Solution · APRA CPS 234

    Keep customer data out of non-production environments — provably.

    APRA CPS 234 paragraph 14 expects you to control non-production data. WorkLens generates realistic synthetic data on your device, redacts what you must share, and signs a tamper-evident audit receipt — so you can show the auditor your controls, not just claim them. You remain responsible for compliance.

    Built for: APRA-regulated entity InfoSec / CISO

    The problem

    • Engineering teams want production data in staging to reproduce bugs — but legal can't approve it
    • Existing DLP tools assume data has already left your perimeter. Yours hasn't yet.
    • Auditors want evidence that no real customer data sits in dev/test, not just a policy
    • Synthetic data tools require uploading your schema — which is itself sensitive metadata

    How WorkLens solves it

    • Synthetic data generated on your device — schema and rows never leave the browser
    • Audit receipt: Ed25519-signed fingerprint of every scan (what was processed, what was found)
    • AU validators (TFN, ABN, Medicare, BSB) with checksum validation — not just pattern guesses
    • Local-first runs in a regulated air-gapped network with no outbound calls