By accessing or using the Delphitek platform, you agree to be bound by these Terms of Use.
If you do not agree, do not use the platform.
1. Platform Overview
Delphitek ("the Platform") is a SaaS multi-framework Compliance Assessment Platform that assists Managed Service Providers (MSPs)
and their customers in assessing and monitoring alignment with multiple cybersecurity and compliance standards.
The Platform currently supports twenty-one compliance frameworks, delivered through a single cloud portal:
ASD Essential Eight (Nov 2024)
ISO/IEC 27001:2022
NIST CSF 2.0
CIS Controls v8
SOC 2 Type II Readiness
SMB1001 Bronze
PCI DSS v4.0
APRA CPS 234
CMMC 2.0 Level 2
Privacy Act Compliance (APPs)
APRA CPS 230
SOCI Act (CIRMP)
ISO 22301 (BCMS)
ISO 27701 (PIMS)
GDPR
HIPAA Security Rule
DORA
NIS2
NIST 800-53
IRAP Readiness
FedRAMP Readiness
The Platform is operated by Base 60 Capital Pty Ltd (ABN: 406 812 176 94) trading as Delphitek ("Delphitek", "we", "us").
2. Intellectual Property
This toolkit and its methodology — including all assessment logic, scoring algorithms, framework plugins, report templates, and associated
tooling — are proprietary intellectual property of Base 60 Capital Pty Ltd (trading as Delphitek).
This expressly includes the Delphitek Agent Connector and its local assessment engine (the Windows service, orchestration scripts,
collector scripts, scoring engine, and all control/rule/classification data files it installs on your endpoint(s)) — installing this
software on your own hardware does not transfer, license, or waive any of Delphitek's intellectual property rights in it, and it remains
subject to this section in full on every machine it is installed on.
- No redistribution, resale, or sharing of the platform, the Agent Connector/local assessment engine, or their outputs is permitted without written consent
- No reverse engineering, decompilation, disassembly, or derivative works are permitted — of the Platform or of the Agent Connector/local assessment engine, including any attempt to extract, copy, or repurpose its scoring methodology or rule/classification data
- No white-label rights are granted unless explicitly licensed in writing
- Derivative tools or materially similar systems created using this platform, including via AI-assisted reconstruction, are considered IP infringement
3. Authorised Use
You may use the Platform solely for your organisation's internal compliance assessment purposes or, if you are an MSP,
to assess and monitor the compliance posture of your authorised end-customers across the frameworks covered by your subscription.
You must not:
- Use the Platform for any unlawful purpose
- Attempt to gain unauthorised access to any part of the Platform or its infrastructure
- Use the Platform to assess organisations you are not authorised to act on behalf of
- Share API keys, agent tokens, or login credentials with unauthorised parties
- Attempt to access compliance frameworks for which your subscription is not licensed
- Copy, extract, or run the Agent Connector or its local assessment engine outside of a live, licensed, currently-entitled Delphitek
tenant, or on any endpoint not covered by your active subscription
4. Subscriptions and Billing
Access to the Platform is provided on a per-tenant annual subscription basis. Subscription tiers (Basic, Pro, Premium, Enterprise),
framework add-on pricing, and included features are as agreed in your commercial terms with Delphitek.
Subscriptions auto-renew unless cancelled. Billing is processed via Stripe. You authorise Delphitek to charge your
nominated payment method on the agreed billing cycle.
Access to specific compliance frameworks is gated by your active subscription entitlement. Attempting to run an assessment
against an unlicensed framework will be declined by the Platform.
5. Assessment Data and Accuracy
Assessment results are generated based on data collected via Microsoft 365 Graph API and/or the Delphitek Assessment Agent
(AssessmentKit) deployed locally in a customer environment. Results represent the assessed posture at the time of collection
and may not reflect all security controls in your environment.
The controls and data points assessed vary by framework. Some frameworks rely exclusively on Microsoft Graph API telemetry;
others may incorporate additional data sources collected by the local Assessment Agent.
Assessment outputs do not constitute a formal security audit and should not be relied upon as the sole
basis for compliance decisions. Engage a qualified cybersecurity professional for formal assessments and advice.
6. Data Handling
Your use of the Platform is also governed by our Privacy Policy, which is incorporated into
these Terms by reference.
7. Assessment Scope and Limitations
The Delphitek AssessmentKit provides compliance readiness assessments only. These assessments:
- Are generated by automated software tools and do not constitute formal certification, attestation, or a compliance determination under any framework (including ASD Essential Eight, ISO/IEC 27001:2022, NIST CSF 2.0, CIS Controls v8, SOC 2 Type II, SMB1001 Bronze, PCI DSS v4.0, APRA CPS 234, CMMC 2.0 Level 2, Privacy Act Compliance, APRA CPS 230, SOCI Act (CIRMP), ISO 22301, ISO 27701, GDPR, HIPAA Security Rule, DORA, NIS2, NIST 800-53, IRAP Readiness, FedRAMP Readiness, or any other). For PCI DSS v4.0 specifically, this Platform does not perform or replace a Qualified Security Assessor (QSA) assessment or Self-Assessment Questionnaire (SAQ), and does not determine Cardholder Data Environment (CDE) scope. For APRA CPS 234 and APRA CPS 230 specifically, this Platform does not perform or replace an APRA supervisory review, and each standard applies only to APRA-regulated entities (authorised deposit-taking institutions, general/life/private health insurers, and registrable superannuation entity licensees) — use of these add-ons does not determine your organisation's regulatory status or obligations. For CMMC 2.0 specifically, this Platform models Level 2 only (built on NIST SP 800-171 Revision 2), does not perform or replace an assessment from an accredited Third-Party Assessment Organization (C3PAO), and does not itself constitute a CMMC certification for any contract. For Privacy Act Compliance specifically, this Platform assesses the 13 Australian Privacy Principles at principle level only, does not constitute legal advice, and does not replace a qualified privacy law practitioner or the guidance of the Office of the Australian Information Commissioner (OAIC). For the SOCI Act (CIRMP) specifically, this Platform does not perform or replace a review by the Cyber and Infrastructure Security Centre, and the SOCI Act applies only to responsible entities of critical infrastructure assets as defined under that Act. For ISO 22301 and ISO 27701 specifically, this Platform does not perform or replace a certification audit by an accredited certification body; ISO 27701 additionally extends an existing ISO/IEC 27001 Information Security Management System, and purchase of the ISO 27701 add-on requires an active ISO/IEC 27001 add-on for the same tenant. For GDPR specifically, this Platform does not constitute legal advice, does not determine your organisation's regulatory status under the GDPR, and does not replace the guidance of a qualified EU data-protection legal practitioner or a supervisory authority. For HIPAA specifically, this Platform assesses the Security Rule only (not the separate Privacy Rule or Breach Notification Rule), does not constitute legal advice, and does not replace a qualified US health-privacy legal practitioner or a determination by the US Department of Health and Human Services Office for Civil Rights (OCR). For DORA specifically, this Platform does not perform or replace a competent authority's compliance determination, and DORA applies only to entities within its own defined list of EU financial entities. For NIS2 specifically, this Platform assesses the EU-level Directive baseline only, not any specific EU Member State's transposing national law, and does not perform or replace a competent authority's compliance determination. For NIST 800-53 specifically, this Platform does not constitute an Authorization to Operate (ATO), a FedRAMP assessment, or qualified US federal compliance/legal advice. For IRAP Readiness specifically, this Platform is NOT a real IRAP (Infosec Registered Assessors Program) assessment, does not constitute Australian Signals Directorate (ASD) endorsement, and assesses only a curated subset of the full Australian Government Information Security Manual (ISM) — a genuine IRAP assessment can only be performed by an ASD-endorsed IRAP assessor. For FedRAMP Readiness specifically, this Platform is NOT a FedRAMP authorization, does not perform or replace an assessment from an accredited Third-Party Assessment Organization (3PAO), and does not constitute or determine FedRAMP Marketplace listing eligibility — a real FedRAMP authorization attaches to a specific cloud service offering and is granted by an individual federal agency or the FedRAMP Board.
- Are limited to controls observable via the Microsoft 365 Graph API and/or the local Assessment Agent, and represent a partial assessment of the full framework control set.
- Do not replace a formal audit conducted by a qualified assessor or accredited certification body.
- Should not be relied upon as evidence of compliance in regulatory, contractual, or legal proceedings without independent verification by a qualified third party.
Controls Without Telemetry. Some framework controls cannot be assessed via available data sources (for example, application control, endpoint hardening, and backup verification for certain frameworks). These controls are explicitly marked Not Assessed in all reports and scores and are excluded from scoring calculations. A "Not Assessed" designation does not indicate alignment or non-alignment — it indicates that no valid telemetry was available to support a scoring determination. The number of controls assessed may vary based on Microsoft 365 API permissions and Assessment Agent coverage at the time of assessment.
Readiness Indicators. All scoring outputs (Aligned, Partially Aligned, Not Aligned, Unable to Verify, or framework-equivalent designations) are readiness indicators only. They do not represent a formal determination of compliance status and must not be presented to auditors, insurers, regulators, or boards as evidence of certification or compliance without independent verification by a qualified third party.
Delphitek accepts no liability for compliance outcomes, audit results, or regulatory enforcement actions arising from the use of AssessmentKit reports.
8. Subscription, Auto-Renewal, and Cancellation
Auto-Renewal
Subscriptions renew automatically at the end of each billing period (monthly or annual, as selected at checkout). You will be charged the then-current subscription price on your renewal date.
Cancellation
You may cancel your subscription at any time via the Billing Portal within the AssessmentKit portal. Cancellation takes effect at the end of the current billing period. No partial-period refunds are provided.
Refund Policy
Subscription fees are non-refundable except where required by applicable law (including Australian Consumer Law). If you believe you are entitled to a refund, contact us at info@delphitek.com within 7 days of the charge.
Framework Add-On Subscriptions
The base subscription (Basic, Pro, Premium, or Enterprise) includes access to the ASD Essential Eight framework.
The following compliance frameworks are available as separately billed annual add-ons:
ISO/IEC 27001:2022 — $9,000/tenant/yr
SOC 2 Readiness — $10,500/tenant/yr
NIST CSF 2.0 — $5,400/tenant/yr
CIS Controls v8 — $3,600/tenant/yr
SMB1001 Bronze — $2,500/tenant/yr
PCI DSS v4.0 — $3,000/tenant/yr
APRA CPS 234 — $2,400/tenant/yr
CMMC 2.0 Level 2 — $1,200/tenant/yr
Privacy Act Compliance — $2,400/tenant/yr
APRA CPS 230 — $1,250/tenant/yr
SOCI Act (CIRMP) — $1,000/tenant/yr
ISO 22301 (BCMS) — $750/tenant/yr
ISO 27701 (PIMS) — $750/tenant/yr
GDPR — $500/tenant/yr
HIPAA Security Rule — $750/tenant/yr
DORA — $1,250/tenant/yr
NIS2 — $1,000/tenant/yr
NIST 800-53 — $1,500/tenant/yr
IRAP Readiness — $1,500/tenant/yr
FedRAMP Readiness — $2,500/tenant/yr
A Multi-Framework Pack (ISO 27001 + SOC 2 + NIST CSF + CIS Controls + SMB1001 + PCI DSS v4.0 + APRA CPS 234 + CMMC 2.0 Level 2 + Privacy Act Compliance + APRA CPS 230 + SOCI Act + ISO 22301 + ISO 27701 + GDPR + HIPAA + DORA + NIS2 + NIST 800-53 + IRAP Readiness + FedRAMP Readiness — all twenty framework add-ons) is available at $39,995/tenant/yr.
Framework add-on subscriptions may be cancelled independently of the base subscription. Cancellation of a framework add-on
takes effect at the end of the current billing period, after which access to that framework's assessment features will be removed.
GST (Australian Goods and Services Tax)
Prices shown are exclusive of GST. Australian GST (currently 10%) will be added to all invoices issued to Australian customers. Tax invoices are available from the Billing Portal.
9. Availability and Support
Delphitek will use reasonable efforts to maintain Platform availability. We do not guarantee uninterrupted or error-free
operation. Scheduled maintenance will be communicated where practicable.
Support is available at info@delphitek.com.
10. Limitation of Liability
To the maximum extent permitted by law, Delphitek is not liable for any indirect, incidental, consequential, or punitive
damages arising from your use of the Platform or reliance on assessment outputs.
11. Termination
Delphitek reserves the right to suspend or terminate access to the Platform at any time for breach of these Terms or
non-payment of subscription fees, with or without notice.
12. Governing Law
These Terms are governed by the laws of New South Wales, Australia. Any disputes will be subject to the exclusive
jurisdiction of the courts of New South Wales.
13. Changes to Terms
Delphitek may update these Terms at any time. Continued use of the Platform following notification of changes constitutes
acceptance of the updated Terms.
14. Contact
Delphitek trading under Base 60 Capital Pty Ltd
Email: info@delphitek.com