Skip to content
arrow_back

Legal

Terms of Service.

Effective: 29 June 2026

These terms govern your use of the Control Stack website (controlstack.au), the Control Stack mobile app, and the Control Stack compliance tracker (together, the "Service"), operated by Mindset Cyber PTY LTD (ABN 55 668 364 261) ("we", "us", "our"). By using the Service you agree to these terms. If you do not agree, please do not use the Service.

The Service

Control Stack is a free library of Australian and international security and AI governance controls (covering ISO/IEC 27001, ISO/IEC 42001, the ASD Essential Eight, and the ASD Information Security Manual) rewritten in plain English, with cross-framework mappings, implementation tips and audit evidence guidance. It also offers an optional compliance tracker. The Service is free to use, with no paid tiers and no in-app purchases. We may add, change, or discontinue features at any time.

Accounts

Browsing the library does not require an account. To use the compliance tracker you create a free account. You must be at least 16 years old to create an account. You are responsible for keeping your sign-in credentials secure, for providing accurate information, and for activity that happens under your account. Tell us promptly if you believe your account has been accessed without your permission.

Acceptable use

You agree not to:

  • Use the Service unlawfully or to infringe the rights of others.
  • Scrape, bulk-download, resell, or redistribute the content except as the Service expressly allows (such as the built-in share feature).
  • Attempt to disrupt, overload, reverse engineer, or gain unauthorised access to the Service or its infrastructure.

Reference information, not advice

Control Stack provides plain-English general reference information about security and AI governance controls. It is not legal, compliance, or professional advice, and it is not a substitute for the official source frameworks or for advice from a qualified professional. The compliance tracker helps you organise and track your own work; it does not certify, assess, or guarantee compliance, and it does not guarantee any audit, assessment, or certification outcome. You remain responsible for how you interpret and apply the controls in your own environment.

No affiliation or endorsement

Control Stack is an independent tool. It is not affiliated with, authorised by, or endorsed by the International Organization for Standardization (ISO), the Australian Signals Directorate (ASD) or Australian Cyber Security Centre (ACSC), Apple, or Google. Framework names and standards referenced in the Service are the property of their respective owners and are used for identification and reference only.

Intellectual property

The plain-English explanations, mappings, design, and software that make up the Service are owned by Mindset Cyber PTY LTD or its licensors. The underlying frameworks and standards remain the property of their respective publishers. We grant you a personal, non-exclusive, non-transferable licence to use the Service for your own compliance and educational purposes.

Disclaimer of warranties

The Service is provided "as is" and "as available", without warranties of any kind to the extent permitted by law. We do not warrant that the content is complete, current, or error-free, or that the Service will be uninterrupted or secure.

Limitation of liability

To the maximum extent permitted by law, Mindset Cyber PTY LTD is not liable for any indirect, incidental, or consequential loss, or for any loss arising from your reliance on the content or your use of the Service. Nothing in these terms excludes, restricts, or modifies any rights or remedies you may have under the Australian Consumer Law or other laws that cannot lawfully be excluded.

Suspension and termination

You may stop using the Service and delete your account at any time (see our account deletion page). We may suspend or terminate access if you breach these terms or use the Service in a way that risks harm to others or to the Service.

Privacy

Our handling of your data is described in our Privacy Policy, which forms part of these terms.

Governing law

These terms are governed by the laws of Australia and of the State or Territory in which Mindset Cyber PTY LTD is registered, and you submit to the non-exclusive jurisdiction of the courts of that place.

Changes to these terms

We may update these terms from time to time. The "effective" date at the top of this page reflects the most recent revision; continued use of the Service means you accept the updated terms.

Contact us

Questions about these terms? Contact us at info@controlstack.au.