ORCA Opti

Opti Assist Free

Free, governed AI for regulated Australian organisations.

Sovereign infrastructure. No credit card. Compliance gap analysis in fifteen minutes.

Australian organisations are already using AI. Most just don't know where their data is going. Opti Assist Free is a governed AI environment Australian organisations can safely operationalise, with a structured compliance readiness check built in.

  • Sovereign Australian-hosted infrastructure
  • No data sent to third-party AI providers
  • No training on user inputs
  • Microsoft 365 work email sign-in

What you get

A governed AI environment, with a compliance assessment built in.

The version of AI Australian organisations have been waiting for. Free for any Microsoft 365 work or school account, on sovereign infrastructure, with the standards your industry runs on already mapped.

100,000 OO Credits every month

Enough for a full readiness assessment plus everyday governance queries, gap analysis and report generation. No credit card. No procurement approval. No trial timer.

9-section readiness report

Structured compliance gap analysis scored from 0 to 100 across each domain. Gaps rated by severity, prioritised remediation steps, audit-ready language. About fifteen minutes from sign-in to finished report.

Specialist industry agents

Personalised to your sector at onboarding. Trained on the standards and regulations that apply to your industry, from defence and NDIS to financial services and research.

Sovereign by design

Runs on Australian infrastructure. Your inputs never leave for an offshore AI platform. Your data is never used to train third-party models. The audit trail stays with you.

$15,000 and three weeks.

Now free, and about fifteen minutes.

“A DISP readiness report at this level of detail used to cost around fifteen thousand dollars and take three weeks. We're giving it away for free, on sovereign infrastructure, and it takes about fifteen minutes. Every Australian organisation deserves to know where they stand on compliance. Cost and complexity shouldn't be the barrier, and neither should having to send the answers to an overseas tech company.”
Kathryn Giudes, Founder and Managing Director, ORCA Opti

Coverage

The standards your industry runs on, already mapped

Run a scored readiness assessment against any of these frameworks. Each report is structured the way an auditor expects to read it, with gaps rated by severity and remediation steps prioritised.

ISO 27001

Information Security Management

Essential Eight

ACSC cyber controls maturity

DISP

Defence Industry Security Program readiness

NDIS Practice Standards

Quality and Safeguards expectations

ISO 42001

AI Management System

PSPF

Protective Security Policy Framework

DSPF

Defence Security Principles Framework

ISO 9001

Quality Management System

Why now

The visibility gap is already inside your organisation.

Employees are using AI. Most of it is happening outside any system the organisation can see, on personal accounts, on platforms that train on user inputs, under offshore jurisdiction. Banning it has stopped working. Governing it is the only path left.

85.7%

of knowledge workers now use AI at work (Cyberhaven, 2026)

72.8%

of those using personal accounts their employer can't see (Cyberhaven, 2026)

36%+

of Australian professionals have exposed sensitive company data to AI platforms (Josys, 2025)

11%

of what employees paste into AI tools is confidential (Cyberhaven, 2026)

In March 2026 a single contractor exploited a known vulnerability in McKinsey's internal AI assistant and extracted 46.5 million confidential conversations referencing 728,000 client files in two hours. In 2023, Samsung engineers pasted proprietary semiconductor source code into the consumer version of ChatGPT within twenty days of lifting an internal ban. That data entered the model's training pipeline and cannot be removed.

The regulatory floor is rising

Australian regulators have already moved.

The Office of the Australian Information Commissioner's October 2024 guidance made organisations directly accountable for any personal information employees enter into commercial AI tools, including ChatGPT, Copilot and Gemini.

Privacy Act reforms lifted maximum penalties for serious breaches to the greater of $50 million, three times the benefit obtained, or 30 per cent of adjusted turnover.

The Australian Signals Directorate's March 2026 update to the Information Security Manual introduced its first formal AI-specific controls. Australia's Voluntary AI Safety Standard set out ten guardrails covering transparency, accountability, human oversight and data governance.

In February 2025, the Australian Government banned DeepSeek from all federal devices under Direction 001-2025, citing foreign-government access risk under China's National Intelligence Law.

The lesson was never “ban AI.” The lesson was “ungoverned AI is the risk.”

Built for

Regulated Australian organisations without the headcount of a Fortune 500 security team

The organisations most exposed to the current visibility gap. Built to enterprise rigour, priced and packaged so a thirty-person team can actually say yes.

Professional services

Firms operating under client confidentiality obligations and rising AI-use scrutiny from auditors.

Healthcare providers

Clinical and operational teams where patient data cannot move to offshore consumer AI tools.

NDIS operators

Providers carrying Practice Standards and Quality and Safeguards obligations with limited compliance headcount.

Financial services

Regulated entities where data residency, auditability and CPS 234 alignment are non-negotiable.

Government suppliers

Organisations that need to evidence PSPF, ISM and supply-chain assurance before contract.

Defence industry

Suppliers and primes who need DISP-ready governance with sovereign data handling.

Research institutions

Universities and labs balancing open collaboration with ethics, IP and DISP-related expectations.

At a glance

Everything in Opti Assist Free

  • Sovereign Australian-hosted infrastructure
  • No data sent to third-party AI providers
  • No training on user inputs
  • Compliance gap analysis with scored readiness across eight frameworks
  • Specialist industry agents personalised to your sector
  • 100,000 OO Credits every month
  • Free Microsoft 365 work-email sign-up
  • Clear upgrade path to paid Opti Assist and Opti Core tiers when you need more

Need more than one user, additional credits, Deep Research, automated workflows or full governance, risk and compliance tooling? Paid Opti Assist and Opti Core tiers are built on the same sovereign architecture.

Know where you stand. In about fifteen minutes.

Sign in with your Microsoft 365 work or school account. No credit card, no procurement approval, no trial period. Your data stays in your tenant, in Australia, always.