Trust & Security · Built for regulated enterprises

Trust and security. Architected from day one.

One security architecture. Every customer. Whether you're a small team running One Lite or a regulated enterprise running the full platform, you sit on the same sovereign Australian infrastructure and the same security commitments.

Trust & Security
Hosted in AU
TS
Sovereign · GCP Australia
ISO 27001:2022
In progress · Q4 2026
Certification
SOC 2 Type 1
Planned · Q3 2026
Service org control
APRA CPS 230
CPS 234 · Aligned
Prudential
GCP Australia
Sydney primary · Melbourne DR
Data residency
🇦🇺🇳🇿🇭🇰🇻🇳🇲🇾🇹🇼🇦🇪🇸🇦🇶🇦🇵🇰
Designed for Australia, New Zealand, APAC and GCC markets
01Compliance status

Four programs. Honest reporting.

We publish the real status of every compliance program - what is complete, what is in flight, and what is planned. No ambiguous "ISO-aligned" claims. You will see exactly where we are, with target dates and audit body engagement where confirmed.

In progress

ISO/IEC 27001:2022

Information Security Management System certification - international standard for information security management. Targeted for Q4 2026 with a recognised certification body.

Scope defined · ISMS documentation in placeDone
Risk assessment and treatment planDone
Statement of Applicability · Annex A controlsDone
Internal audit cycle · first roundQ2 2026
Stage 1 audit · certification bodyQ3 2026
Stage 2 audit · certificationQ4 2026
Planned · Q3 2026

SOC 2 Type 1

American Institute of CPAs Service Organization Controls - Type 1 report covering the design of security, availability, and confidentiality controls. Type 2 to follow on a six-month observation window.

Control framework mapped to Trust Service CriteriaDone
Evidence collection infrastructureQ2 2026
Type 1 report · point-in-timeQ3 2026
Observation period beginsQ3 2026
Type 2 report · six-month windowQ1 2027
Aligned

APAC Financial Regulators

Alignment with prudential and operational risk regulators across Australia, New Zealand and Hong Kong - the largest financial markets in the region.

APRA CPS 230 · operational risk (Australia)Done
APRA CPS 234 · information security (Australia)Done
NZISM · information security (New Zealand)Done
HKMA TM-G-1 · operational resilience (Hong Kong)Done
Continuous control monitoringOngoing
Aligned

APAC Privacy & Data Protection

Privacy regulations vary across the region. We align to the strictest applicable standard per customer jurisdiction - by default, not by request.

Privacy Act 1988 and Australian Privacy PrinciplesDone
Privacy Act 2020 (New Zealand)Done
Personal Data (Privacy) Ordinance (Hong Kong)Done
GDPR-aligned data subject rights (baseline)Done
UAE PDPL · Saudi PDPL alignmentQ3 2026
02Data residency & infrastructure

Sovereign Australian residency. By default.

Customer data is held in Google Cloud Platform Australia - Sydney as primary, Melbourne as disaster recovery. Residency is a contract-level commitment: customer data - primary, backup, analytics, logs - does not leave the Australian region. Additional Asia-Pacific regions are on the platform roadmap as customer demand and regulatory drivers warrant.

- Infrastructure at a glance
Cloud provider
Google Cloud Platform
Single-cloud
Primary region
australia-southeast1 Sydney
Live
Disaster recovery
australia-southeast2 Melbourne
Live
APAC roadmap regions
Auckland · Hong Kong · Ho Chi Minh City (subject to customer demand)
Roadmap
Data residency
Australia · contract-level commitment
Guaranteed
Encryption · at rest
AES-256 · Google-managed keys default · CMEK on Enterprise
Encryption · in transit
TLS 1.3 only · HSTS enforced · older versions blocked at load balancer
Backup retention
35 days rolling · Point-in-time recovery enabled
Recovery objectives
RTO 4 hours · RPO 15 minutes · DR test conducted quarterly
03Security architecture

Defence in depth. Architected from day one.

Security is built into every module, every deployment, every user interaction - not added as a layer at the end. Six controls your security team will ask about first.

- 01 · Authentication

SSO · MFA · session control

Single Sign-On via SAML 2.0 and OIDC (Okta, Microsoft Entra ID, Google Workspace, Azure AD). Multi-factor authentication enforceable at tenant level. Session management with configurable timeouts. Password policy defaults exceed NIST SP 800-63B.

- 02 · Encryption

AES-256 at rest · TLS 1.3 in transit

AES-256 encryption at rest for all customer data including backups, with Google-managed keys by default. TLS 1.3 only in transit - older versions blocked at the load balancer. Customer-managed encryption keys (CMEK) available on Enterprise tier.

- 03 · Role-based access

Granular RBAC · least-privilege default

Granular role-based access control across all twelve disciplines. Role templates for Admin, Assessor, Reviewer, and Executive. Custom roles available on Enterprise. Least-privilege by default. Every permission change audit-logged.

- 04 · Audit logging

Immutable · 7-year retention

Every user action, every data change, every permission modification - logged to a write-once audit store. Retained for seven years by default. Exportable via API. Tamper-evident, cryptographically signed.

- 05 · Backup & DR

PITR · 35-day retention · quarterly DR test

Point-in-time recovery on primary databases. Daily backups to australia-southeast2 Melbourne with 35-day retention. RTO 4 hours, RPO 15 minutes. Disaster recovery test conducted quarterly with documented results.

- 06 · Incident response

NIST SP 800-61 aligned · 72-hour notification

Documented incident response plan aligned to NIST SP 800-61. Severity-based service level agreements for customer notification - 72-hour maximum for any security incident affecting customer data. Post-incident reports provided for Enterprise customers.

04Operational security

The controls behind the platform.

Technical controls are the easy half. Operational controls - the people, processes, and vendors that surround the platform - are where most incidents originate. Four areas where the discipline matters most.

- 01

Personnel vetting

Every employee and contractor with production access passes a police check, reference verification, and confidentiality undertaking. Production access is role-based, time-limited, and reviewed quarterly. No shared credentials, ever.

- 02

Security training

Mandatory annual security awareness training for all staff. Role-specific training for engineers (secure coding, OWASP Top 10), customer success (social engineering, data handling), and leadership (incident decision-making). Completion tracked, refresher enforced.

- 03

Vendor assessment

Every sub-processor undergoes security review before onboarding. Data Processing Agreements in place with all vendors who touch customer data. Sub-processor list published and updated on change - see Section 06. Exits from vendors who fall below the bar.

- 04

Change management

All production changes follow a controlled process - code review, automated testing, staging validation, approved change window. Emergency changes are exception-handled and documented. Every deployment traceable to a ticket and an author.

05Data handling commitments

Your data is your data.

Beyond the compliance framework, four commitments govern how we handle customer data. These are written into every contract and applied to every engagement - without exception.

No data sold. No data licensed.

We do not sell customer data. We do not anonymise and license it. We do not use it to train third-party models. Customer data supports the customer's engagement and account - and nothing else. Aggregate, fully-anonymised benchmarking statistics are produced from customer data with explicit opt-in.

No advertising. No third-party trackers.

No third-party advertising trackers, no behavioural analytics pixels, no retargeting cookies. The product does not serve advertisements - not now, not ever. First-party telemetry is minimal and purpose-limited to product quality and customer support.

Data stays in your declared region.

Customer data does not leave the region declared in the contract. Primary, backup, analytics and logs are all in-region - currently Australia. Offshore support access is not the default - it is a per-ticket exception requiring written customer approval, logged and reviewable.

Customer-owned. Fully exportable.

Customer data belongs to the customer. On termination, we provide a full export in standard formats (JSON, CSV, XLSX, PDF) within 30 days, and delete originals within 60 days. No ransom, no lock-in, no last-minute exit fees.

06Sub-processors

Sub-processors. Transparent and reviewed.

Our primary infrastructure sub-processor is published below. Additional sub-processors are disclosed in the trust pack under NDA - every vendor has a signed Data Processing Agreement and undergoes periodic security review. The complete list is updated whenever a vendor is added, removed, or changes region.

- Vendor
Purpose
Status
Google Cloud Platform
Primary cloud infrastructure - compute, storage, databases, networking. Australian regions only.
DPA signed
- Additional sub-processors disclosed under NDA. Request the trust pack for the complete list, including DPA scope and data residency confirmation for each vendor.
07Responsible disclosure

Found a security issue? Tell us directly.

We welcome and credit security researchers who report vulnerabilities through responsible disclosure. We commit to acknowledging within 48 hours, triaging within 5 business days, and keeping you informed through to remediation.

Please access only the data necessary to demonstrate the issue, and refrain from publication until remediation is complete. Researchers who follow responsible disclosure are credited publicly (with their consent) once the issue is closed. A formal bug bounty program is in development - early contributors will be credited at launch.
- Subject line"Security"
- PGP keyAvailable on request
- Response SLA48 hours · 5 business days triage
08Trust pack

Need the full compliance pack?

For APRA-regulated customers, government tenders, and enterprise security reviews, we provide a detailed trust pack under NDA - covering the Information Security Management System summary, security architecture documentation, sub-processor list with DPA references, penetration test reports, and relevant policy documents. Available to verified prospects in active evaluation.