systems. - A.8.20 Networks security: Secure and manage networks to protect information. - A.8.21 Security of network services: Identify the security mechanisms, service levels and service requirements of each network service, implement them (whether the service is provided in-house or by an external provider), and monitor that they continue to be met. - A.8.22 Segregation of networks: Segregate groups of services, users and systems on networks. - A.8.23 Web filtering: Manage access to external websites to reduce exposure to malicious content. - A.8.24 Use of cryptography: Define and implement rules for effective use of cryptography and key management. - A.8.25 Secure development life cycle: Establish and apply rules for secure development of software and systems. - A.8.26 Application security requirements: Identify, specify and approve security requirements for applications. - A.8.27 Secure system architecture and engineering principles: Establish and apply secure engineering principles. - A.8.28 Secure coding: Apply secure coding principles to software development. - A.8.29 Security testing in development and acceptance: Define and implement security testing in the development lifecycle. - A.8.30 Outsourced development: Direct, monitor and review outsourced development activity. - A.8.31 Separation of development, test and production environments: Separate and secure dev, test and production environments. - A.8.32 Change management: Subject changes to information processing facilities to change management. - A.8.33 Test information: Select, protect and manage test data appropriately. - A.8.34 Protection of information systems during audit testing: Plan and agree audit tests to minimise disruption to systems. # IT policy and evidence templates mapped to controls Compliance readiness checklist: https://aestech.com.au/compliance-readiness/ Markdown compliance readiness checklist: https://aestech.com.au/compliance-readiness/checklist.md Use the readiness checklist to choose SOC 2, ISO 27001, PCI DSS, or ISO 42001 based on buyer demand, cardholder data scope, certification need, and AI governance risk. The readiness flow covers scope and accountability, risk and control mapping, policies and procedures, evidence operations, and audit readiness. Policy template library: https://aestech.com.au/policy-templates/ Control-to-policy mapping: https://aestech.com.au/policy-templates/control-mapping/ Markdown policy template pack: https://aestech.com.au/policy-templates/policy-pack.md Individual Markdown policy templates: https://aestech.com.au/policy-templates/access-control-policy.md, https://aestech.com.au/policy-templates/acceptable-use-policy.md, https://aestech.com.au/policy-templates/information-classification-and-handling-policy.md, https://aestech.com.au/policy-templates/supplier-security-policy.md, https://aestech.com.au/policy-templates/incident-response-policy.md, https://aestech.com.au/policy-templates/secure-development-policy.md, https://aestech.com.au/policy-templates/backup-and-continuity-policy.md, https://aestech.com.au/policy-templates/endpoint-and-mobile-device-policy.md, https://aestech.com.au/policy-templates/cryptography-and-key-management-policy.md, https://aestech.com.au/policy-templates/ai-use-and-governance-policy.md, https://aestech.com.au/policy-templates/data-retention-and-disposal-policy.md, https://aestech.com.au/policy-templates/backup-policy.md, https://aestech.com.au/policy-templates/vulnerability-and-patch-management-policy.md, https://aestech.com.au/policy-templates/logging-and-monitoring-policy.md, https://aestech.com.au/policy-templates/business-continuity-and-disaster-recovery-policy.md, https://aestech.com.au/policy-templates/change-management-policy.md, https://aestech.com.au/policy-templates/human-resources-security-policy.md, https://aestech.com.au/policy-templates/physical-and-environmental-security-policy.md, https://aestech.com.au/policy-templates/data-breach-response-policy.md, https://aestech.com.au/policy-templates/mobile-device-and-byod-policy.md, https://aestech.com.au/policy-templates/network-security-policy.md, https://aestech.com.au/policy-templates/password-and-authentication-policy.md, https://aestech.com.au/policy-templates/malware-protection-policy.md, https://aestech.com.au/policy-templates/security-awareness-and-training-policy.md, https://aestech.com.au/policy-templates/cloud-and-outsourcing-policy.md, https://aestech.com.au/policy-templates/asset-management-policy.md, https://aestech.com.au/policy-templates/isms-internal-audit-procedure.md, https://aestech.com.au/policy-templates/management-review-procedure.md, https://aestech.com.au/policy-templates/nonconformity-and-corrective-action-procedure.md, https://aestech.com.au/policy-templates/information-risk-management-procedure.md, https://aestech.com.au/policy-templates/remote-working-policy.md, https://aestech.com.au/policy-templates/email-and-communications-policy.md, https://aestech.com.au/policy-templates/clear-desk-and-clear-screen-policy.md, https://aestech.com.au/policy-templates/information-security-roles-and-responsibilities.md 45 copy-paste starting templates are available. 34 are reusable policy templates mapped directly to ISO 27001, SOC 2, PCI DSS and ISO 42001 controls. Control-to-template shortcuts: access reviews and MFA -> access control policy; data classification and privacy -> information classification and handling policy; supplier and cloud risk -> supplier security policy; incidents and breach response -> incident response policy; secure development and change -> secure development policy; AI tool use and human review -> AI use and governance policy. ## ISMS scope statement - https://aestech.com.au/policy-templates/#isms-scope-statement Defines exactly what your ISMS covers. Auditors read this first. Frameworks: general. Template body: ``` The Information Security Management System (ISMS) of [Company Pty Ltd] covers the provision of [product/service] to customers, including: - People: all staff and contractors of [teams/departments] - Processes: [e.g. software development, customer support, IT operations] - Technology: [e.g. the AWS production environment, corporate Google Workspace, employee endpoints] - Locations: [e.g. the Sydney office and all remote workers] Excluded from scope: [list exclusions and the justification]. Boundaries and interfaces with third parties: [e.g. AWS (IaaS), Stripe (payments)]. ``` ## Statement of Applicability (SoA) row - https://aestech.com.au/policy-templates/#statement-of-applicability-soa-row One row per Annex A control. The central ISMS document. Frameworks: general. Template body: ``` Columns: Control ID | Control name | Applicable (Y/N) | Justification | Implementation status | Reference Example: A.8.5 | Secure authentication | Y | MFA required for all access to production and email | Implemented | Okta policy POL-07 A.7.4 | Physical security monitoring | N | No company-controlled premises; fully remote | N/A | Remote Work Policy POL-12 ``` ## Risk register / risk assessment - https://aestech.com.au/policy-templates/#risk-register-risk-assessment Records each risk, its rating, and how you will treat it. Frameworks: general. Template body: ``` Columns: Risk ID | Asset | Threat | Vulnerability | Likelihood (1-5) | Impact (1-5) | Risk score | Owner | Treatment (Treat/Tolerate/Transfer/Terminate) | Controls | Residual score | Review date Example: R-014 | Customer database | Credential theft | No MFA on admin | 4 | 5 | 20 | CTO | Treat | A.8.5 MFA, A.8.2 privileged access | 6 | 2026-09-30 ``` ## Information security policy (outline) - https://aestech.com.au/policy-templates/#information-security-policy-outline The top-level policy. Keep topic policies separate and reference them. Frameworks: general. Template body: ``` 1. Purpose and scope 2. Information security objectives 3. Roles and responsibilities (incl. management commitment) 4. Risk management approach 5. Policy areas (reference): Access Control, Acceptable Use, Cryptography, Supplier Security, Incident Response, Business Continuity, Secure Development 6. Legal and contractual obligations 7. Compliance, exceptions and disciplinary process 8. Review: at least annually, owned by [role] Approved by: [name/role] Version: [x.y] Date: [date] ``` ## Supplier security clause - https://aestech.com.au/policy-templates/#supplier-security-clause Drop into vendor agreements (maps to A.5.20). Frameworks: general. Template body: ``` The Supplier shall: (a) implement and maintain information security controls appropriate to the data processed, consistent with recognised standards such as ISO/IEC 27001; (b) notify [Company] of any security incident affecting [Company] data without undue delay and within [24/48] hours; (c) permit reasonable review of its security posture on request; (d) ensure subcontractors are bound by equivalent obligations; and (e) return or securely delete [Company] data on termination. ``` ## Incident response plan (outline) - https://aestech.com.au/policy-templates/#incident-response-plan-outline Maps to A.5.24 to A.5.28. Frameworks: general. Template body: ``` 1. Purpose and scope 2. Severity levels (SEV1-SEV4) and examples 3. Roles: Incident Manager, Comms Lead, Technical Lead, Exec sponsor 4. Phases: Detect -> Triage -> Contain -> Eradicate -> Recover -> Review 5. Reporting channel: [how staff report], 24/7 contact: [details] 6. External contacts: regulators, law enforcement, key customers, cyber insurer 7. Evidence handling and chain of custody 8. Communication templates (internal, customer, regulator) 9. Post-incident review: within [5] business days, actions tracked to closure 10. Test: tabletop exercise at least annually ``` ## Cardholder data flow and inventory - https://aestech.com.au/policy-templates/#cardholder-data-flow-and-inventory Find and document every place card data lives or moves. Shrinking this shrinks scope. Frameworks: general. Template body: ``` For each flow: Source -> Transport -> Process -> Store? Columns: Flow ID | Channel (web/phone/POS) | Data elements (PAN, expiry, CVV) | Systems touched | Encrypted? | Stored? (where/how long) | Owner Example: F-01 | E-commerce checkout | PAN, expiry | Browser -> Stripe.js -> Gateway | TLS 1.3 | No (tokenised) | Payments lead F-02 | Phone orders | PAN read aloud | Agent -> virtual terminal | TLS | No | Support lead ``` ## PCI DSS scope definition - https://aestech.com.au/policy-templates/#pci-dss-scope-definition Document and validate scope at least annually (req 12.5). Frameworks: general. Template body: ``` 1. Cardholder data environment (CDE): [systems that store/process/transmit CHD] 2. Connected-to / security-impacting systems: [e.g. jump hosts, logging, IdP] 3. Out of scope (and why): [segmented systems with no CHD access] 4. Network segmentation in place: [yes/no, how verified] 5. Third-party service providers in scope: [list + what they handle] 6. Merchant level: [1-4] SAQ type or ROC: [type] Reviewed by: [name] Date: [date] Next review: [date] ``` ## SAQ selection quick-guide - https://aestech.com.au/policy-templates/#saq-selection-quick-guide Pick the right Self-Assessment Questionnaire for how you take payments. Frameworks: general. Template body: ``` SAQ A Card-not-present, payment fully outsourced to a compliant third party (e.g. hosted/redirect or iframe). Smallest scope. SAQ A-EP E-commerce, payment processing outsourced but your site can affect the payment (e.g. JavaScript on your page). SAQ B Imprint machines or standalone dial-out terminals. No electronic storage. SAQ B-IP Standalone, IP-connected payment terminals. No electronic storage. SAQ C-VT Web-based virtual terminal, one device, no storage. SAQ C Payment application connected to the internet, no storage. SAQ P2PE Hardware payment terminals in a validated P2PE solution. No storage. SAQ D Everything else, including all service providers. Largest scope. Confirm your eligibility and level with your acquiring bank. ``` ## TPSP responsibility matrix - https://aestech.com.au/policy-templates/#tpsp-responsibility-matrix Split each requirement between you and each provider (req 12.8/12.9). Frameworks: general. Template body: ``` Columns: PCI requirement | Your responsibility | TPSP responsibility | Evidence held Example: Req 3 (stored data) | We store no CHD | Stripe stores/tokenises CHD | Stripe AOC on file Req 9 (physical) | Office + endpoints | AWS data-centre physical security | AWS AOC / shared responsibility Req 11 (testing) | App pen test, internal scans | Provider infrastructure testing | Pen test report; provider AOC ``` ## PCI incident response plan (outline) - https://aestech.com.au/policy-templates/#pci-incident-response-plan-outline Required by req 12.10; must cover suspected card-data compromise. Frameworks: general. Template body: ``` 1. Roles and 24/7 contacts 2. Severity and what counts as a suspected card-data compromise 3. Immediate actions: contain, preserve evidence, do not wipe 4. Who to notify and when: acquiring bank, card brands, forensic (PFI) if required, regulators 5. Containment and recovery steps 6. Communication templates 7. Post-incident review and control updates 8. Test at least annually ``` ## Access control policy - https://aestech.com.au/policy-templates/access-control-policy.md Use for ISO 27001 A.5.15, A.5.16, A.5.17, A.5.18, A.8.2, SOC 2 Security, and PCI DSS requirements 7 and 8. Frameworks: ISO 27001, SOC 2, PCI DSS. Template body: ``` 1. Purpose This policy defines how access to company systems, data, facilities and administrative functions is requested, approved, provisioned, reviewed and removed. 2. Scope This policy applies to all employees, contractors, service accounts, administrator accounts, production systems, business systems and third-party access. 3. Principles - Access is granted only for a documented business need. - Least privilege and need-to-know apply by default. - Shared user accounts are prohibited unless explicitly approved and monitored. - Privileged access requires separate approval and stronger monitoring. - MFA is required for email, identity, cloud, production, code, finance and admin systems. 4. Process - Access requests must be submitted in [ticketing system]. - The system owner approves access before provisioning. - IT or the system administrator provisions access according to the approved role. - Access is removed within [x] hours of termination and adjusted on role change. - Privileged access is reviewed at least quarterly. 5. Evidence Keep access request tickets, approval records, provisioning logs, access review sign-offs, offboarding records and exception approvals. Owner: [role] Review cadence: at least annually and after major system or role changes. ``` ## Acceptable use policy - https://aestech.com.au/policy-templates/acceptable-use-policy.md Use for ISO 27001 A.5.10, A.6.3, A.6.4, endpoint controls, remote work, and SOC 2 Security awareness. Frameworks: ISO 27001, SOC 2. Template body: ``` 1. Purpose This policy defines acceptable use of company information, devices, networks, SaaS tools, AI tools and communication systems. 2. User responsibilities Users must: - Protect company and customer information according to its classification. - Use approved systems for company work. - Lock screens when unattended. - Report suspected security events immediately. - Use company-approved AI tools only for permitted data types. - Follow password, MFA and device security requirements. 3. Prohibited activity Users must not: - Share credentials. - Store confidential data in unapproved tools. - Bypass security controls. - Install unapproved software on managed devices. - Upload customer, source-code or confidential information to unapproved AI systems. 4. Monitoring and enforcement The company may monitor company systems to protect security, meet legal obligations and investigate misuse. Violations may lead to access removal or disciplinary action. Evidence: signed acknowledgements, training completion, exception approvals, monitoring records and incident tickets. ``` ## Information classification and handling policy - https://aestech.com.au/policy-templates/information-classification-and-handling-policy.md Use for ISO 27001 A.5.12, A.5.13, A.5.14, privacy, SOC 2 Confidentiality, and data handling controls. Frameworks: ISO 27001, SOC 2, PCI DSS. Template body: ``` 1. Purpose This policy defines how information is classified, labelled, stored, transferred, retained and disposed of. 2. Classification levels - Public: approved for public release. - Internal: business information for employees and contractors. - Confidential: customer, employee, financial, security or commercial information. - Restricted: highly sensitive data such as credentials, production secrets, regulated data or security evidence. 3. Handling rules - Confidential and Restricted data must be stored only in approved systems. - External transfer requires approved channels and encryption where appropriate. - Restricted data must not be used in test, demo or AI tools unless approved and masked. - Records must be retained according to the retention schedule. - Data past its retention period must be deleted or anonymised. 4. Evidence Keep data inventories, transfer approvals, DLP alerts, retention schedules, deletion records, data processing records and exceptions. Owner: [role] Review cadence: annually and after material data-flow changes. ``` ## Supplier security policy - https://aestech.com.au/policy-templates/supplier-security-policy.md Use for ISO 27001 A.5.19 to A.5.23, SOC 2 vendor management, cloud services, and AI supplier reviews. Frameworks: ISO 27001, SOC 2, ISO 42001. Template body: ``` 1. Purpose This policy defines how suppliers are assessed, approved, monitored and offboarded when they can affect company information, customer data or critical services. 2. Supplier risk tiers - Critical: stores or processes confidential data, affects production, security, availability or regulated obligations. - Standard: supports business processes but has limited data or system access. - Low: no access to confidential data or critical systems. 3. Due diligence Before approval, critical suppliers must be reviewed for security posture, privacy, data location, subcontractors, incident notification, continuity, certifications and contractual terms. 4. Ongoing review Critical suppliers are reviewed at least annually and after major scope, product, location, subprocessor or incident changes. 5. Evidence Keep supplier register, risk tier, review records, security reports, contracts, data processing terms, offboarding records and exception approvals. ``` ## Incident response policy - https://aestech.com.au/policy-templates/incident-response-policy.md Use for ISO 27001 A.5.24 to A.5.28, SOC 2 incident response, PCI DSS 12.10, and security event handling. Frameworks: ISO 27001, SOC 2, PCI DSS. Template body: ``` 1. Purpose This policy defines how security events and incidents are reported, assessed, contained, investigated, communicated and reviewed. 2. Severity levels - SEV1: confirmed breach, active compromise, material customer impact or legal notification likely. - SEV2: serious security event requiring urgent investigation. - SEV3: contained event or control failure with limited impact. - SEV4: low-risk event, alert or near miss. 3. Process - Detect and report through [channel]. - Triage and classify severity. - Contain affected accounts, devices, systems or integrations. - Preserve evidence before changes are made. - Eradicate root cause and recover service. - Communicate to internal and external stakeholders as required. - Complete post-incident review within [x] business days. 4. Evidence Keep incident tickets, timeline, affected assets, decisions, communications, evidence chain, root cause, corrective actions and closure approval. ``` ## Secure development policy - https://aestech.com.au/policy-templates/secure-development-policy.md Use for ISO 27001 A.8.25 to A.8.32, source code controls, change management, and SOC 2 change controls. Frameworks: ISO 27001, SOC 2. Template body: ``` 1. Purpose This policy defines how software and system changes are designed, built, tested, approved, released and monitored securely. 2. Requirements - Security requirements must be considered during design. - Source code repositories require MFA, least privilege, branch protection and review. - Changes must be tracked in tickets or pull requests. - Code review is required before merge. - Security testing must include dependency scanning and appropriate static or dynamic testing. - Production releases require approval and rollback planning. - Production, test and development environments must be separated. - Production data must not be copied into test environments unless approved and masked. 3. Evidence Keep design reviews, tickets, pull requests, approvals, test results, release records, rollback plans, vulnerability remediation records and exceptions. ``` ## Backup and continuity policy - https://aestech.com.au/policy-templates/backup-and-continuity-policy.md Use for ISO 27001 A.5.29, A.5.30, A.8.13, A.8.14, SOC 2 Availability, and resilience controls. Frameworks: ISO 27001, SOC 2. Template body: ``` 1. Purpose This policy defines how critical systems and information are backed up, restored and kept available during disruption. 2. Requirements - Critical systems must have defined recovery time objectives and recovery point objectives. - Backups must be protected against unauthorised access and deletion. - Backup coverage must be monitored. - Restore tests must be performed at least annually for critical systems. - Continuity plans must include security responsibilities during disruption. - Failover or redundancy must match the availability commitment made to customers. 3. Evidence Keep backup job reports, restore test records, recovery objectives, continuity exercises, failover tests, incident records and corrective actions. ``` ## Endpoint and mobile device policy - https://aestech.com.au/policy-templates/endpoint-and-mobile-device-policy.md Use for ISO 27001 A.6.7, A.7.9, A.8.1, malware protection, remote work, and SOC 2 endpoint controls. Frameworks: ISO 27001, SOC 2. Template body: ``` 1. Purpose This policy defines baseline security requirements for laptops, mobile devices and remote work. 2. Requirements - Company devices must be enrolled in device management where practical. - Disk encryption, screen lock and supported operating systems are required. - Endpoint protection or malware protection must be enabled. - Lost or stolen devices must be reported immediately. - Confidential information must not be stored on unmanaged removable media. - Remote work must use approved networks, MFA and secure storage practices. 3. Evidence Keep device inventory, MDM compliance reports, endpoint protection status, encryption status, exception approvals and lost-device incident records. ``` ## Cryptography and key management policy - https://aestech.com.au/policy-templates/cryptography-and-key-management-policy.md Use for ISO 27001 A.8.24, secure authentication, encryption, SOC 2 Security, and PCI DSS encryption requirements. Frameworks: ISO 27001, SOC 2, PCI DSS. Template body: ``` 1. Purpose This policy defines how encryption and cryptographic keys are selected, used, protected, rotated and retired. 2. Requirements - Use TLS for data in transit where confidential or customer data is transmitted. - Encrypt confidential and restricted data at rest where supported. - Store secrets in approved secret managers, not source code or documents. - Limit access to keys to authorised roles. - Rotate keys after compromise, staff changes affecting key access, or according to system requirements. - Retire and destroy keys when no longer needed. 3. Evidence Keep encryption configuration, key access records, rotation logs, secret scanning results, exceptions and incident records. ``` ## AI use and governance policy - https://aestech.com.au/policy-templates/ai-use-and-governance-policy.md Use for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk. Frameworks: ISO 42001, ISO 27001, SOC 2. Template body: ``` 1. Purpose This policy defines how AI systems and AI tools are approved, used, monitored and reviewed. 2. Requirements - Keep an inventory of AI systems and approved AI tools. - Classify each AI system by purpose, data used, owner, affected stakeholders and risk tier. - Prohibit uploading confidential, restricted, customer, source-code or regulated data to unapproved AI tools. - Require human review for AI outputs used in consequential decisions, customer commitments, legal, security or financial workflows. - Review AI suppliers for data use, model training terms, confidentiality, security and change notification. - Record incidents, unsafe outputs, hallucination patterns, complaints, drift and material changes. 3. Evidence Keep AI inventory, AI impact assessments, supplier reviews, approved tool list, human review records, incidents, exceptions and management reviews. ``` ## Data retention and disposal policy - https://aestech.com.au/policy-templates/data-retention-and-disposal-policy.md Use for ISO 27001 A.5.33, A.5.34, A.8.10, SOC 2 Confidentiality and Privacy, and PCI DSS requirement 3. Frameworks: ISO 27001, SOC 2, PCI DSS. Template body: ``` 1. Purpose This policy defines how long records and data are kept, how they are securely disposed of when no longer required, and how the company meets legal, contractual and regulatory retention obligations. It limits the volume of data held to what is necessary, reducing risk and audit scope. 2. Scope This policy applies to all company and customer information in any format, including production databases, backups, file storage, email, paper records, removable media and data held by suppliers on the company behalf. It applies to all employees, contractors and service accounts. 3. Policy statements - Every category of data must have a defined retention period recorded in the retention schedule. - Data must not be kept longer than the retention period unless there is a legal hold, active investigation or documented business need approved by the data owner. - Personal and regulated data must be retained only for as long as the lawful purpose requires. - Cardholder data must be kept to the minimum required and deleted when no longer needed for a documented legal, regulatory or business reason. - When a retention period ends, data must be deleted, anonymised or destroyed using approved methods. - Electronic media must be sanitised or destroyed before reuse, return or disposal so that data cannot be recovered. - Paper records must be shredded or disposed of through an approved secure destruction service. - Suppliers holding company data must delete or return it on contract termination and on request. - Legal holds override scheduled deletion until the hold is formally released. 4. Roles and responsibilities - The [Data Protection Lead] owns the retention schedule and approves changes. - Data owners confirm retention periods for their data categories and authorise exceptions. - IT and system administrators implement deletion and media sanitisation. - Legal advises on retention obligations and issues or releases legal holds. - All staff follow the schedule and do not retain copies of data outside approved systems. 5. Procedures - Maintain a retention schedule listing data category, owner, system, retention period, legal basis and disposal method. - Review the retention schedule at least annually and after legal or product changes. - Run scheduled or periodic deletion jobs for data that has reached end of retention. - Sanitise media using cryptographic erasure, secure wipe or physical destruction, and record the method. - Issue a certificate of destruction for physical media and bulk destruction events. - Apply and track legal holds through [legal hold register]. 6. Evidence and records Keep the retention schedule, deletion job logs, media sanitisation and destruction records, certificates of destruction, legal hold register, supplier deletion confirmations and exception approvals. 7. Review cadence This policy is reviewed at least annually and after material changes to legal, regulatory or contractual retention obligations. Owner: [role] Version: [x.y] Approved by: [name/role] Date: [date] ``` ## Backup policy - https://aestech.com.au/policy-templates/backup-policy.md Use for ISO 27001 A.8.13, A.8.14, SOC 2 Availability, and PCI DSS requirement 12 resilience expectations. Frameworks: ISO 27001, SOC 2. Template body: ``` 1. Purpose This policy defines how company and customer data is backed up, protected, tested and restored so that information can be recovered after loss, corruption, ransomware or system failure. 2. Scope This policy applies to all critical systems, production databases, configuration data, source code, and any information whose loss would materially affect the business or customers. It applies to backups stored on company infrastructure and with cloud or third-party providers. 3. Policy statements - Each critical system must have a defined backup frequency aligned to its recovery point objective. - Each critical system must have a defined recovery time objective. - Backups must be encrypted at rest and in transit. - At least one backup copy must be kept in a separate location or account from the primary system. - Backups must be protected against unauthorised access, modification and deletion, including protection against ransomware such as immutable or write-once storage where available. - Backup success and failure must be monitored, and failures must be investigated and resolved. - Restore tests must be performed at least annually for each critical system, and results recorded. - Backup retention must align with the data retention schedule and any regulatory requirements. 4. Roles and responsibilities - The [IT Manager] owns the backup programme and approves backup configurations. - System owners define recovery point and recovery time objectives for their systems. - IT and system administrators configure, monitor and test backups. - The [Security Lead] reviews backup protection controls and restore test results. 5. Procedures - Maintain a backup register listing system, data, frequency, retention, location and owner. - Configure automated backups for all in-scope systems. - Monitor backup jobs daily and alert on failures. - Perform and document a restore test for each critical system at least annually. - Review backup encryption, access controls and immutability settings at least annually. 6. Evidence and records Keep the backup register, backup job reports, restore test records, recovery objective definitions, encryption and access configuration, immutability settings and exception approvals. 7. Review cadence This policy is reviewed at least annually and after major changes to systems, providers or recovery objectives. Owner: [role] Version: [x.y] Approved by: [name/role] Date: [date] ``` ## Vulnerability and patch management policy - https://aestech.com.au/policy-templates/vulnerability-and-patch-management-policy.md Use for ISO 27001 A.8.8, A.8.19, A.8.32, SOC 2 Security, and PCI DSS requirements 6 and 11. Frameworks: ISO 27001, SOC 2, PCI DSS. Template body: ``` 1. Purpose This policy defines how technical vulnerabilities are identified, assessed, prioritised and remediated, and how security patches are applied across company systems, in order to reduce the risk of exploitation. 2. Scope This policy applies to all production and corporate systems, servers, endpoints, cloud services, containers, network devices, applications and third-party software components used by the company. 3. Policy statements - Vulnerability scanning must be performed regularly on internal and external systems. - Discovered vulnerabilities must be assigned a severity using a recognised scoring method such as CVSS. - Remediation timeframes apply from the date a vulnerability is confirmed: - Critical: within [7] days. - High: within [30] days. - Medium: within [90] days. - Low: at the next scheduled maintenance. - Security patches must be tested where practical and applied within the remediation timeframe for their severity. - Where a vulnerability cannot be remediated in time, a compensating control and a documented, time-bound exception must be approved. - Internet-facing systems and systems handling regulated data are prioritised. - Penetration testing must be performed at least annually and after significant changes. - Software components and dependencies must be tracked, and end-of-life software must be replaced or isolated. 4. Roles and responsibilities - The [Security Lead] owns the vulnerability management programme and approves exceptions. - System and application owners remediate vulnerabilities in their systems within the required timeframe. - IT applies operating system and infrastructure patches. - Developers update vulnerable application dependencies. 5. Procedures - Run authenticated vulnerability scans on a [weekly or monthly] cadence and external scans regularly. - Triage findings, deduplicate, assign severity and create remediation tickets. - Track remediation to closure against the required timeframes. - Record and review exceptions with compensating controls. - Commission annual penetration testing and remediate findings. 6. Evidence and records Keep scan reports, remediation tickets and timestamps, patch records, penetration test reports, exception approvals, software inventory and end-of-life tracking. 7. Review cadence This policy is reviewed at least annually and after significant changes to the environment or threat landscape. Owner: [role] Version: [x.y] Approved by: [name/role] Date: [date] ``` ## Logging and monitoring policy - https://aestech.com.au/policy-templates/logging-and-monitoring-policy.md Use for ISO 27001 A.8.15, A.8.16, A.8.17, SOC 2 Security, and PCI DSS requirements 10 and 11. Frameworks: ISO 27001, SOC 2, PCI DSS. Template body: ``` 1. Purpose This policy defines how events on company systems are logged, retained, protected and monitored so that security events can be detected, investigated and used as evidence. 2. Scope This policy applies to all production systems, cloud platforms, identity and access systems, network devices, applications, security tools and administrative activity. It applies to all employees, contractors and service accounts whose actions are recorded. 3. Policy statements - Security relevant events must be logged, including authentication, authorisation changes, privileged actions, access to sensitive data, configuration changes and security tool alerts. - Logs must include enough detail to answer who did what, when, from where and the outcome. - Clocks across systems must be synchronised to a reliable time source. - Logs must be protected against unauthorised access, modification and deletion. - Logs must be retained for at least [12] months, with at least [3] months immediately available, or longer where regulation requires. - Security alerts must be reviewed and triaged, and confirmed events must follow the incident response process. - Monitoring must include alerting for suspicious activity such as repeated failed logins, privilege escalation and unusual data access. 4. Roles and responsibilities - The [Security Lead] owns the logging and monitoring programme and defines required log sources. - IT and system owners ensure their systems forward required logs. - The [Security Operations] function or designated staff review and triage alerts. - The [Incident Response] team handles confirmed security events. 5. Procedures - Maintain a list of in-scope log sources and required event types. - Forward logs to a central, access-controlled logging platform. - Configure time synchronisation across systems. - Define and tune alert rules for high-risk activity. - Review alerts on a defined cadence and record actions taken. - Periodically verify that critical log sources are still reporting. 6. Evidence and records Keep the log source inventory, logging configuration, retention settings, alert rules, alert review records, time synchronisation configuration and access controls on the logging platform. 7. Review cadence This policy is reviewed at least annually and after material changes to systems or threats. Owner: [role] Version: [x.y] Approved by: [name/role] Date: [date] ``` ## Business continuity and disaster recovery policy - https://aestech.com.au/policy-templates/business-continuity-and-disaster-recovery-policy.md Use for ISO 27001 A.5.29, A.5.30, A.5.7, SOC 2 Availability, and resilience and recovery requirements. Frameworks: ISO 27001, SOC 2. Template body: ``` 1. Purpose This policy defines how the company maintains and recovers critical operations during and after a disruptive event, and how information security is preserved throughout. It establishes recovery objectives and the planning, testing and review needed to meet them. 2. Scope This policy applies to all critical business processes, supporting systems, people and facilities. It covers events such as major system outages, supplier failure, cyber incidents, loss of premises and loss of key staff. 3. Policy statements - Critical business processes must be identified through a business impact analysis and reviewed at least annually. - Each critical process must have a recovery time objective and, where data is involved, a recovery point objective. - Business continuity and disaster recovery plans must be documented, accessible during a disruption and assigned to named owners. - Information security controls must remain in force during disruption and recovery, including access control, logging and approvals. - Continuity and recovery plans must be tested at least annually, and results must drive improvements. - Key dependencies on suppliers and cloud providers must be assessed for continuity. - Crisis communication arrangements must cover staff, customers, regulators and other stakeholders. 4. Roles and responsibilities - Executive management sponsors the programme and approves recovery objectives. - The [Continuity Lead] maintains the business impact analysis and coordinates plans and tests. - Process and system owners maintain recovery procedures for their areas. - The [Incident Response] team coordinates with continuity activities during major events. 5. Procedures - Conduct and maintain a business impact analysis of critical processes and dependencies. - Document continuity plans and technical disaster recovery procedures for critical systems. - Define activation criteria, recovery teams and escalation paths. - Run continuity and recovery exercises at least annually, including at least one realistic scenario test. - Record lessons learned and track corrective actions to closure. 6. Evidence and records Keep the business impact analysis, recovery objectives, continuity and recovery plans, exercise records, test results, corrective actions and communication templates. 7. Review cadence This policy and the supporting plans are reviewed at least annually and after major incidents or significant business change. Owner: [role] Version: [x.y] Approved by: [name/role] Date: [date] ``` ## Change management policy - https://aestech.com.au/policy-templates/change-management-policy.md Use for ISO 27001 A.8.32, A.8.9, SOC 2 change management criteria, and PCI DSS requirement 6 change controls. Frameworks: ISO 27001, SOC 2, PCI DSS. Template body: ``` 1. Purpose This policy defines how changes to production systems, applications, infrastructure and configurations are requested, assessed, approved, tested, implemented and reviewed, so that changes do not introduce security or availability risk. 2. Scope This policy applies to all changes to production and security-relevant systems, including code deployments, infrastructure changes, configuration changes, database changes and changes to security controls. It applies to all employees and contractors who make such changes. 3. Policy statements - All changes to production must be recorded in a ticket or pull request before implementation. - Changes must describe the reason, the affected systems, the risk and the rollback plan. - Changes must be reviewed and approved by an authorised person other than the sole implementer, except for pre-approved standard changes. - Changes must be tested before release where practical. - Production, test and development environments must be kept separate. - Emergency changes may bypass normal lead time but must still be recorded, approved as soon as practical and reviewed afterwards. - Significant changes must be assessed for their effect on security controls and compliance scope. - Changes affecting customers or availability must include a communication and rollback plan. 4. Roles and responsibilities - The [Engineering Lead] owns the change process and the definition of standard changes. - Change requesters document and propose changes. - Approvers review risk and authorise changes. - Implementers carry out changes and confirm success or trigger rollback. 5. Procedures - Raise a change record with description, risk, test evidence and rollback plan. - Obtain the required review and approval before deployment. - Deploy through the approved pipeline and verify the outcome. - For emergency changes, record the change, gain expedited approval and complete a post-change review. - Maintain a list of pre-approved standard changes and review it periodically. 6. Evidence and records Keep change tickets and pull requests, approvals, test evidence, deployment records, rollback plans, emergency change reviews and the standard change list. 7. Review cadence This policy is reviewed at least annually and after major changes to the deployment process. Owner: [role] Version: [x.y] Approved by: [name/role] Date: [date] ``` ## Human resources security policy - https://aestech.com.au/policy-templates/human-resources-security-policy.md Use for ISO 27001 A.6.1 to A.6.6, A.6.8, SOC 2 Security, and personnel security controls. Frameworks: ISO 27001, SOC 2. Template body: ``` 1. Purpose This policy defines the security responsibilities and controls that apply to people before, during and after employment or engagement with the company, so that staff understand and meet their information security obligations. 2. Scope This policy applies to all employees and contractors throughout their relationship with the company, from recruitment to termination, including changes of role. 3. Policy statements - Background and identity verification appropriate to the role and to legal limits must be completed before access to sensitive systems is granted. - Employment and contractor agreements must include information security and confidentiality obligations. - New starters must receive security awareness training before or shortly after gaining access, and refresher training at least annually. - Access must be granted according to role and the access control policy, and adjusted promptly on role change. - On termination or end of engagement, access must be revoked within [x] hours and company assets must be returned. - A disciplinary process must apply to breaches of security policy, applied consistently and fairly. - Confidentiality obligations continue after employment ends where appropriate. 4. Roles and responsibilities - [HR] manages screening, agreements, onboarding and offboarding administration. - Hiring managers define role requirements and approve access needs. - IT provisions and revokes access in line with HR triggers. - The [Security Lead] owns security awareness training and the security elements of the disciplinary process. 5. Procedures - Complete pre-employment screening proportionate to the role. - Issue agreements that include security and confidentiality terms. - Run onboarding that includes security training and acknowledgement of key policies. - Trigger access changes for joiners, movers and leavers through a defined workflow. - Recover assets and confirm access removal at offboarding. - Track training completion and follow up non-completion. 6. Evidence and records Keep screening records, signed agreements and acknowledgements, training completion records, joiner, mover and leaver tickets, asset return records and disciplinary records where applicable. 7. Review cadence This policy is reviewed at least annually and after changes to legal or regulatory requirements. Owner: [role] Version: [x.y] Approved by: [name/role] Date: [date] ``` ## Physical and environmental security policy - https://aestech.com.au/policy-templates/physical-and-environmental-security-policy.md Use for ISO 27001 A.7.1 to A.7.14, SOC 2 Security, and PCI DSS requirement 9 physical access controls. Frameworks: ISO 27001, SOC 2, PCI DSS. Template body: ``` 1. Purpose This policy defines how company facilities, equipment and physical media are protected against unauthorised access, damage, theft and environmental threats. 2. Scope This policy applies to all company premises, secure areas, equipment, media and the facilities of providers that host company systems. Where the company is fully remote, the requirements apply to data centre and cloud provider facilities and to home working arrangements. 3. Policy statements - Access to offices and secure areas must be restricted to authorised people and controlled by suitable measures such as locks, access cards or reception controls. - Visitors must be identified, recorded and supervised in sensitive areas. - Physical access rights must be reviewed periodically and revoked promptly when no longer needed. - Equipment must be protected from theft, damage and unauthorised use, and must not be left unattended in insecure locations. - A clear desk and clear screen practice applies to confidential information. - Media and equipment containing data must be securely sanitised or destroyed before disposal or reuse. - Environmental controls such as power protection, fire detection and suitable cooling must protect critical equipment, primarily through the hosting provider. - Where systems are hosted with cloud or data centre providers, physical security must be confirmed through provider attestations. 4. Roles and responsibilities - The [Facilities or Office Manager] manages premises access and visitor controls. - IT manages equipment, media disposal and asset tracking. - The [Security Lead] reviews physical controls and provider attestations. - All staff follow clear desk, clear screen and visitor handling rules. 5. Procedures - Maintain an access list for offices and secure areas and review it periodically. - Record and supervise visitors. - Track equipment and media as assets and record secure disposal. - Obtain and review physical security attestations from hosting providers at least annually. - Define home working security expectations for remote staff. 6. Evidence and records Keep access lists and reviews, visitor logs, asset and media inventories, secure disposal records, provider attestations and exception approvals. 7. Review cadence This policy is reviewed at least annually and after changes to premises or hosting arrangements. Owner: [role] Version: [x.y] Approved by: [name/role] Date: [date] ``` ## Data breach response policy - https://aestech.com.au/policy-templates/data-breach-response-policy.md Use for ISO 27001 A.5.24 to A.5.28, SOC 2 incident handling, privacy notification, and PCI DSS requirement 12.10. Frameworks: ISO 27001, SOC 2, PCI DSS. Template body: ``` 1. Purpose This policy defines how the company responds to a suspected or confirmed data breach involving personal, customer, cardholder or other sensitive data, including assessment, containment, notification and review. It complements the incident response policy with breach-specific notification duties. 2. Scope This policy applies to any event that may have resulted in unauthorised access to, disclosure of, loss of or alteration of personal or sensitive data, whether caused internally, by a supplier or by an external attacker. 3. Policy statements - Any suspected data breach must be reported immediately through the incident channel. - The company must assess whether personal or sensitive data was involved and the likely harm to affected individuals. - Containment must take priority, while preserving evidence for investigation. - The company must determine its notification obligations to regulators, affected individuals, customers, card brands and acquiring banks, and the applicable timeframes. - Where notification to a regulator is required, it must be made within the legally required timeframe, for example without undue delay and within [72] hours of becoming aware where that applies. - Affected individuals must be notified where required, with clear information on the breach and recommended actions. - All breach decisions, assessments and communications must be documented. - A post-breach review must identify root cause and corrective actions. 4. Roles and responsibilities - The [Incident Manager] coordinates the overall response. - The [Data Protection Lead or Legal] determines notification obligations and timeframes. - The [Communications Lead] manages internal and external messaging. - Executive management approves regulatory and customer notifications. 5. Procedures - Triage the report and confirm whether sensitive data is involved. - Contain the breach and preserve evidence. - Assess scope, data categories, number of affected individuals and likely harm. - Decide and execute required notifications within the applicable timeframes. - Maintain a record of the breach and all decisions. - Hold a post-breach review and track corrective actions to closure. 6. Evidence and records Keep the breach record, assessment of harm, notification decisions and content, regulator and customer correspondence, timelines, root cause analysis and corrective actions. 7. Review cadence This policy is reviewed at least annually and after any significant breach or change to notification law. Owner: [role] Version: [x.y] Approved by: [name/role] Date: [date] ``` ## Mobile device and BYOD policy - https://aestech.com.au/policy-templates/mobile-device-and-byod-policy.md Use for ISO 27001 A.6.7, A.7.9, A.8.1, SOC 2 Security, and controls for remote and personally owned devices. Frameworks: ISO 27001, SOC 2. Template body: ``` 1. Purpose This policy defines the security requirements for mobile devices and for personally owned devices used to access company information, so that company data is protected regardless of who owns the device. 2. Scope This policy applies to all smartphones, tablets and personally owned computers used to access company email, systems or data, and to all employees and contractors who use such devices. 3. Policy statements - Access to company data from a personal device is permitted only where the device meets the minimum security requirements and the user accepts this policy. - Devices accessing company data must have a screen lock, a supported operating system and current security updates. - Company data on mobile and personal devices should be contained within managed apps or profiles where possible. - Company data must not be stored in unapproved personal cloud accounts or applications. - The company must be able to remotely remove company data, or the managed work profile, from a device that is lost, stolen or belongs to a leaver. - Jailbroken or rooted devices must not access company data. - Lost or stolen devices must be reported immediately. - Users must not disable required security controls on devices used for work. 4. Roles and responsibilities - The [IT Manager] defines minimum device requirements and manages enrolment. - IT administers mobile device management and remote wipe capability. - The [Security Lead] approves exceptions and reviews compliance. - Users keep their devices compliant and report loss or theft. 5. Procedures - Define the minimum security baseline for mobile and personal devices. - Enrol eligible devices in mobile device management or apply managed app controls. - Require users to accept the policy before access is granted. - Monitor compliance and restrict access for non-compliant devices. - Execute selective wipe of company data at offboarding or on loss. 6. Evidence and records Keep device enrolment and compliance reports, signed user acknowledgements, exception approvals, remote wipe records and lost-device incident tickets. 7. Review cadence This policy is reviewed at least annually and after changes to device management capability. Owner: [role] Version: [x.y] Approved by: [name/role] Date: [date] ``` ## Network security policy - https://aestech.com.au/policy-templates/network-security-policy.md Use for ISO 27001 A.8.20, A.8.21, A.8.22, A.8.23, SOC 2 Security, and PCI DSS requirements 1 and 4. Frameworks: ISO 27001, SOC 2, PCI DSS. Template body: ``` 1. Purpose This policy defines how company networks and network services are designed, controlled and monitored to protect the confidentiality, integrity and availability of information in transit. 2. Scope This policy applies to all company networks, cloud networks, virtual private clouds, firewalls, security groups, remote access services and connections to third parties. It applies to all systems connected to company networks. 3. Policy statements - Network access controls such as firewalls or security groups must restrict traffic to what is required, with default deny on inbound traffic. - Networks must be segmented to separate environments of different sensitivity, such as production, corporate and any cardholder data environment. - Inbound and outbound rules must be documented, justified and reviewed at least every [6] months. - Remote access to internal systems must use encrypted connections and multi-factor authentication. - Wireless networks must use strong encryption and must separate guest access from internal systems. - Data transmitted over public or untrusted networks must be encrypted in transit. - Connections to third parties must be controlled, documented and limited to required services. - Network changes must follow the change management policy. 4. Roles and responsibilities - The [Network or Infrastructure Lead] owns network architecture and firewall rule sets. - IT implements and maintains network controls and remote access. - The [Security Lead] reviews segmentation, rule sets and remote access. - System owners request and justify required network access. 5. Procedures - Maintain network diagrams and a record of firewall or security group rules with justifications. - Apply default deny and add rules only with documented business need. - Review rule sets at least every six months and remove unnecessary rules. - Configure remote access with encryption and multi-factor authentication. - Validate network segmentation periodically, especially around regulated environments. 6. Evidence and records Keep network diagrams, firewall and security group rule sets with justifications, rule review records, remote access configuration, segmentation validation results and change records. 7. Review cadence This policy is reviewed at least annually and rule sets at least every six months. Owner: [role] Version: [x.y] Approved by: [name/role] Date: [date] ``` ## Password and authentication policy - https://aestech.com.au/policy-templates/password-and-authentication-policy.md Use for ISO 27001 A.5.17, A.8.5, SOC 2 Security, and PCI DSS requirement 8 authentication controls. Frameworks: ISO 27001, SOC 2, PCI DSS. Template body: ``` 1. Purpose This policy defines the requirements for passwords, multi-factor authentication and other authentication methods used to access company systems, so that only authorised users can gain access. 2. Scope This policy applies to all user accounts, administrator accounts and service accounts on company systems, including cloud platforms, email, identity providers, production systems and code repositories. 3. Policy statements - Each user must have a unique individual account, and shared accounts are prohibited unless explicitly approved and monitored. - Passwords must meet a minimum length of at least [12] characters and be checked against common or breached password lists where supported. - Multi-factor authentication is required for email, identity providers, cloud consoles, production access, code repositories, finance systems and all remote and administrative access. - Where supported, the company should prefer phishing-resistant authentication such as hardware security keys or passkeys for privileged access. - Default and vendor-supplied credentials must be changed before a system is used. - Credentials must not be shared, reused across personal and work accounts, or stored in plaintext. - A company-approved password manager must be used to store work credentials. - Accounts must lock or rate-limit after repeated failed authentication attempts. - Service account credentials must be stored in a secret manager, restricted to required systems and rotated on a defined schedule or on compromise. 4. Roles and responsibilities - The [Security Lead] owns authentication standards and approves exceptions. - IT enforces password and multi-factor settings through the identity provider and system configuration. - System owners ensure their systems meet the authentication requirements. - Users protect their credentials and report suspected compromise. 5. Procedures - Configure password and multi-factor policies centrally where possible. - Enforce multi-factor authentication on all in-scope systems. - Provide and require use of an approved password manager. - Change all default credentials during system setup. - Store and rotate service account secrets through a secret manager. - Review authentication settings and exceptions periodically. 6. Evidence and records Keep identity provider configuration, multi-factor enforcement reports, password policy settings, secret manager records, default credential change records and exception approvals. 7. Review cadence This policy is reviewed at least annually and after material changes to identity systems. Owner: [role] Version: [x.y] Approved by: [name/role] Date: [date] ``` ## Malware protection policy - https://aestech.com.au/policy-templates/malware-protection-policy.md Use for ISO 27001 A.8.7, SOC 2 Security, and PCI DSS requirement 5 anti-malware controls. Frameworks: ISO 27001, SOC 2, PCI DSS. Template body: ``` 1. Purpose This policy defines how the company prevents, detects and responds to malicious software, including viruses, ransomware, spyware and malicious scripts, so that systems and data are protected from compromise. 2. Scope This policy applies to all company endpoints, servers, virtual machines, cloud workloads, email systems and web browsing, and to all employees and contractors who use company systems or access company data. 3. Policy statements - Approved endpoint protection software must be installed, enabled and kept current on all workstations and servers that support it. - Endpoint protection must include real-time scanning and, where available, behavioural detection and ransomware protection. - Signature and detection engine updates must be applied automatically and at least daily. - Users must not disable, bypass or uninstall malware protection, and administrative controls must prevent this on managed devices. - Email must be filtered for malicious attachments, links and spoofing before delivery to users. - Web filtering must block known malicious sites and unapproved high-risk file downloads where technically practical. - Software may only be installed from approved sources, and execution of unauthorised software should be restricted on managed devices. - Files received from external parties or downloaded from the internet must be scanned before use where scanning is not automatic. - Systems that cannot run endpoint protection must be identified and protected with compensating controls approved by the [Security Lead]. - Confirmed or suspected malware infections must be treated as security events under the incident response policy. 4. Roles and responsibilities - The [Security Lead] owns the malware protection programme, selects approved tooling and approves exceptions. - IT deploys and maintains endpoint protection, email filtering and web filtering, and monitors coverage. - System owners ensure their systems meet these requirements. - All users report suspected infections, suspicious emails and unexpected system behaviour immediately through [reporting channel]. 5. Procedures - Deploy endpoint protection through central management and enrol every eligible device. - Monitor the management console for coverage gaps, outdated agents and detections on a [daily or weekly] cadence. - On detection, isolate the affected device from the network, preserve logs, remove the malware or reimage the device, and reset credentials used on it where compromise is possible. - Verify that email and web filtering rules remain effective after major platform changes. - Review devices without protection and record compensating controls or remediation. 6. Evidence and records Keep endpoint protection coverage reports, update status, detection and quarantine logs, email filtering configuration and reports, incident tickets for infections, isolation and reimage records, and exception approvals. 7. Review cadence This policy is reviewed at least annually and after significant malware incidents or changes to protection tooling. Owner: [role] Version: [x.y] Approved by: [name/role] Date: [date] ``` ## Security awareness and training policy - https://aestech.com.au/policy-templates/security-awareness-and-training-policy.md Use for ISO 27001 A.6.3, SOC 2 Security awareness criteria, and PCI DSS requirement 12.6 training obligations. Frameworks: ISO 27001, SOC 2, PCI DSS. Template body: ``` 1. Purpose This policy defines how the company builds and maintains security awareness among its people, so that employees and contractors understand the threats relevant to their work, their obligations under company policies, and how to report security concerns. 2. Scope This policy applies to all employees, contractors and, where relevant, temporary staff who access company systems or information, from their start date until the end of their engagement. 3. Policy statements - All new starters must complete security awareness training before, or within [x] days of, being granted access to company systems. - All staff must complete refresher training at least annually. - Training content must cover, at minimum: phishing and social engineering, password and MFA practices, safe handling of confidential data, acceptable use, reporting of security events, and safe use of approved AI tools. - Training content must be updated when policies, threats or company tooling change materially. - Phishing simulations must be run at least [quarterly], with results used for education rather than punishment on a first failure. - Staff who fail repeated phishing simulations must receive targeted follow-up training. - Staff in roles with elevated risk, such as developers, administrators, finance and customer support, must receive additional role-specific training relevant to their duties, for example secure coding for developers. - Completion of required training is a condition of continued system access, and non-completion must be escalated to the staff member and their manager. - Awareness communications, such as alerts about current phishing campaigns, must be issued when relevant threats are identified. 4. Roles and responsibilities - The [Security Lead] owns the awareness programme, selects training content and runs phishing simulations. - [HR] ensures training is assigned at onboarding and tracks completion as part of the joiner process. - Managers ensure their teams complete required training on time. - All staff complete assigned training and apply it in their daily work. 5. Procedures - Assign onboarding training automatically when an account is created. - Schedule annual refresher training and send reminders before the due date. - Run phishing simulations, record results and deliver follow-up training to repeat clickers. - Review training content at least annually against current threats and policy changes. - Report completion rates and simulation results to management at least [quarterly]. 6. Evidence and records Keep training completion records with dates, training content versions, phishing simulation schedules and results, follow-up training records, escalation records for non-completion, and management reports. 7. Review cadence This policy and the training content are reviewed at least annually and after material changes to threats, tools or policies. Owner: [role] Version: [x.y] Approved by: [name/role] Date: [date] ``` ## Cloud services and outsourcing policy - https://aestech.com.au/policy-templates/cloud-and-outsourcing-policy.md Use for ISO 27001 A.5.19 to A.5.23, SOC 2 vendor management, and oversight of cloud and outsourced service providers. Frameworks: ISO 27001, SOC 2. Template body: ``` 1. Purpose This policy defines how cloud services and outsourced functions are selected, approved, operated and exited, so that the company retains control over its information and obligations when work or data is placed with an external provider. 2. Scope This policy applies to all cloud services, including infrastructure, platform and software as a service, and to any outsourced business or technology function that processes company or customer information or supports critical operations. 3. Policy statements - New cloud services and outsourcing arrangements must be approved by the [Security Lead or IT Manager] before company data is placed in them, and unapproved services must not be used for company work. - Due diligence proportionate to the risk tier must be completed before approval, covering security posture, certifications or assurance reports, data protection terms, subcontractors, incident notification commitments, financial viability and support arrangements. - Data residency must be confirmed before approval, and services storing regulated or customer data must keep it in [approved regions] unless an exception is approved. - A shared responsibility mapping must be documented for each significant cloud service, recording which security controls the provider operates and which the company must operate, such as identity, access, configuration, backup and monitoring. - Contracts must include confidentiality, security requirements, breach notification within [x] hours, audit or assurance rights appropriate to the service, and data return or deletion on termination. - Each approved service must have a named business owner and must be recorded in the cloud services register. - Company-managed controls on cloud services, such as MFA, least privilege access and logging, must be configured before production use. - An exit strategy must be documented for critical services, covering data export formats, migration options, notice periods and how long an exit would take. - Services must be reviewed on a cadence matched to their risk tier, and on contract renewal, major changes or provider incidents. 4. Roles and responsibilities - The [Security Lead] sets the assessment standard, performs or reviews due diligence and approves exceptions. - Business owners justify the need, own the relationship and initiate reviews and offboarding. - IT configures company-managed controls and manages access. - Legal or the contract owner ensures required terms are in place. 5. Procedures - Request approval for a new service through [ticketing system] with the intended data types and users. - Complete the due diligence checklist and assign a risk tier. - Record the service, owner, data types, residency and responsibility mapping in the register. - Review critical services at least annually, and confirm assurance reports remain current. - On exit, export data, confirm provider deletion in writing and remove integrations and access. 6. Evidence and records Keep the cloud services register, due diligence records, assurance reports, contracts and data processing terms, responsibility mappings, review records, exception approvals, exit plans and deletion confirmations. 7. Review cadence This policy is reviewed at least annually and after material changes to providers, regulations or company data flows. Owner: [role] Version: [x.y] Approved by: [name/role] Date: [date] ``` ## Asset management policy - https://aestech.com.au/policy-templates/asset-management-policy.md Use for ISO 27001 A.5.9, A.5.10, A.5.11, A.7.9 to A.7.14, SOC 2 Security, and PCI DSS asset inventory expectations. Frameworks: ISO 27001, SOC 2, PCI DSS. Template body: ``` 1. Purpose This policy defines how information and the assets that support it are identified, recorded, owned, handled, returned and disposed of, so that the company knows what it has, who is responsible for it, and that assets are protected throughout their life cycle. 2. Scope This policy applies to all assets associated with information and information processing, including hardware such as laptops, mobile devices, servers and removable media, software and SaaS subscriptions, cloud resources, information assets such as databases and repositories, and supporting services. It applies to all employees and contractors who are issued or handle company assets. 3. Policy statements - An inventory of assets must be maintained and kept accurate, recording at minimum the asset, its owner, its location or hosting, its classification and its status. - Every asset in the inventory must have a named owner responsible for its protection, appropriate handling and life cycle decisions. - Assets must be handled in accordance with the classification of the information they store or process, as defined in the information classification policy. - Company equipment must not be modified, lent or used in ways that compromise its security controls, and must be physically protected when off premises. - Removable media may be used only where approved, must be encrypted when carrying confidential data, and must be tracked while in use. - All company assets, including devices, media, access cards and documentation, must be returned on termination of employment or engagement, or when no longer required for the role. - Equipment and media containing company data must be securely sanitised or physically destroyed before disposal, resale, return to a lessor or reuse, using methods that prevent data recovery. - Disposal of assets must be recorded, and bulk or third-party destruction must be supported by a certificate of destruction. - Unaccounted-for assets must be investigated, and lost assets containing company data must be reported as security events. 4. Roles and responsibilities - The [IT Manager] maintains the asset inventory and manages issue, return and disposal of equipment. - Asset owners approve access to and handling of their assets and confirm inventory accuracy. - [HR] triggers asset return at offboarding and confirms completion with IT. - All staff take reasonable care of assigned assets and report loss, theft or damage immediately. 5. Procedures - Record new assets in the inventory at procurement or creation, and assign an owner. - Issue equipment to staff against a signed record of receipt. - Reconcile the inventory at least [annually] against device management and procurement records. - At offboarding, collect all assets, confirm return against the issue record and wipe or reassign devices. - Sanitise storage using secure erase, cryptographic erasure or physical destruction, and record the method, date and person responsible. 6. Evidence and records Keep the asset inventory, issue and return records, reconciliation results, sanitisation and disposal logs, certificates of destruction, lost asset incident tickets and exception approvals. 7. Review cadence This policy is reviewed at least annually and after significant changes to equipment, hosting or ways of working. Owner: [role] Version: [x.y] Approved by: [name/role] Date: [date] ``` ## ISMS internal audit procedure - https://aestech.com.au/policy-templates/isms-internal-audit-procedure.md How to plan and run internal ISMS audits under ISO 27001 clause 9.2, from programme to follow-up. Frameworks: ISO 27001. Template body: ``` 1. Purpose This procedure defines how [Company Pty Ltd] plans, conducts and follows up internal audits of the Information Security Management System (ISMS), so that management receives objective evidence that the ISMS conforms to ISO/IEC 27001:2022 and to our own requirements, and that it is effectively implemented and maintained. 2. Scope Applies to all processes, controls, teams and locations inside the ISMS scope statement, including outsourced processes for which [Company] retains responsibility. 3. Audit programme 3.1 The [ISMS Manager] maintains a rolling audit programme covering every ISMS clause and every applicable Annex A control at least once per [certification cycle, typically 3 years], with higher-risk areas audited at least annually. 3.2 Programme inputs: risk assessment results, incident history, prior audit findings, changes to systems or suppliers, and certification body feedback. 3.3 The programme records, for each audit: scope, criteria, method (interview, document review, technical sampling), auditor, and planned month. 4. Auditor independence and competence 4.1 Auditors must not audit their own work or areas they manage. Where the team is small, use a trained auditor from another function, a peer company arrangement, or an external contractor. 4.2 Auditors must have completed [internal auditor training / ISO 27001 lead auditor course] and be approved by the [ISMS Manager]. 5. Planning each audit 5.1 At least [10] business days before fieldwork, the auditor issues an audit plan stating scope, criteria (ISO 27001 clauses, Annex A controls, internal policies), interviewees, and evidence to be sampled. 5.2 Auditees confirm availability and pre-supply requested documents. 6. Fieldwork 6.1 Open with a short briefing confirming scope and method. 6.2 Gather objective evidence: interview staff, review records, observe practice, and sample system configurations. Record what was examined, not only conclusions. 6.3 Test that controls operate as described, not merely that documents exist. 7. Findings and reporting 7.1 Classify each finding as: major nonconformity, minor nonconformity, observation, or opportunity for improvement, with the criterion breached and the evidence. 7.2 Issue the audit report to the auditee and [top management] within [5] business days of fieldwork. 7.3 Nonconformities enter the corrective action process per the [Nonconformity and Corrective Action Procedure]. 8. Follow-up The auditor verifies completion and effectiveness of corrective actions by [agreed due dates] and records closure. Overdue actions are escalated to [management review]. 9. Roles and responsibilities [ISMS Manager]: owns the programme and this procedure. Auditors: plan, execute, report, verify closure. Auditees: provide access and evidence, own corrective actions. [Top management]: receives results, resources the programme. 10. Records Retain the audit programme, audit plans, evidence notes, reports and closure records for at least [3] years in [location]. 11. Review Review this procedure at least annually and after any certification audit. Owner: [ISMS Manager]. Version: [x.y]. Approved by: [name/role]. Date: [date]. ``` ## Management review procedure - https://aestech.com.au/policy-templates/management-review-procedure.md Runs the clause 9.3 management review, with a standing agenda, required inputs, outputs and action tracking. Frameworks: ISO 27001. Template body: ``` 1. Purpose This procedure defines how [Company Pty Ltd] top management reviews the ISMS at planned intervals, per ISO/IEC 27001:2022 clause 9.3, to confirm it remains suitable, adequate and effective, and to decide on changes and resources. 2. Scope Covers the full ISMS scope. Applies to [CEO, CTO, ISMS Manager, and heads of relevant functions]. 3. Cadence and attendance 3.1 Reviews are held at least [twice per year / quarterly], and additionally after a major incident, significant organisational change, or an adverse audit result. 3.2 Quorum requires [the CEO or delegate] plus the [ISMS Manager]. The [ISMS Manager] chairs and prepares the input pack, circulated at least [5] business days before the meeting. 4. Required inputs The input pack must address every clause 9.3.2 item: status of actions from previous reviews; changes in external and internal issues relevant to the ISMS; changes in interested party needs and expectations; feedback on security performance including nonconformities and corrective actions, monitoring and measurement results, audit results, and fulfilment of security objectives; feedback from interested parties; risk assessment results and risk treatment plan status; and opportunities for continual improvement. 5. Standing agenda 1. Actions from the previous review: status and overdue items 2. Changes to internal and external issues, and to interested party requirements 3. Security objectives: performance against metrics and targets 4. Internal and external audit results 5. Nonconformities, corrective actions and their effectiveness 6. Incidents, near misses and lessons learned since last review 7. Risk assessment update and risk treatment plan progress 8. Risk acceptance decisions requiring management sign-off 9. Supplier and third party security performance 10. Resources: budget, staffing, training needs 11. Opportunities for continual improvement 12. Decisions, new actions, owners and due dates 6. Outputs Recorded decisions must cover: continual improvement opportunities adopted, any needed changes to the ISMS (scope, policy, objectives, risk criteria), and resource decisions. Each action gets an owner and a due date. 7. Minutes and action tracking 7.1 The [ISMS Manager] issues minutes within [5] business days, capturing attendees, inputs considered, decisions and actions. 7.2 Actions are logged in the [action register / ticketing system] and tracked to closure; overdue actions open the next review. 8. Roles and responsibilities [Top management]: attends, decides, allocates resources. [ISMS Manager]: schedules, prepares inputs, chairs, records, chases actions. Function heads: supply input data for their areas. 9. Records Retain input packs, minutes and action logs for at least [3] years in [location]; these are primary evidence for clause 9.3 at certification audits. 10. Review Review this procedure annually. Owner: [ISMS Manager]. Version: [x.y]. Approved by: [name/role]. Date: [date]. ``` ## Nonconformity and corrective action procedure - https://aestech.com.au/policy-templates/nonconformity-and-corrective-action-procedure.md Handles clause 10.1 end to end: raising nonconformities, containment, root cause, corrective action and effectiveness checks. Frameworks: ISO 27001. Template body: ``` 1. Purpose This procedure defines how [Company Pty Ltd] reacts to nonconformities in the ISMS, corrects them, addresses their causes so they do not recur, and records the results, per ISO/IEC 27001:2022 clause 10.1. 2. Scope Applies to any failure to meet a requirement of ISO/IEC 27001, our own policies and procedures, legal or contractual security obligations, or planned control operation. Sources include internal and external audits, incidents, monitoring results, supplier reviews, and staff reports. 3. Raising a nonconformity (NC) 3.1 Anyone may raise an NC via [ticketing system / form / email to ISMS Manager]. 3.2 Each NC record states: what requirement was not met, the objective evidence, where and when it was found, and who raised it. 3.3 The [ISMS Manager] triages within [2] business days, assigns a unique ID (NC-[YYYY]-[nn]), a severity ([major/minor]) and an owner. 4. Immediate correction and containment 4.1 The owner takes action to control and correct the nonconformity and to deal with its consequences, for example disabling an exposed account, restoring a control, or notifying affected parties. 4.2 If the NC involves a security incident, invoke the [Incident Response Plan] in parallel; the NC record links to the incident record. 5. Root cause analysis 5.1 For every major NC, and for minor NCs at the owner discretion or where a pattern exists, evaluate the need for action to eliminate the cause. 5.2 Use a structured method such as [5 Whys / fishbone analysis], and check whether similar nonconformities exist or could occur elsewhere in the ISMS. 5.3 Record the root cause, distinguishing symptom (what happened) from cause (why the system allowed it). 6. Corrective action 6.1 Define actions proportionate to the effects of the NC, with owner and due date: [major NCs within 30 days, minor within 90 days, or as agreed]. 6.2 Update risk assessments, policies, training or the Statement of Applicability where the cause reveals a gap in them. 7. Effectiveness check After actions complete, the [ISMS Manager] or an independent reviewer verifies, after a suitable operating period of [30 to 90] days, that the NC has not recurred and the control now operates. Ineffective actions reopen the NC. 8. Register and reporting The [ISMS Manager] maintains an NC register with columns: ID, date raised, source, description, severity, owner, correction, root cause, corrective action, due date, effectiveness check result, closure date. Trends and open items are reported to every management review. 9. Roles and responsibilities All staff: report suspected NCs. NC owner: correction, root cause, actions. [ISMS Manager]: triage, register, verification, reporting. [Top management]: resources and escalation path for overdue majors. 10. Records Retain NC records and the register for at least [3] years in [location] as clause 10.1 evidence. 11. Review Review annually. Owner: [ISMS Manager]. Version: [x.y]. Approved by: [name/role]. Date: [date]. ``` ## Information risk management procedure - https://aestech.com.au/policy-templates/information-risk-management-procedure.md The clause 6.1.2/6.1.3 and 8.2/8.3 engine: risk identification, analysis scales, evaluation, treatment, acceptance and review. Frameworks: ISO 27001. Template body: ``` 1. Purpose This procedure defines how [Company Pty Ltd] identifies, analyses, evaluates and treats information security risks, per ISO/IEC 27001:2022 clauses 6.1.2, 6.1.3, 8.2 and 8.3, so that risk decisions are consistent, repeatable and produce comparable results over time. 2. Scope All information assets, processes, people, suppliers and technology within the ISMS scope statement. 3. Risk criteria 3.1 Likelihood scale (1 to 5): 1 Rare (less than once in 5 years), 2 Unlikely (once in 2 to 5 years), 3 Possible (once a year), 4 Likely (several times a year), 5 Almost certain (monthly or more). 3.2 Impact scale (1 to 5) considering confidentiality, integrity and availability: 1 Negligible, 2 Minor (limited internal disruption), 3 Moderate (customer impact or cost above [$10k]), 4 Major (regulatory report, cost above [$100k]), 5 Severe (existential, mass data breach). 3.3 Risk score = likelihood x impact. Acceptance threshold: scores of [6] or below may be accepted by the risk owner; [8 to 12] require [ISMS Manager] approval; above [12] require [top management] approval. 4. Risk identification 4.1 The [ISMS Manager] runs a full assessment at least annually and a targeted assessment on significant change (new system, supplier, market, or major incident). 4.2 Identify risks by considering assets and their owners, threats, vulnerabilities, incident history, audit findings and interested party requirements. Every risk gets a named risk owner. 5. Risk analysis and evaluation 5.1 Rate likelihood and impact using section 3 scales, taking existing controls into account (current risk). 5.2 Compare scores against the acceptance threshold and rank risks to produce a prioritised list for treatment. 6. Risk treatment 6.1 For each risk above threshold choose: modify (apply controls), retain (accept with approval), avoid (stop the activity), or share (insurance, outsourcing, contracts). 6.2 Where modifying, select controls, compare them against Annex A to confirm nothing necessary has been overlooked, and update the Statement of Applicability with inclusion and exclusion justifications. 6.3 Produce a risk treatment plan: risk ID, chosen option, controls, owner, due date, expected residual score. 6.4 Obtain risk owner approval of the plan and explicit acceptance of residual risks, recorded with name and date. 7. Risk register Maintain the register in [tool/spreadsheet] with columns: ID, asset or process, description, threat, vulnerability, likelihood, impact, score, owner, treatment option, controls, residual score, acceptance approver, next review date. 8. Monitoring and review Review the full register at least [quarterly]; report movements, new risks and overdue treatments to management review. Reassess any risk on relevant incident or control failure. 9. Roles and responsibilities [ISMS Manager]: method, facilitation, register. Risk owners: ratings, treatment decisions, acceptance. [Top management]: approves criteria and high risk acceptances. 10. Records Retain assessments, treatment plans and acceptance records for at least [3] years in [location]. 11. Review Review this procedure and the criteria in section 3 annually. Owner: [ISMS Manager]. Version: [x.y]. Approved by: [name/role]. Date: [date]. ``` ## Remote and hybrid working policy - https://aestech.com.au/policy-templates/remote-working-policy.md Use for ISO 27001 A.6.7, remote and hybrid work arrangements, home office security, and SOC 2 endpoint and access controls. Frameworks: ISO 27001, SOC 2. Template body: ``` 1. Purpose This policy defines the security requirements that apply when staff work away from company premises, including working from home, while travelling, and in public or shared spaces. It exists so that the confidentiality, integrity and availability of company and customer information does not depend on where the work happens. 2. Scope This policy applies to all employees, contractors and third parties who access company information or systems from any location outside company-controlled offices, using company-issued or approved personal devices. 3. Policy statements - Remote work is permitted only on devices that meet the requirements of the [endpoint and mobile device policy], including disk encryption, screen lock, endpoint protection and a supported operating system. - Home networks used for company work must have the router administrator password changed from the default, use WPA2 or WPA3 encryption, and have remote administration disabled. - Company information must be accessed only through approved tools and services listed in [approved tools register]. Personal email, personal cloud storage and unapproved messaging apps must not be used for company data. - In public or shared spaces, staff must use a privacy screen where practical, position screens away from overlooking, never leave devices unattended, and avoid discussing confidential matters where they can be overheard. - Public wifi may be used only with [company VPN or equivalent protection] enabled. Public charging cables and unknown USB accessories must not be used with company devices. - Confidential papers must not be printed at home or in public facilities unless approved by [role], and must be stored locked and destroyed by [cross-cut shredding or approved return process]. - Household members and other third parties must not use company devices or view company information. 4. Roles and responsibilities - Staff: comply with this policy, maintain their home working environment, and report issues. - Managers: confirm remote arrangements are appropriate for the role and data involved. - [IT or security lead]: maintain the approved tools register, VPN and device controls. 5. Procedures - New remote workers complete the [remote work checklist] before their first remote day. - Exceptions are requested through [ticketing system] and approved by [role]. - Lost or stolen devices, suspected compromise, or accidental disclosure while remote must be reported to [security contact] within [1 hour] of discovery. 6. Evidence and records Keep signed policy acknowledgements, remote work checklists, VPN and device management enrolment reports, exception approvals and incident tickets relating to remote work. 7. Review Owner: [role]. Reviewed at least annually and after any incident or material change to remote working arrangements. ``` ## Email and communications security policy - https://aestech.com.au/policy-templates/email-and-communications-policy.md Use for ISO 27001 A.5.14 and A.8.24, information transfer, encryption in transit, phishing response, and SOC 2 communication controls. Frameworks: ISO 27001, SOC 2. Template body: ``` 1. Purpose This policy defines how company email and other communication channels are used and protected, so that information sent inside and outside the company is transferred securely, phishing is handled consistently, and records are retained appropriately. 2. Scope This policy applies to all staff and contractors using company email, chat, video conferencing, file sharing and any other channel used to transmit company or customer information. 3. Policy statements - Company business must be conducted only through approved channels listed in [approved communications register], such as [company email, chat platform, video tool]. Personal accounts must not be used for company business. - Email in transit must be protected by TLS. Mail to domains that cannot support encrypted transport must not carry Confidential or Restricted information. - Confidential or Restricted content sent externally must use [message encryption feature, secure file share link, or approved portal] rather than plain attachments. Credentials, keys and card data must never be sent by email or chat. - Automatic forwarding of company mail to external addresses is prohibited. Manual forwarding of Confidential material outside the company requires a business need and, where required, approval from [role]. - Staff must verify unusual or high-risk requests received by email, such as payment changes or credential requests, through a second channel before acting. - Suspected phishing must not be replied to, clicked or forwarded to colleagues. It must be reported using [report button or security contact] immediately. Anyone who has clicked a link or entered credentials must report it at once; early reporting is never penalised. - Distribution lists and external sharing settings must be reviewed before sending bulk or sensitive communications, and recipients checked before sending. 4. Roles and responsibilities - Staff: use approved channels, apply encryption rules, report phishing. - [IT or security lead]: maintain mail security controls such as SPF, DKIM, DMARC, filtering and alerting, and run phishing awareness activities. - Managers: reinforce reporting culture and escalate repeated issues. 5. Procedures - Reported phishing is triaged by [security contact] within [4 hours]; confirmed campaigns trigger the [incident response policy]. - Requests to send Restricted data externally are raised in [ticketing system] for approval. - Mailbox retention follows the [retention schedule]; legal holds override deletion when instructed by [role]. 6. Evidence and records Keep phishing reports and triage records, mail security configuration exports, DMARC reports, forwarding rule audit results, external transfer approvals, retention settings and training completion records. 7. Review Owner: [role]. Reviewed at least annually and after significant phishing incidents or changes to communication platforms. ``` ## Clear desk and clear screen policy - https://aestech.com.au/policy-templates/clear-desk-and-clear-screen-policy.md Use for ISO 27001 A.7.7, physical protection of papers and screens, printing controls, and office and visitor area practices. Frameworks: ISO 27001. Template body: ``` 1. Purpose This policy defines the rules for keeping papers, removable media and screens free of exposed information when unattended, so that Confidential and Restricted information cannot be read, photographed or removed by unauthorised people. 2. Scope This policy applies to all staff, contractors and visitors in company offices, home offices, co-working spaces and any other location where company information is displayed or handled physically. 3. Policy statements - Screens must lock automatically after no more than [10] minutes of inactivity, and staff must lock screens manually with [shortcut] whenever leaving a device unattended, even briefly. - Desks must be cleared of papers, notebooks and removable media containing Internal, Confidential or Restricted information at the end of each day and whenever leaving the desk for an extended period. Such material must be stored in [lockable drawers or cabinets]. - Passwords, access codes and keys must never be written on notes, whiteboards or visible surfaces. - Printing of Confidential or Restricted documents must be collected immediately. Where available, [secure print release] must be used. Uncollected print jobs found at printers must be handed to [role] or destroyed. - Paper and media requiring disposal must go into [locked shred bins or a cross-cut shredder], never general waste or recycling. - Whiteboards and flip charts must be erased after meetings that involve Confidential information, and meeting room screens disconnected or cleared before leaving. - In visitor areas and meeting rooms visible to visitors, no Confidential material may be left on display. Visitors must be escorted and must not be left alone in work areas. - Screens in reception, shared or public-facing positions must be angled or fitted with privacy filters so that passers-by cannot read them. 4. Roles and responsibilities - Staff: follow clear desk and clear screen practices at all locations. - Managers: address repeated non-compliance within their teams. - [Office manager or security lead]: provide lockable storage, shred bins and privacy filters, and run periodic walkthroughs. 5. Procedures - [Role] performs a documented clear desk walkthrough at least [quarterly], recording findings and corrective actions. - Findings such as exposed documents or unlocked screens are logged in [ticketing system] and raised with the individual and their manager. - Screen lock timeouts are enforced centrally through [device management tool]. 6. Evidence and records Keep walkthrough checklists and findings, corrective action records, device management screen lock configuration reports, shredding or secure destruction certificates and policy acknowledgements. 7. Review Owner: [role]. Reviewed at least annually and after office moves or repeated findings. ``` ## Information security roles and responsibilities - https://aestech.com.au/policy-templates/information-security-roles-and-responsibilities.md Use for ISO 27001 A.5.2, A.5.3 and A.5.4, defining security roles, segregation of duties, management responsibilities, and SOC 2 organisational controls. Frameworks: ISO 27001, SOC 2. Template body: ``` 1. Purpose This policy defines and allocates information security roles so that every security responsibility has a named, accountable owner, conflicting duties are separated, and staff know who decides, who does the work and who must be informed. 2. Scope This policy applies to all employees, contractors and governance bodies of [Company Pty Ltd], and covers all activities within the ISMS scope. 3. Policy statements - Every control, asset, risk and policy in the ISMS must have a named owner recorded in [ISMS register]. Ownership follows the role, not the person, and transfers automatically on role change. - Duties must be segregated so that no single person can request, approve and implement the same high-risk change, or grant themselves privileged access. Where headcount makes separation impractical, [compensating monitoring or independent review] must be documented and approved by [role]. - Security responsibilities must be stated in employment contracts, position descriptions and supplier agreements. 4. Roles and responsibilities - [CEO or managing director]: ultimately accountable for information security; approves the information security policy, risk appetite and ISMS resourcing; is informed of all SEV1 incidents. - [CISO or security lead]: accountable for operating the ISMS; runs risk assessments, coordinates internal audits and management reviews, reports ISMS performance to leadership at least [quarterly], and is the escalation point for security decisions. - Asset owners: accountable for the protection of their assets; approve access, set classification, and accept or escalate risks affecting their assets. - Risk owners: accountable for individual risks in the [risk register]; decide treatment, track actions to closure and formally accept residual risk within delegated limits. - [IT lead or system administrators]: responsible for implementing technical controls, provisioning approved access and maintaining logging and backups; consulted on all changes affecting security. - Managers: responsible for ensuring their teams complete training, follow policies and report events; consulted on role changes affecting access. - All staff: responsible for following policies, protecting information they handle and reporting suspected security events immediately; informed of policy changes through [channel]. 5. Procedures - Escalation path: staff report to their manager or [security contact]; the [security lead] escalates to [CEO] for SEV1 incidents, risk acceptances above [threshold] and legal notification decisions. - The role register is updated within [5] business days of any appointment, departure or restructure. - Deputies are named in [register] for the [security lead] and each asset owner to cover absence. 6. Evidence and records Keep the role and ownership register, signed position descriptions, delegation and deputy records, segregation of duties matrix, risk acceptance records, management review minutes and escalation records. 7. Review Owner: [role]. Reviewed at least annually, after organisational changes and after any audit finding on accountability. ``` # SOC 2 (Service Organization Control 2) SOC 2 hub: https://aestech.com.au/soc-2/ SOC 2 is an audit report, not a certificate. A licensed CPA firm evaluates controls against the Trust Services Criteria and issues a Type I or Type II report. Trust Services Criteria: Security is mandatory; Availability, Processing Integrity, Confidentiality, and Privacy are selected based on customer commitments and system scope. Core SOC 2 evidence usually includes access control, incident response, vendor management, change management, backup, encryption, endpoint, secure development, risk, and monitoring records. Trust Services Criteria index: https://aestech.com.au/soc-2/criteria/ ## SOC 2 Security criterion - https://aestech.com.au/soc-2/criteria/security/ The security criterion is mandatory for every SOC 2 report. It covers protection against unauthorised access (both logical and physical). Every organisation that does SOC 2 includes this one. - Logical access security - Access authorisation - Role-based access - Onboarding and offboarding - Multi-factor authentication - Privileged access management - Network security - Data encryption (in transit and at rest) - Malware protection - Security event monitoring - Vulnerability management - Asset management and labelling ## SOC 2 Availability criterion - https://aestech.com.au/soc-2/criteria/availability/ Availability covers system availability, processing capacity, and disaster recovery. It matters most for SaaS companies that promise uptime SLAs to customers. - System monitoring - Capacity planning - Backup and recovery procedures - Disaster recovery plan - Environmental protection - Recovery time objectives - Redundancy and failover ## SOC 2 Processing Integrity criterion - https://aestech.com.au/soc-2/criteria/processing-integrity/ Processing integrity means system processing is complete, accurate, timely, and authorised. It is most relevant for organisations that process data on behalf of others (payment processors, data processors). - Input validation and processing - Output verification - Error handling - Reconciliation procedures - Data quality checks ## SOC 2 Confidentiality criterion - https://aestech.com.au/soc-2/criteria/confidentiality/ Confidentiality covers the protection of designated confidential information. It matters when you handle client data, trade secrets, or any information marked as confidential. - Confidential information identification and labelling - Encryption of confidential data - Access restrictions on confidential data - Data retention and disposal - NDA and confidentiality agreements - Information flow controls ## SOC 2 Privacy criterion - https://aestech.com.au/soc-2/criteria/privacy/ Privacy covers the collection, use, retention, disclosure, and disposal of personal information in line with the organisation's privacy notice and applicable laws (GDPR, CCPA, Australian Privacy Principles). - Notice and consent - Choice and consent mechanisms - Collection limitations - Data quality and integrity - Access and correction rights - Disclosure and consent - Retention and disposal - Privacy incident response Templates: https://aestech.com.au/soc-2/templates/ Software guide: https://aestech.com.au/best/best-soc-2-compliance-software/ Framework comparison: https://aestech.com.au/compare/soc-2-vs-iso-27001-vs-pci-dss/ ## What Is SOC 2? A Plain-English Guide - https://aestech.com.au/soc-2/overview/ SOC 2 is the trust report that most SaaS buyers ask for before they sign. Here is what it is, how it works, and what it takes to get one. SOC 2 is the trust report that most enterprise SaaS buyers require before they sign. It is not a certification - it is an audit report produced by a licensed CPA firm, based on the AICPA Trust Services Criteria. Unlike ISO 27001, SOC 2 is tailored to what you tell your customers. You select which Trust Services Criteria apply, and your report covers only those. Most SaaS companies start with Security plus Availability. This guide explains what SOC 2 is, how it differs from ISO 27001, and the practical steps to implement it. ### What SOC 2 actually is SOC 2 stands for Service Organization Control 2. It is an audit framework created by the AICPA (American Institute of Certified Public Accountants) that evaluates how organisations manage customer data. The audit covers the Trust Services Criteria (TSC): Security (mandatory), Availability, Processing Integrity, Confidentiality, and Privacy (all optional). Your report covers Security plus whichever optional criteria you selected. You do not get a certificate. You get a report from a licensed CPA firm that states whether your controls are suitably designed (Type I) and operating effectively over a period (Type II). Buyers almost always want Type II. ### SOC 2 vs ISO 27001 vs PCI DSS These three compliance frameworks serve different purposes and audiences. SOC 2 is a US-origin audit report focused on trust and data handling, widely demanded by SaaS buyers. ISO 27001 is an international certification for information security management systems, often required by government and enterprise procurement. PCI DSS is not a security standard in the same sense. It is a payment-card-industry requirement for anyone that handles cardholder data, with specific technical and operational requirements for protecting card data. Many companies end up pursuing all three, because they serve different buyers and different regulatory contexts. Compliance automation platforms like Vanta, Drata, and Secureframe help you run multiple frameworks from a single control base. FAQ: Is SOC 2 a certification? No. It is an audit report produced by a licensed CPA firm. You do not get a certificate. You get a report that you can share with customers and prospects. FAQ: How long does it take to get SOC 2? A Type I report can be completed in 4 to 8 weeks. A Type II report requires at least 6 months of operational evidence, so plan for 8 to 12 months total from start to finish. FAQ: How much does SOC 2 cost? Total cost typically ranges from $15,000 to $50,000+ depending on company size, scope, and the auditor. Compliance automation platforms reduce the internal effort significantly. ## SOC 2 Implementation Checklist: From Zero to Audit-Ready - https://aestech.com.au/soc-2/implementation-checklist/ A practical SOC 2 implementation checklist for SaaS companies. Every step from scoping to audit, with what you need, who owns it, and how automation platforms help. SOC 2 is the trust report that most enterprise SaaS buyers require before they sign. Unlike ISO 27001, it is not a standard you study from a book - it is a framework built around the AICPA Trust Services Criteria, and implementation looks very different depending on your scope and which criteria you choose. This checklist walks through the actual steps most SaaS companies follow to go from zero to audit-ready. It is practical, not theoretical: every step names what you need, who owns it, and how automation platforms (Vanta, Drata, Secureframe, Sprinto) reduce the manual work. SOC 2 has five Trust Services Criteria. Security is mandatory; the other four - Availability, Processing Integrity, Confidentiality, and Privacy - are optional and selected based on what you tell your customers. Most SaaS companies implement Security plus Availability, and sometimes Confidentiality. ### Phase 1: Decide scope and criteria Before writing a single policy, you need to answer two questions: what systems are in scope, and which Trust Services Criteria apply. For scope, pick the service or product you are getting SOC 2 for. If you sell a SaaS platform, that is usually the platform plus its supporting infrastructure (cloud accounts, CI/CD, customer support tools). Do not include the entire company unless you need to. For criteria, start with Security (the Common Criteria). Every SOC 2 report includes it. Then add Availability if you make uptime or performance commitments to customers. Add Confidentiality if you handle confidential data like NDAs or financial information. Privacy only if you process personal data and make privacy commitments. Write your scope and selected criteria in a one-page scoping document. This becomes your reference point for every decision that follows. ### Phase 2: Map the Trust Services Criteria to controls The AICPA publishes the Trust Services Criteria (TSC) - a detailed catalogue of requirements organized by criterion. For Security alone, there are roughly 6-11 categories with 30-60 specific requirements depending on how granular you read them. Map each applicable TSC requirement to a control in your organisation. Some controls already exist (MFA on admin accounts, encrypted backups). Others need to be created (an incident response plan, a vendor assessment process). Automation platforms come with pre-mapped control libraries that align TSC requirements to real-world controls. This saves hours of manual mapping. You still need to review and tailor them to your actual infrastructure. Document each control with: what it is, where it lives in your stack, who owns it, and what evidence proves it works. ### Phase 3: Write required policies SOC 2 auditors will look for written policies that demonstrate you run a structured security program. You do not need hundreds of policies - you need the ones that actually matter to your scope. Core policies for a typical SaaS SOC 2: Access Control Policy, Incident Response Policy, Risk Assessment Policy, Vendor Management Policy, Encryption/Data Protection Policy, and a System/Operations Policy. Most automation platforms provide templates for all of these. Write policies in plain English. Avoid copying the standard verbatim. Each policy should state what you do, who it applies to, and how it is enforced. Keep them living documents - update them when processes change. Get leadership sign-off on each policy. The auditor wants to see that someone with authority approved them, not just that they exist. ### Phase 4: Implement technical controls This is where you make the controls real in your infrastructure. The exact controls depend on your scope and criteria, but most SaaS companies need to implement: Identity and access: MFA on all accounts (especially admin and cloud), SSO if possible, role-based access control, offboarding procedures that revoke access within 24 hours. Infrastructure security: encryption at rest and in transit, vulnerability scanning, patch management, secure CI/CD pipelines, infrastructure as code where possible. Monitoring and logging: centralized logging, alerting on security events, log retention (typically 90 days minimum, 1 year preferred), intrusion detection. Data protection: backup and restore testing, data classification, encryption of sensitive data, secure key management. Automation platforms connect directly to your cloud provider (AWS, GCP, Azure), identity provider, and code repositories to verify these controls automatically - no manual screenshots. ### Phase 5: Run the program for an observation period SOC 2 is not a point-in-time audit. The auditor needs to see that your controls operate consistently over time. Most Type I reports cover a point in time; Type II (the one buyers actually want) covers a period, typically 3 to 12 months. During the observation period, your automation platform continuously monitors controls and collects evidence. You will see failures - a new team member without MFA, an unpatched server, an overly permissive IAM role. Fix them promptly and document the remediation. This is also when you run your first internal audit. Test a sample of controls, interview team members, and verify that policies are being followed in practice, not just on paper. Hold quarterly management reviews. Leadership should review the control status, any exceptions, and any changes to scope or criteria. ### Phase 6: Select an auditor and prepare for the audit Choose an auditor (a CPA firm licensed to perform SOC 2 audits) early - good auditors book months in advance. Get quotes from 2-3 firms and compare their experience with companies of your size and industry. Before the audit starts, do a readiness assessment. Many automation platforms offer this, or you can hire a consultant for a pre-audit review. The goal is to find and fix major issues before the auditor does. Prepare your evidence repository. Your automation platform should have everything organized and tagged by control. Make sure every control has current evidence - expired certificates, outdated screenshots, and missing logs are the most common auditor findings. Brief your team. Everyone should know what SOC 2 is, why it matters, and what the auditor might ask them. Most questions are straightforward: "Do you have MFA?" "What happens when someone leaves?" "How do you handle security incidents?" ### Phase 7: The audit and remediation The auditor will review your system description, test your controls, and examine evidence. For a Type II report, they will test a sample of control operations across the observation period. You will receive a report with opinions on each Trust Services Criteria. Most companies get unqualified opinions (clean) on Security. Exceptions may appear for controls that had gaps during the period - this is normal and not fatal. If the auditor finds exceptions, you will have a remediation plan to submit. Address each one with a specific action, owner, and timeline. Follow-up audits verify that remediation is complete. Once the report is issued, share it with customers, prospects, and your sales team. A SOC 2 report is a sales asset as much as it is a compliance deliverable. FAQ: How long does SOC 2 implementation take? From start to a Type II report, most SaaS companies take 6 to 12 months. The observation period alone is 3-12 months. Automation platforms can get you audit-ready in 2-3 months by handling evidence collection and control monitoring. FAQ: Do I need a consultant to implement SOC 2? Not if you use an automation platform. Platforms like Vanta, Drata, and Secureframe guide you through every step. Consultants are helpful for complex environments or if you need help with the system description and auditor coordination. FAQ: What is the difference between SOC 2 Type I and Type II? Type I is a point-in-time assessment: do your controls exist at a specific date? Type II covers a period (usually 3-12 months): do your controls operate effectively over time? Buyers almost always want Type II. FAQ: How much does SOC 2 cost? Expect $15,000-$50,000+ total. The automation platform is $10,000-$30,000/year, the auditor is $5,000-$20,000+, and internal effort is significant. The cost drops dramatically after the first certification because ongoing monitoring is automated. FAQ: Can I get SOC 2 with a small team? Yes. The requirements scale with your scope, not your headcount. A 5-person SaaS company can get SOC 2 - the controls just need to be appropriate for your size and risk profile. Automation platforms are especially valuable for small teams. FAQ: Is SOC 2 a one-time thing? No. You need annual surveillance audits to maintain the report. Your automation platform handles the continuous monitoring; the auditor reviews annually. SOC 2 is a continuous program, not a project. ## How Much Does SOC 2 Cost? (2026 Breakdown) - https://aestech.com.au/soc-2/cost/ SOC 2 costs break down into software, auditor fees, consultancy, and internal time. Here is the full 2026 cost breakdown for startups and mid-market companies. If you are evaluating SOC 2 compliance, the first question is almost always: how much will it cost? The answer depends on your company size, scope, and which Trust Services Criteria you choose, but most SaaS companies fall into one of two buckets. A small startup with a narrow scope typically spends $15,000 to $50,000 total for a Type I report. A mid-market company with broader scope and Type II certification usually pays $30,000 to $100,000 or more. These ranges include software, auditor fees, consultancy, and the internal team time that is often overlooked. ### Total cost ranges by company size Small startup (up to 50 employees, single product, Security criterion only): $15,000 to $50,000. This covers a Type I report, which is the fastest and cheapest path. Many startups use this as a stepping stone before investing in Type II. Mid-market (50 to 500 employees, multiple products, Security plus Availability or Confidentiality): $30,000 to $100,000+. Type II reports are the expectation for enterprise buyers, and they require six to twelve months of operational evidence, which adds cost. Large enterprise (500+ employees, complex infrastructure, multiple criteria): $100,000+. These engagements often involve multiple business units, extensive custom controls, and larger auditor teams. The biggest cost variable is scope. A narrow scope (one product, a few systems) keeps costs down. A broad scope (entire company, all products) multiplies the work. ### Cost breakdown: software Compliance automation platforms are the biggest recurring cost. Vanta, Drata, Secureframe, and Sprinto all use custom pricing based on employee count and scope, but typical annual costs are: Small startup: $10,000 to $20,000 per year. These platforms typically start around $5,000 to $10,000 annually for small teams and scale with headcount. Mid-market: $20,000 to $60,000 per year. As employee count and system count grow, the platform fee increases. Some platforms also charge per framework if you run multiple standards. This is the one cost that automation platforms directly reduce. Without a platform, you spend far more on manual evidence collection and control monitoring. The platform pays for itself for most teams above 15 to 20 employees. ### Cost breakdown: auditor fees The auditor is a separate cost from the software platform. A licensed CPA firm conducts the audit and issues the SOC 2 report. Auditor fees depend on the scope, complexity, and whether you choose a Big 4 firm or a mid-tier boutique. Small startup Type I: $8,000 to $15,000. The auditor reviews your control design at a point in time. This is a one-time fee. Small startup Type II: $15,000 to $25,000. The auditor tests operating effectiveness over six to twelve months. Mid-market Type II: $25,000 to $50,000+. More systems, more controls, and more evidence to review means higher fees. Big 4 firms (Deloitte, PwC, EY, KPMG) typically charge at the top of these ranges or above. Tip: mid-tier firms like BDO, RSM, and Crowe often deliver comparable quality at lower fees. The SOC 2 standard is the same regardless of which licensed CPA firm issues the report. ### Cost breakdown: consultancy Consultancy is optional but common. Most companies do not have an in-house compliance expert, so they hire a consultant to help with scoping, gap analysis, and audit readiness. Light touch (scoping review and gap analysis): $5,000 to $15,000. A consultant reviews your current state and produces a remediation plan. Full engagement (end-to-end guidance through the audit): $15,000 to $40,000. The consultant stays involved through implementation and the audit itself. If you use a compliance automation platform, the built-in guidance and support often reduce or eliminate the need for external consultancy. Drata and Vanta, for example, include dedicated customer success teams that walk you through the process. ### Cost breakdown: internal time This is the most overlooked cost. Even with a platform and a consultant, your engineering, security, and operations teams spend significant time implementing controls, collecting evidence, and responding to auditor requests. Small startup: 200 to 400 hours over the first six months. That is roughly one person-quarter for a small team. The bulk of the time goes to technical control implementation (MFA, encryption, access reviews) and writing policies. Mid-market: 500 to 1,000+ hours. More systems mean more controls to implement and monitor. Cross-functional coordination across engineering, HR, and operations adds overhead. At an all-in cost of $150 to $250 per hour for engineering time, this internal effort can add $30,000 to $250,000 to the total cost. Automation platforms dramatically reduce this by collecting evidence automatically and providing guided workflows. ### How to reduce SOC 2 costs Narrow your scope. Only include systems and processes that are actually required by your customers. A focused scope is the single biggest cost reducer. Choose a mid-tier auditor. The SOC 2 report means the same thing whether issued by a Big 4 firm or a regional CPA practice. Save $10,000 to $30,000 by going boutique. Use a compliance automation platform. The upfront software cost is real, but the reduction in internal time and consultancy fees usually makes it the best ROI line item. Platforms like Vanta, Drata, Secureframe, and Sprinto automate evidence collection, control monitoring, and policy management. Start with Type I. A Type I report proves your controls are designed correctly and can be shared with early buyers while you build toward Type II. It is faster, cheaper, and gets you revenue-generating deals sooner. Leverage existing controls. If you already run ISO 27001, GDPR, or HIPAA programs, many of your controls already map to SOC 2. Do not start from scratch. Do not over-invest in policies. SOC 2 auditors want to see written policies, but you do not need a 200-page security manual. Five to eight core policies cover the vast majority of requirements. ### Software options by budget tier Every compliance automation platform can deliver a SOC 2 report. The differences are in user experience, integrations, support quality, and pricing model. Here is how the main options compare: Premium tier ($20K+ per year): Vanta and Drata. Both are market leaders with the broadest integrations and the most mature control libraries. Best for teams that want the smoothest experience and do not want to manage the process manually. Vanta has the strongest brand recognition among enterprise buyers. Mid tier ($10K to $20K per year): Secureframe and Sprinto. Secureframe offers guided implementation with hands-on support, which is valuable for first-time compliance teams. Sprinto is popular with companies that want a modern platform with strong multi-framework support. Budget tier ($5K to $10K per year): Thoropass. Thoropass positions itself as the affordable option, pairing automation with its own audit capability. Good for very small teams or startups that need SOC 2 on a tight budget. All of these platforms reduce the total cost of compliance by cutting internal effort. The platform fee is almost always less than the internal time it would take to do the work manually. FAQ: How much does SOC 2 cost for a small startup? A small startup with a narrow scope typically spends $15,000 to $50,000 for a Type I report. This includes the compliance platform ($10K to $20K), auditor fees ($8K to $15K), and internal team time. A Type II report adds another $10K to $25K in auditor fees plus six months of ongoing monitoring. FAQ: How much does SOC 2 cost for a mid-market company? Mid-market companies typically spend $30,000 to $100,000+ for a Type II report. The range depends on employee count, number of systems in scope, and whether you need additional Trust Services Criteria beyond Security. FAQ: Can I do SOC 2 without a compliance platform? Yes, but it is significantly more expensive in internal time. Without a platform, your team manually collects evidence, monitors controls, and manages policies. The platform fee usually pays for itself through reduced engineering and security hours. FAQ: What is the cheapest way to get SOC 2? Narrow your scope to a single product and the Security criterion, use a budget platform like Thoropass, hire a mid-tier auditor, and leverage existing controls. This can bring a Type I report down toward $15,000 total. FAQ: Do I need a consultant for SOC 2? No, but it helps if you have no compliance experience. Compliance automation platforms include built-in guidance that covers most of what a consultant provides. Consider a consultant only if your scope is complex or you need to move fast. FAQ: How much does a SOC 2 auditor cost? Auditor fees range from $8,000 to $50,000+ depending on report type (Type I vs Type II), scope, and firm. Mid-tier firms charge $8,000 to $25,000 for Type I and $15,000 to $50,000 for Type II. Big 4 firms charge more. ## SOC 2 Type 1 vs Type 2: Which Report Do You Need? - https://aestech.com.au/soc-2/type-1-vs-type-2/ A SOC 2 Type 1 report tests control design at a point in time; a Type 2 tests control operation over a period. Here is how to choose. SOC 2 comes in two flavours, Type 1 and Type 2, and buyers and auditors mean different things by each. Choosing the wrong one wastes months and money. In short: a Type 1 report says your controls are designed correctly at a single moment; a Type 2 report says they actually operated effectively over a period of time. Most enterprise customers want Type 2. ### What a Type 1 report covers A SOC 2 Type 1 evaluates whether your controls are suitably designed to meet the Trust Services Criteria as of a specific date. It is a point-in-time snapshot. It is faster and cheaper to obtain, which makes it a reasonable first step, but it does not prove the controls work consistently in practice. ### What a Type 2 report covers A SOC 2 Type 2 evaluates whether those same controls operated effectively over an observation period, commonly three to twelve months. Because it tests evidence across time, it is far more meaningful to buyers, and it is the report most enterprise procurement teams actually ask for. ### How to choose If you need something quickly to unblock a deal, a Type 1 can buy time while you build toward Type 2. Many companies do Type 1 first, then a Type 2 covering the following period. If you can wait for the observation window, going straight to Type 2 avoids paying an auditor twice and gives customers the report they prefer. ### How long each takes A Type 1 can often be completed within a few weeks of finishing readiness work. A Type 2 adds the observation period on top, so plan for several months end to end. Compliance-automation platforms shorten the readiness and evidence-collection work that dominates both timelines. FAQ: Is Type 2 always better than Type 1? For proving trust to customers, yes, it tests controls over time. Type 1 is mainly useful as a faster first step. FAQ: Can I skip Type 1 and go straight to Type 2? Yes, many companies do. It avoids paying for two audits, provided you can wait for the observation period. FAQ: How long is the Type 2 observation period? Commonly three to twelve months; three to six months is typical for a first Type 2. ## The Five SOC 2 Trust Services Criteria, Explained - https://aestech.com.au/soc-2/trust-services-criteria/ SOC 2 is built on five Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Security is always required. Every SOC 2 report is scoped against the Trust Services Criteria, or TSC. Understanding them tells you exactly what your audit will and will not cover. There are five criteria. Security (the Common Criteria) is mandatory in every SOC 2; the other four are optional and chosen based on what you promise customers. ### Security (the Common Criteria) Security is the only mandatory criterion and underpins all the others. It covers protection of systems and data against unauthorised access, covering access controls, change management, risk management, and monitoring. If a SOC 2 report mentions only one criterion, it is almost always Security. ### Availability Availability addresses whether systems are available for operation and use as committed, think uptime commitments, monitoring, incident response, and disaster recovery. Include it if customers depend on your uptime or you make availability commitments in contracts or SLAs. ### Processing Integrity Processing Integrity covers whether system processing is complete, valid, accurate, timely, and authorised. It matters most for systems that process transactions or critical data on a customer’s behalf. ### Confidentiality and Privacy Confidentiality covers protection of information designated as confidential (for example, customer business data under NDA). Privacy covers how you collect, use, retain, disclose, and dispose of personal information in line with your privacy notice. Add these when your product handles confidential or personal data accordingly. FAQ: Which Trust Services Criteria are required? Only Security (the Common Criteria) is mandatory. The other four are optional and selected based on your commitments. FAQ: Should I include all five? Not necessarily. More criteria mean more controls and cost. Include only those relevant to what you promise customers. FAQ: What is the difference between Confidentiality and Privacy? Confidentiality protects information designated confidential; Privacy specifically governs personal information handling. ## SOC 2 Readiness Checklist: From Zero to Audit - https://aestech.com.au/soc-2/readiness-checklist/ A practical, ordered checklist to get from no compliance program to a SOC 2 audit: scope, gap assessment, controls, evidence, auditor, and observation period. Most SOC 2 delays come from doing the steps out of order. This checklist puts them in the sequence that actually works. The work splits into readiness (getting controls and evidence in place) and the audit itself (performed by an independent CPA firm). Readiness is where automation tools earn their keep. ### 1. Define scope and pick Type Decide which Trust Services Criteria apply and which systems, products, and teams are in scope. Choose Type 1 or Type 2 based on your timeline and what customers require. Tighter scope means less work, do not include criteria or systems you do not need to. ### 2. Run a gap assessment Compare your current controls against the criteria to find gaps. A compliance platform or a readiness consultant can map this quickly. ### 3. Implement controls and policies Close the gaps: access controls, change management, risk assessment, vendor management, incident response, and the supporting policies. Assign owners for each. ### 4. Collect evidence continuously Auditors want evidence that controls operate, not just exist. Automating evidence collection from your cloud, identity, and ticketing systems removes most of the manual burden, especially for a Type 2 observation period. ### 5. Engage an auditor and complete the observation period SOC 2 reports are issued by licensed CPA firms, not the software vendor. Select an auditor, run the Type 2 observation period, then complete fieldwork and receive the report. FAQ: Do compliance tools issue the SOC 2 report? No. They automate readiness and evidence; an independent CPA firm performs the audit and issues the report. FAQ: How long does SOC 2 readiness take? Often a few weeks to a few months depending on starting maturity, plus the Type 2 observation period. FAQ: What is the most time-consuming part? Evidence collection over time. Automating it from your existing systems saves the most effort. ## SOC 2 Evidence Collection: What Auditors Actually Want - https://aestech.com.au/soc-2/evidence-collection/ SOC 2 audits live and die on evidence. Here is what auditors sample, why screenshots fall short, the most common evidence rejections, and how automation changes the workload. A SOC 2 audit is ultimately an exercise in evidence. The auditor does not take your word that access reviews happen or that offboarding revokes accounts; they ask for proof, and for a Type II report they ask for proof spread across the whole observation period. Evidence collection is where most of the internal hours go and where most first-time audits stumble. Understanding what auditors sample, what makes evidence acceptable, and where manual collection breaks down will save weeks of rework and awkward audit-season scrambles. ### What auditors sample and why For a Type II report, auditors test that controls operated throughout the period, and they do it by sampling. For a recurring control such as user access reviews they pick a sample of occurrences across the period; for event-driven controls such as onboarding, offboarding, or change management they select a sample of the events, for example fifteen of the two hundred production changes, and ask for the evidence trail on each. This sampling approach has a sharp consequence: a control that ran for ten months but lapsed for two produces exceptions, because samples land in the gap. You cannot backfill operating evidence after the fact. The discipline is to keep evidence flowing continuously, not to assemble it in the fortnight before fieldwork. ### Screenshots vs automated evidence Manual screenshots are the traditional currency of SOC 2 evidence: a picture of the MFA setting, the firewall rule, the access list. They work, but they are point-in-time by nature, expensive to produce at sample volume, and easy to get wrong, for example missing the timestamp or the account context that proves when and where the screenshot was taken. Automated evidence comes from API integrations that pull configuration and activity data directly from your cloud provider, identity provider, and code repositories on a schedule. It is timestamped, consistent, and covers the whole period rather than the day someone remembered to capture it. Auditors increasingly prefer it because it is harder to stage and easier to verify, and for a Type II observation window it is the only sane way to show continuous operation. ### Common evidence rejections The most frequent rejects are mundane: screenshots without visible dates or system context, evidence dated outside the observation period, exports that show a policy exists but not that anyone followed it, and population lists that do not match the sample the auditor asked for, which suggests an incomplete inventory. The other classic failure is evidence that contradicts itself, for example an offboarding ticket closed on the fifth of the month while the access log shows the account alive until the twentieth. Auditors cross-check. Before submitting anything, verify the evidence tells one consistent story, and where there was a genuine control gap, disclose it with the remediation rather than hoping the sample misses it. ### How automation platforms change the workload Compliance automation platforms such as Secureframe, Vanta, and Drata connect to your stack and collect the bulk of technical evidence continuously: user lists, MFA status, encryption settings, vulnerability scan results, change logs. They map that evidence to controls and flag failures as they happen, which turns audit preparation from an archaeology project into a review. They do not remove the human element entirely. Policies still need approval, access reviews still need a person to attest, and process evidence such as board minutes or vendor assessments still needs uploading. A realistic expectation is that automation covers the majority of technical evidence and leaves a manageable manual remainder, which is precisely the trade that makes a Type II sustainable for a small team. FAQ: How much evidence does a SOC 2 audit require? It depends on scope and control count, but expect the auditor to request evidence for every in-scope control, with samples across the observation period for a Type II. Typical requests run to hundreds of individual evidence items for a first audit. FAQ: Are screenshots acceptable SOC 2 evidence? Yes, if they show the system, the setting, the account context, and a date. But they are point-in-time and labour-intensive at sample volume, so most teams move to automated, API-collected evidence for anything recurring. FAQ: Can I collect evidence after the observation period ends? Configuration that still exists can be captured late, but operating evidence cannot be recreated: if a control did not run during the period, no after-the-fact document fixes it. Continuous collection during the period is the only reliable approach. # ISO 42001 (ISO/IEC 42001:2023 AI management system) ISO 42001 is the AI management system standard for organisations that develop, provide, or use AI systems. It helps teams govern AI risk, accountability, data, lifecycle controls, and continual improvement. ## Management-system requirements, clauses 4 to 10 ### Clause 4: Context of the organization - https://aestech.com.au/iso-42001/requirements/context-of-the-organization/ Define why AI matters to the organisation, who is affected by it, and what parts of the business sit inside the AI management system. - List internal and external issues that affect AI governance, including regulation, customer expectations, product strategy, data access, model suppliers, and risk appetite. - Identify interested parties such as customers, users, employees, regulators, partners, model providers, and people affected by AI outputs. - Set the AIMS scope by business unit, product, geography, AI system type, and third-party dependency. - Create an AI system inventory so the scope is tied to real systems rather than abstract policy language. - Map each AI system to owner, intended use, user group, data sources, model provider, risk tier, and monitoring needs. Evidence: AIMS scope statement; AI system inventory; Interested-party register; AI context and obligations register; Boundary diagram for in-scope AI systems. ### Clause 5: Leadership - https://aestech.com.au/iso-42001/requirements/leadership/ Make senior leadership accountable for responsible AI, policy approval, role assignment, and integration with business processes. - Approve an AI policy that defines acceptable use, prohibited use, escalation paths, and decision authority. - Name an executive owner for the AI management system and assign operational owners for AI risk, data, security, legal, product, and model operations. - Set up an AI governance forum with the authority to approve high-impact AI use cases and stop unsafe deployments. - Define who can approve new AI systems, material model changes, training data changes, and exceptions to AI policy. - Ensure AI objectives are not only technical goals, but include risk, transparency, human oversight, and stakeholder protection. Evidence: Approved AI policy; AI governance charter; Role descriptions or RACI; Steering committee minutes; Approval records for AI use cases. ### Clause 6: Planning - https://aestech.com.au/iso-42001/requirements/planning/ Plan how the organisation will assess AI risks and opportunities, set measurable objectives, and manage changes to the AIMS. - Define an AI risk assessment method that covers harm, bias, privacy, safety, security, reliability, explainability, misuse, and legal impact. - Run an AI impact assessment for systems that affect people, customers, regulated decisions, safety, or material business outcomes. - Maintain a risk treatment plan that links each risk to controls, accountable owners, due dates, and residual risk approval. - Set AIMS objectives such as inventory coverage, assessment completion, incident response time, model monitoring coverage, and training completion. - Define how changes to models, prompts, datasets, providers, or intended use trigger reassessment. Evidence: AI risk methodology; AI risk register; AI impact assessments; Risk treatment plan; AIMS objectives and progress reports. ### Clause 7: Support - https://aestech.com.au/iso-42001/requirements/support/ Provide the people, skills, communication, documentation, and records needed for the AI management system to operate. - Define competence requirements for teams that build, buy, approve, monitor, or use AI systems. - Train staff on acceptable AI use, data handling, prompt safety, human review, incident reporting, and limits of AI-generated outputs. - Create communication rules for AI disclosures, customer questions, regulatory requests, and internal escalation. - Control documented information such as policies, model cards, impact assessments, testing records, and monitoring reports. - Keep evidence in a system that preserves ownership, version history, review status, and retention requirements. Evidence: AI training records; Competence matrix; Communication plan; Document control register; Versioned model and system documentation. ### Clause 8: Operation - https://aestech.com.au/iso-42001/requirements/operation/ Run the processes that control AI systems across design, acquisition, development, deployment, use, monitoring, and retirement. - Require intake and approval before new AI systems or material AI features are deployed. - Apply lifecycle gates for data selection, model selection, testing, human oversight design, release approval, monitoring, and retirement. - Define operating controls for AI outputs, including review thresholds, confidence rules, fallback processes, and user escalation. - Manage AI suppliers by reviewing model provider terms, data use, security posture, transparency commitments, and change notifications. - Keep logs for high-impact AI decisions, model changes, prompt changes, incidents, overrides, and human review actions. Evidence: AI intake tickets; Lifecycle gate records; Release approvals; Supplier due diligence; Monitoring logs and incident records. ### Clause 9: Performance evaluation - https://aestech.com.au/iso-42001/requirements/performance-evaluation/ Measure whether the AIMS is working, audit it, and have leadership review performance and needed changes. - Define monitoring for both management-system performance and AI system performance. - Track indicators such as incidents, exceptions, overdue risk treatments, model drift, complaint trends, assessment coverage, and review completion. - Run internal audits that sample AI systems, policies, evidence, suppliers, risk decisions, and corrective actions. - Hold management reviews that cover AIMS performance, changes in context, audit findings, stakeholder feedback, incidents, and improvement needs. - Use evidence from monitoring and audits to adjust AI objectives, controls, and risk appetite. Evidence: AIMS KPI dashboard; Internal audit plan and reports; Management review minutes; Corrective action tracker; Monitoring reports. ### Clause 10: Improvement - https://aestech.com.au/iso-42001/requirements/improvement/ Correct failures, learn from incidents and audits, and continually improve the AI management system. - Define how AI nonconformities are recorded, assessed, corrected, and verified. - Investigate root causes for AI incidents, control failures, policy breaches, assessment gaps, and supplier issues. - Assign corrective actions with owners, due dates, evidence expectations, and verification steps. - Feed lessons learned into policy updates, lifecycle gates, model monitoring, training, and supplier requirements. - Review whether improvement actions reduce residual risk rather than only closing tickets. Evidence: Nonconformity register; Root cause analyses; Corrective action records; Updated policies and procedures; Verification evidence. ## AI control areas ### A.2 AI policies - https://aestech.com.au/iso-42001/controls/ai-policies/ Set direction for responsible AI use and make policy expectations clear to builders, buyers, operators, and users. - Approve an AI policy and acceptable-use rules - Define prohibited AI use cases and exception handling - Review policy after incidents, regulatory change, or major AI adoption - Publish role-specific guidance for staff and product teams Evidence: AI policy; Acceptable-use standard; Policy approval record; Exception register. Metrics: Policy acknowledgement rate; Open policy exceptions; Days since last policy review. ### A.3 Internal organization - https://aestech.com.au/iso-42001/controls/internal-organization/ Assign accountability and decision rights for AI governance across leadership, product, engineering, legal, security, privacy, and operations. - Define AI governance roles and RACI - Create an AI review board or equivalent forum - Assign owners for each AI system and risk treatment - Record approval decisions and escalation outcomes Evidence: Governance charter; RACI matrix; AI system owner list; Review board minutes. Metrics: Systems with named owners; Overdue governance decisions; Average approval cycle time. ### A.4 Resources for AI systems - https://aestech.com.au/iso-42001/controls/resources-for-ai-systems/ Ensure the organisation has the people, tools, data, infrastructure, and budget needed to govern AI systems properly. - Identify resource needs for each AI lifecycle stage - Set competence requirements for AI roles - Provide tooling for evaluation, monitoring, and evidence collection - Plan capacity for human oversight and incident response Evidence: Resource plan; Competence matrix; Tooling inventory; Training completion records. Metrics: Training completion; Coverage of monitoring tooling; Human review backlog. ### A.5 AI system impact assessment - https://aestech.com.au/iso-42001/controls/ai-system-impact-assessment/ Understand who may be affected by an AI system and what harms, benefits, rights impacts, or business impacts may occur. - Run impact assessments for new and changed AI systems - Assess affected groups, intended use, foreseeable misuse, and severity of harm - Document controls for fairness, transparency, privacy, security, safety, and human oversight - Approve residual impact before release Evidence: AI impact assessment; Affected-party analysis; Residual impact approval; Control mapping. Metrics: Assessment coverage; High-impact systems awaiting approval; Residual high risks accepted. ### A.6 AI system lifecycle - https://aestech.com.au/iso-42001/controls/ai-system-lifecycle/ Control AI systems from idea and design through data work, model selection, testing, release, operation, change, and retirement. - Define lifecycle gates for AI systems - Document intended use and design assumptions - Test against performance, robustness, bias, security, and misuse criteria - Control model, prompt, dataset, and provider changes Evidence: Lifecycle procedure; Design records; Test results; Release approval and change logs. Metrics: Systems passing lifecycle gates; Failed release criteria; Unauthorized AI changes. ### A.7 Data for AI systems - https://aestech.com.au/iso-42001/controls/data-for-ai-systems/ Govern data used for AI so it is lawful, suitable, representative enough for the purpose, protected, and traceable. - Document data sources, rights, lineage, and quality checks - Assess training, validation, test, prompt, and operational data separately - Apply privacy, classification, retention, and access controls - Track data changes that could affect model behaviour Evidence: Data inventory; Data lineage records; Data quality checks; Privacy and security reviews. Metrics: Datasets with lineage recorded; Data quality exceptions; Open privacy or retention issues. ### A.8 Information for interested parties - https://aestech.com.au/iso-42001/controls/information-for-interested-parties/ Provide appropriate transparency to users, customers, staff, regulators, auditors, and affected people. - Define what information each stakeholder group needs - Prepare user notices, model cards, customer FAQs, and audit packs where appropriate - Explain AI limitations, human oversight, appeal paths, and data use in plain language - Keep disclosures current when systems change Evidence: Stakeholder communication plan; AI notices; Model or system cards; Customer assurance pack. Metrics: Disclosure coverage; Stakeholder questions unresolved; Expired assurance documents. ### A.9 Use of AI systems - https://aestech.com.au/iso-42001/controls/use-of-ai-systems/ Control how AI systems are used in practice so outputs are reviewed, limitations are understood, and misuse is detected. - Define permitted users and permitted use cases - Set output review rules for consequential decisions - Train users on limitations and escalation - Monitor use patterns, overrides, complaints, and unsafe outputs Evidence: User guidance; Access records; Human review logs; Usage monitoring reports. Metrics: Users trained before access; Human override rate; Misuse or unsafe-output events. ### A.10 Third-party and customer relationships - https://aestech.com.au/iso-42001/controls/third-party-and-customer-relationships/ Manage AI risks introduced by model providers, SaaS tools, implementation partners, customers, and downstream users. - Assess AI suppliers before use - Review provider terms for data use, confidentiality, model training, change notice, and incident notification - Define customer responsibilities where your AI system is deployed by others - Monitor supplier changes that affect risk or compliance Evidence: Supplier AI assessment; Contract clauses; Shared responsibility matrix; Supplier review records. Metrics: Critical suppliers assessed; Contracts with AI clauses; Supplier changes reviewed. ### A.11 Responsible use - https://aestech.com.au/iso-42001/controls/responsible-use/ Make responsible AI principles operational, including fairness, accountability, transparency, privacy, security, safety, and human agency. - Define responsible AI principles and turn them into controls - Set human oversight levels based on impact - Document fairness, explainability, safety, and misuse tests where relevant - Create channels for feedback, appeal, and incident reporting Evidence: Responsible AI principles; Oversight design; Fairness or safety test records; Feedback and appeal records. Metrics: High-impact systems with oversight defined; Appeals or complaints; Responsible AI test completion. ### A.12 AI objectives and metrics - https://aestech.com.au/iso-42001/controls/ai-objectives-and-metrics/ Define measurable objectives for AI performance and governance so the AIMS can be evaluated and improved. - Set measurable AI objectives tied to business value, risk, quality, and stakeholder protection - Define metrics for model performance and governance performance - Review metrics in management review and risk forums - Use metric trends to trigger corrective action or reassessment Evidence: AIMS objectives; Metric definitions; Performance dashboards; Management review actions. Metrics: Objective completion; Model drift alerts; Corrective actions from metric reviews. # PCI DSS v4.0.1 ## Requirement 1: Install and maintain network security controls - https://aestech.com.au/pci-dss/requirements/1/ Network security controls (NSCs), such as firewalls, control traffic between your cardholder data environment (CDE) and everything else. - 1.1 Processes and mechanisms are defined and understood: Document NSC policies and assign ownership; keep them current and known to staff. - 1.2 NSCs are configured and maintained: Define a configuration standard, restrict changes via change control, and review rule sets at least every six months. - 1.3 Network access to and from the CDE is restricted: Allow only necessary traffic in and out of the CDE; deny all else by default. - 1.4 Network connections between trusted and untrusted networks are controlled: Place NSCs at the boundary and restrict inbound/outbound traffic to what is authorised. - 1.5 Risks from devices connecting to both untrusted networks and the CDE are mitigated: Harden laptops/endpoints that can reach the CDE (e.g. host firewalls, restrictions). ## Requirement 2: Apply secure configurations to all system components - https://aestech.com.au/pci-dss/requirements/2/ Default passwords and settings are public knowledge. Every component must be hardened before it goes live. - 2.1 Processes and mechanisms are defined and understood: Document configuration standards and ownership. - 2.2 System components are configured and managed securely: Apply hardening baselines, change all vendor defaults, and remove unnecessary services/accounts. - 2.3 Wireless environments are configured and managed securely: Change wireless defaults (keys, SNMP, passwords) and use strong encryption. ## Requirement 3: Protect stored account data - https://aestech.com.au/pci-dss/requirements/3/ If you store account data, it must be rendered unreadable, and sensitive authentication data must never be stored after authorisation. - 3.1 Processes and mechanisms are defined and understood: Document data-retention and protection policy. - 3.2 Storage of account data is kept to a minimum: Define retention, store only what is needed, and securely delete the rest. - 3.3 Sensitive authentication data (SAD) is not stored after authorisation: Never store full track data, card verification codes, or PINs after authorisation. - 3.4 Access to displays of full PAN and ability to copy PAN is restricted: Mask PAN on display (show at most first six/last four) except for those with a need. - 3.5 PAN is secured wherever it is stored: Render PAN unreadable via strong encryption, truncation, tokenisation, or hashing. - 3.6 Cryptographic keys protecting stored account data are secured: Protect keys, restrict access, and store them separately from the data. - 3.7 Key management is fully documented and implemented: Define key generation, distribution, rotation, retirement and replacement procedures. ## Requirement 4: Protect cardholder data with strong cryptography during transmission over open, public networks - https://aestech.com.au/pci-dss/requirements/4/ Card data in transit over public networks must be encrypted so it cannot be intercepted. - 4.1 Processes and mechanisms are defined and understood: Document transmission-security policy. - 4.2 PAN is protected with strong cryptography during transmission: Use strong TLS, accept only trusted keys/certificates, and maintain an inventory of where PAN is sent. ## Requirement 5: Protect all systems and networks from malicious software - https://aestech.com.au/pci-dss/requirements/5/ Malware is a primary breach vector. Components must be protected, and protections kept current and active. - 5.1 Processes and mechanisms are defined and understood: Document anti-malware policy and ownership. - 5.2 Malware is prevented, or detected and addressed: Deploy anti-malware on systems commonly affected, and evaluate periodically for those not. - 5.3 Anti-malware mechanisms are active and monitored: Keep engines current, run periodic scans, and prevent users from disabling them. - 5.4 Anti-phishing mechanisms protect users: Deploy technical anti-phishing controls (e.g. email filtering) alongside awareness training. ## Requirement 6: Develop and maintain secure systems and software - https://aestech.com.au/pci-dss/requirements/6/ Vulnerabilities in your own and third-party software must be found and fixed, and software developed securely. - 6.1 Processes and mechanisms are defined and understood: Document secure-development and patch policy. - 6.2 Bespoke and custom software is developed securely: Train developers, use a secure SDLC, and review code before release. - 6.3 Security vulnerabilities are identified and addressed: Track vulnerabilities (incl. dependencies), rank by risk, and patch critical ones within one month. - 6.4 Public-facing web applications are protected against attacks: Use a WAF or regular automated/manual application reviews. - 6.5 Changes to all system components are managed securely: Apply change control with documentation, testing, approval and rollback. ## Requirement 7: Restrict access to system components and cardholder data by business need to know - https://aestech.com.au/pci-dss/requirements/7/ People should only access the data and systems their job requires, on a least-privilege basis. - 7.1 Processes and mechanisms are defined and understood: Document an access control policy. - 7.2 Access is appropriately defined and assigned: Assign access by role and need-to-know, with documented approval. - 7.3 Access is managed via an access control system: Enforce access through a system set to deny-all by default. ## Requirement 8: Identify users and authenticate access to system components - https://aestech.com.au/pci-dss/requirements/8/ Every user must be uniquely identified and strongly authenticated, with MFA into the CDE. - 8.1 Processes and mechanisms are defined and understood: Document identification and authentication policy. - 8.2 User identification and accounts are managed: Assign unique IDs, no shared accounts, and remove access promptly on departure. - 8.3 Strong authentication is established and managed: Enforce strong authentication factors and protect them in transit and storage. - 8.4 MFA is implemented to secure access into the CDE: Require MFA for all access into the CDE and all remote/admin access. - 8.5 MFA systems are configured to prevent misuse: Configure MFA to resist replay and bypass. - 8.6 Application and system accounts are managed: Control service-account credentials, rotate them, and avoid interactive use. ## Requirement 9: Restrict physical access to cardholder data - https://aestech.com.au/pci-dss/requirements/9/ Physical access to systems and media holding cardholder data must be controlled, and payment devices protected from tampering. - 9.1 Processes and mechanisms are defined and understood: Document physical security policy. - 9.2 Physical access controls manage entry into facilities and systems: Control and monitor entry to areas with cardholder data. - 9.3 Physical access for personnel and visitors is authorised and managed: Authorise personnel access and log/escort visitors. - 9.4 Media with cardholder data is securely stored, accessed, distributed and destroyed: Classify, secure, track and securely destroy media holding card data. - 9.5 Point-of-interaction (POI) devices are protected: Inspect payment terminals for tampering/substitution and train staff to spot it. ## Requirement 10: Log and monitor all access to system components and cardholder data - https://aestech.com.au/pci-dss/requirements/10/ Logging and monitoring let you detect, alert on, and investigate suspicious activity. - 10.1 Processes and mechanisms are defined and understood: Document logging and monitoring policy. - 10.2 Audit logs are implemented to support anomaly detection: Log access, admin actions, and key events with enough detail to investigate. - 10.3 Audit logs are protected from destruction and modification: Restrict and protect logs; forward to a central, tamper-resistant store. - 10.4 Audit logs are reviewed to identify anomalies: Review logs (ideally with automation/SIEM) and act on findings. - 10.5 Audit log history is retained: Retain at least 12 months, with the most recent 3 readily available. - 10.6 Time-synchronisation mechanisms are in place: Sync clocks to an authoritative source so logs correlate. - 10.7 Failures of critical security controls are detected and responded to: Alert on and promptly respond to failures of security controls. ## Requirement 11: Test security of systems and networks regularly - https://aestech.com.au/pci-dss/requirements/11/ Controls degrade over time; regular scanning and testing find new weaknesses before attackers do. - 11.1 Processes and mechanisms are defined and understood: Document security-testing policy. - 11.2 Wireless access points are identified and monitored: Detect authorised and rogue wireless access points periodically. - 11.3 Vulnerabilities are regularly identified, prioritised and addressed: Run internal scans and quarterly external ASV scans; remediate and rescan. - 11.4 Penetration testing is regularly performed: Perform internal and external penetration tests at least annually and after significant changes. - 11.5 Network intrusions and unexpected file changes are detected: Use IDS/IPS and file-integrity monitoring with response. - 11.6 Unauthorised changes on payment pages are detected: Monitor payment-page scripts/headers for tampering (a v4.0 focus on e-skimming). ## Requirement 12: Support information security with organisational policies and programs - https://aestech.com.au/pci-dss/requirements/12/ Technical controls need governance: policy, risk management, awareness, vendor oversight, and incident response. - 12.1 A comprehensive information security policy is maintained: Establish, publish, review (at least annually) and disseminate the policy. - 12.2 Acceptable use policies are defined: Define acceptable use for end-user technologies. - 12.3 Risks to the CDE are formally managed: Perform targeted risk analyses where the standard allows flexibility. - 12.4 PCI DSS compliance is managed: Assign responsibility for the compliance program (and, for service providers, executive oversight). - 12.5 PCI DSS scope is documented and validated: Document and confirm scope at least annually and on significant change. - 12.6 Security awareness education is ongoing: Train personnel at hire and at least annually, covering current threats. - 12.7 Personnel are screened: Screen staff before hire to reduce insider risk, within local law. - 12.8 Third-party service provider (TPSP) risk is managed: Maintain a TPSP list, define responsibilities, and monitor their compliance. - 12.9 TPSPs support their customers’ compliance: If you are a TPSP, acknowledge responsibility and provide evidence to customers. - 12.10 Suspected and confirmed incidents are responded to: Maintain and test an incident response plan covering card-data incidents. # AI compliance playbooks ## How to Manage Compliance Controls with AI - https://aestech.com.au/ai-compliance/manage-controls/ A step-by-step playbook for running your controls with AI and automation: map them once, collect evidence automatically, and stay continuously compliant. - Build one control register: List every control you are responsible for (ISO Annex A, PCI requirements, SOC 2) in one place, with an owner and the system it lives in. A compliance platform gives you this pre-mapped so you are not starting from a blank sheet. - Map controls to frameworks once: Tag each control with the frameworks it satisfies. One control (for example MFA) often covers several frameworks, so you implement once and report many times. Platforms like Vanta and Drata do this cross-mapping for you. - Connect your systems for automated evidence: Integrate your cloud, identity provider, HR system, and code repos. The platform then pulls evidence (access lists, MFA status, encryption settings) automatically instead of you taking screenshots. - Turn on continuous monitoring: Let the platform test each control on a schedule and alert you when one fails (a new admin without MFA, an unencrypted bucket). This converts annual panic into daily signal. - Use an AI assistant to interpret requirements: When a control is unclear, ask an AI assistant what it means and what evidence satisfies it. It is excellent for translating standard-speak into a concrete checklist for your stack. - Remediate by exception: Work only the controls that are failing or drifting. Assign each failure as a task with an owner and due date (see the reminders playbook). - Keep an always-on evidence trail: Because evidence is collected continuously, audit time becomes export-and-review rather than a month-long scramble. Spot-check that the automated evidence actually reflects reality. ## How to Write and Maintain Compliance Policies with AI - https://aestech.com.au/ai-compliance/manage-policies/ Use AI to draft, tailor, review, and keep your ISO 27001 and PCI DSS policies current, without the blank-page problem or the annual scramble. - Start from the control, not a blank page: For each required policy, prompt an AI assistant with the control text plus your context (your stack, size, industry). Ask for a draft policy that would satisfy the control. You get a solid 80 percent draft in minutes. - Tailor to reality: Edit the draft so it describes what you actually do, not an aspirational ideal. A policy you do not follow is worse than none, auditors test policy against practice. - Run an AI gap review: Paste your draft back and ask the AI to check it against the control requirement and flag anything missing or contradictory. Treat it as a reviewer, not the final word. - Get human approval: Route the policy to the accountable owner (often a manager or the CISO) for sign-off. Record who approved it, the version, and the date. - Publish and collect attestations: Publish to one place everyone can find, and collect acknowledgements from staff. Compliance platforms automate the attestation and chase non-responders. - Version and schedule reviews: Keep version history and set a review date (at least annually). When the date arrives, use AI to summarise what changed in your environment and propose policy updates. ## The Compliance Operating Rhythm (a Calendar You Can Run) - https://aestech.com.au/ai-compliance/operating-rhythm/ Compliance is a cadence, not a project. Here is the daily-to-annual operating rhythm for ISO 27001 and PCI DSS, and how AI keeps it running. - List every recurring activity: Go through your controls and write down the activity each one implies (review access, scan for vulnerabilities, test backups). Most controls become a recurring task. - Assign a cadence and an owner: Give each activity a frequency and a single accountable owner. Use the table below as a starting template. - Generate the calendar with AI: Feed your control list to an AI assistant and ask it to produce a compliance calendar grouped by cadence. It will draft the whole rhythm in one pass for you to refine. - Automate the recurring tasks: Create the recurring tasks in your task tool or let a compliance platform schedule control checks. The rhythm should fire on its own. - Hold a short monthly compliance stand-up: Review what is overdue, what failed, and what is coming. Use AI to draft the agenda from open tasks and to write up the minutes and actions. - Review and adjust quarterly: Each quarter, confirm the cadence still fits (new systems, new frameworks) and adjust owners and frequencies. ## Reminders and Task Management for Compliance with AI - https://aestech.com.au/ai-compliance/reminders-and-tasks/ Turn controls into owned, time-bound tasks, and let AI and automation create, assign, chase, and report on them so nothing slips. - Derive tasks from controls: Every recurring activity from your operating rhythm becomes a recurring task. Ask an AI assistant to convert your control list into a task list with suggested owners and frequencies. - Assign one owner and a due date each: No shared ownership. Each task has a single accountable person and a real deadline. - Put tasks where work already happens: Create them in the tool your team lives in (Jira, Asana, Linear, or a compliance platform) so compliance is not a separate island people ignore. - Automate creation and reminders: Use recurring tasks and let the platform fire reminders. Trigger ad-hoc tasks automatically from events: a failed control check or expiring evidence creates a task on its own. - Let AI triage and nudge: Use AI to summarise what is overdue, draft polite nudges to owners, and surface the few things that actually matter this week. Some tools answer questions like "what is overdue for SOC 2?" directly. - Report status automatically: Generate a weekly status summary (done, overdue, at risk) with AI and share it with leadership. Visibility is what keeps owners honest. ## How to Automate Compliance Evidence Collection with AI - https://aestech.com.au/ai-compliance/evidence-collection/ Evidence is the heaviest lift in any audit. A step-by-step playbook for collecting, organising, and sanity-checking evidence with AI and integrations. - Build the evidence request list: For each control in scope, write down what proves it: a config export, an access review record, a training report. Your auditor will send a list; pre-empt it. AI can draft this list from your Statement of Applicability in one pass. - Automate the mechanical evidence: Connect cloud, IdP, MDM, and repos to a compliance platform so configuration evidence (MFA status, encryption, access lists) collects itself continuously instead of as screenshots. - Schedule the human evidence: Some evidence is inherently human: meeting minutes, review sign-offs, test reports. Put each on the operating rhythm as a recurring task that files its output to a known location. - Name and file everything predictably: One folder per control or requirement, files named date-first (2026-06-quarterly-access-review.pdf). Predictable structure is what lets AI, and auditors, find things. - Run an AI freshness sweep monthly: Give the AI your evidence index and ask: what is stale, what is missing, what does not match its control? Treat the output as a task list. - Assemble the audit pack with AI: At audit time, have AI compile the evidence index per requirement, flag gaps, and draft the narrative explanations auditors ask for. Days of work becomes hours. ## How to Run an Internal Audit with AI - https://aestech.com.au/ai-compliance/internal-audit/ ISO 27001 requires internal audits and most teams dread them. Here is how AI compresses planning, fieldwork prep, and reporting, with the audit skill included. - Plan the programme with AI: Give AI your scope, last audit results, and incidents since. Ask for a risk-weighted audit programme: which areas, what depth, what order. Riskier and previously nonconforming areas get audited harder. - Generate the audit checklist: For each area, have AI turn the relevant clauses and controls into concrete audit questions and the evidence to request. Review and cut; an audit drowning in questions finds less. - Keep the auditor independent: The person auditing an area must not own it. In small teams, swap areas between people or bring in an external reviewer. AI prep does not replace this independence requirement. - Do the fieldwork by hand: Interviews, sampling, and walkthroughs are human work. Record findings raw as you go; do not polish in the moment. - Classify findings with AI assistance: Feed raw findings to AI to draft classifications: major nonconformity, minor, observation, opportunity. A human confirms each one; classification drives consequences. - Write the report and corrective actions with AI: AI drafts the audit report from the findings and proposes corrective-action entries (root cause prompts, owners, due dates) for your tracker. Management review gets the summary. ## How to Run a Risk Assessment with AI - https://aestech.com.au/ai-compliance/risk-assessment/ The risk assessment drives everything in ISO 27001 and the targeted risk analyses in PCI DSS v4. Here is the AI-assisted way to run one that auditors respect. - Fix the methodology first: Decide scales (1 to 5 likelihood and impact), risk appetite, and acceptance criteria, and write them down. AI can draft this methodology document; management must approve it. Consistency is what auditors test. - Generate a candidate risk list with AI: Describe your stack, data, vendors, and history; ask AI for candidate risks per asset group with threat and vulnerability stated separately. Expect 60 to 80 percent useful; the rest you cut. - Score in a workshop, not alone: Likelihood and impact ratings need the people who run the systems. AI pre-fills suggested scores with reasoning; the workshop confirms or corrects them in a fraction of the usual time. - Map treatments to controls: For each risk above appetite, AI proposes treatment options and maps them to ISO Annex A controls or PCI requirements, which feeds your Statement of Applicability directly. - Get explicit acceptance: Risk owners sign off residual risk. This is a human signature, never an AI output. Record who accepted what and when. - Re-run on triggers, not just annually: New vendor, new system, incident, or major change triggers a delta assessment. AI makes the delta cheap: feed it the change, get the new and changed risks. ## How to Run Vendor Security Reviews with AI - https://aestech.com.au/ai-compliance/vendor-security-reviews/ Third-party risk is a whole ISO control family and PCI requirement 12.8. Here is the AI-assisted vendor review process, with the questionnaire and skill included. - Tier your vendors: Classify by data access and criticality: Tier 1 touches customer or card data, Tier 2 touches internal data, Tier 3 touches nothing sensitive. Review depth follows tier. AI can pre-tier from your vendor list and what each tool does. - Collect their evidence, not just promises: For Tier 1: SOC 2 report or ISO certificate, recent pen test summary, and their responsibility matrix. For PCI: their Attestation of Compliance. A trust-page screenshot is not evidence. - Let AI read the reports: Feed the SOC 2 or ISO certificate and report to AI: extract scope, period, exceptions and qualifications, carve-outs, and complementary user controls you are responsible for. The exceptions section is where the truth lives. - Send the short questionnaire for gaps: Only ask what the documents did not answer. A 60-question blanket form gets template answers; ten targeted questions get real ones. - Record the decision and the residual risk: Approve, approve with conditions, or reject. Conditions become tasks with owners. The vendor register row links to all the evidence. - Re-review on cadence and on triggers: Annual for Tier 1, two-yearly for Tier 2, and immediately on breach news, ownership change, or scope change. AI monitors expiry dates and drafts the renewal requests. ## How to Use AI in Incident Response (Without Making It Worse) - https://aestech.com.au/ai-compliance/incident-response/ ISO A.5.24 to A.5.28 and PCI DSS 12.10 both demand a tested incident response capability. Here is where AI genuinely helps during an incident, and where it must not be trusted. - Write the plan with AI, test it with humans: AI drafts the IR plan, severity matrix, and per-scenario runbooks (ransomware, account takeover, data leak, payment-page skimming for PCI). Humans tabletop them at least annually; the exercise is the control. - Let AI triage the noise, not declare incidents: AI and SIEM tooling summarise and correlate alerts so a human sees five candidate events, not five hundred. The classification of event versus incident stays with the on-call human, per your criteria. - Make AI the scribe during the incident: One responder pastes updates into the channel; AI maintains the running timeline, decision log, and current-status summary. This is the highest-value, lowest-risk AI job in an incident. - Draft communications with AI, send with approval: Status-page updates, customer notices, internal briefs, and regulator notifications all start as AI drafts from the timeline. Legal or the incident manager approves every external word. - Mind the notification clocks: Know your deadlines in advance: card brands and acquirer for card-data incidents, privacy regulators for personal data (72 hours under GDPR; the Australian NDB scheme has its own test), cyber insurance, and for Australian entities the ransomware payment reporting obligation. AI tracks which clocks an incident starts, your plan names who calls. - Run the post-incident review with AI: AI turns the timeline into a draft post-mortem: sequence, contributing causes, what worked, action items with owners. Feed the actions back into the risk register and control improvements (A.5.27). # Trust, security and disclosure Trust Center: https://aestech.com.au/trust/ Privacy notice: https://aestech.com.au/privacy/ Partner profile for affiliate networks and SaaS vendors: https://aestech.com.au/partners/ Security policy: https://aestech.com.au/security/ Machine-readable AI index: https://aestech.com.au/ai-index.json Image sitemap for owned lightweight WebP visuals: https://aestech.com.au/image-sitemap.xml security.txt: https://aestech.com.au/.well-known/security.txt humans.txt: https://aestech.com.au/humans.txt Some links are affiliate links; commissions never influence rankings. Full policy: https://aestech.com.au/disclosure/