One security architecture. Every customer. Whether you're a small team running One Lite or a regulated enterprise running the full platform, you sit on the same sovereign Australian infrastructure and the same security commitments.
We publish the real status of every compliance program - what is complete, what is in flight, and what is planned. No ambiguous "ISO-aligned" claims. You will see exactly where we are, with target dates and audit body engagement where confirmed.
Information Security Management System certification - international standard for information security management. Targeted for Q4 2026 with a recognised certification body.
American Institute of CPAs Service Organization Controls - Type 1 report covering the design of security, availability, and confidentiality controls. Type 2 to follow on a six-month observation window.
Alignment with prudential and operational risk regulators across Australia, New Zealand and Hong Kong - the largest financial markets in the region.
Privacy regulations vary across the region. We align to the strictest applicable standard per customer jurisdiction - by default, not by request.
Customer data is held in Google Cloud Platform Australia - Sydney as primary, Melbourne as disaster recovery. Residency is a contract-level commitment: customer data - primary, backup, analytics, logs - does not leave the Australian region. Additional Asia-Pacific regions are on the platform roadmap as customer demand and regulatory drivers warrant.
australia-southeast1 Sydneyaustralia-southeast2 MelbourneSecurity is built into every module, every deployment, every user interaction - not added as a layer at the end. Six controls your security team will ask about first.
Single Sign-On via SAML 2.0 and OIDC (Okta, Microsoft Entra ID, Google Workspace, Azure AD). Multi-factor authentication enforceable at tenant level. Session management with configurable timeouts. Password policy defaults exceed NIST SP 800-63B.
AES-256 encryption at rest for all customer data including backups, with Google-managed keys by default. TLS 1.3 only in transit - older versions blocked at the load balancer. Customer-managed encryption keys (CMEK) available on Enterprise tier.
Granular role-based access control across all twelve disciplines. Role templates for Admin, Assessor, Reviewer, and Executive. Custom roles available on Enterprise. Least-privilege by default. Every permission change audit-logged.
Every user action, every data change, every permission modification - logged to a write-once audit store. Retained for seven years by default. Exportable via API. Tamper-evident, cryptographically signed.
Point-in-time recovery on primary databases. Daily backups to australia-southeast2 Melbourne with 35-day retention. RTO 4 hours, RPO 15 minutes. Disaster recovery test conducted quarterly with documented results.
Documented incident response plan aligned to NIST SP 800-61. Severity-based service level agreements for customer notification - 72-hour maximum for any security incident affecting customer data. Post-incident reports provided for Enterprise customers.
Technical controls are the easy half. Operational controls - the people, processes, and vendors that surround the platform - are where most incidents originate. Four areas where the discipline matters most.
Every employee and contractor with production access passes a police check, reference verification, and confidentiality undertaking. Production access is role-based, time-limited, and reviewed quarterly. No shared credentials, ever.
Mandatory annual security awareness training for all staff. Role-specific training for engineers (secure coding, OWASP Top 10), customer success (social engineering, data handling), and leadership (incident decision-making). Completion tracked, refresher enforced.
Every sub-processor undergoes security review before onboarding. Data Processing Agreements in place with all vendors who touch customer data. Sub-processor list published and updated on change - see Section 06. Exits from vendors who fall below the bar.
All production changes follow a controlled process - code review, automated testing, staging validation, approved change window. Emergency changes are exception-handled and documented. Every deployment traceable to a ticket and an author.
Beyond the compliance framework, four commitments govern how we handle customer data. These are written into every contract and applied to every engagement - without exception.
We do not sell customer data. We do not anonymise and license it. We do not use it to train third-party models. Customer data supports the customer's engagement and account - and nothing else. Aggregate, fully-anonymised benchmarking statistics are produced from customer data with explicit opt-in.
No third-party advertising trackers, no behavioural analytics pixels, no retargeting cookies. The product does not serve advertisements - not now, not ever. First-party telemetry is minimal and purpose-limited to product quality and customer support.
Customer data does not leave the region declared in the contract. Primary, backup, analytics and logs are all in-region - currently Australia. Offshore support access is not the default - it is a per-ticket exception requiring written customer approval, logged and reviewable.
Customer data belongs to the customer. On termination, we provide a full export in standard formats (JSON, CSV, XLSX, PDF) within 30 days, and delete originals within 60 days. No ransom, no lock-in, no last-minute exit fees.
Our primary infrastructure sub-processor is published below. Additional sub-processors are disclosed in the trust pack under NDA - every vendor has a signed Data Processing Agreement and undergoes periodic security review. The complete list is updated whenever a vendor is added, removed, or changes region.
We welcome and credit security researchers who report vulnerabilities through responsible disclosure. We commit to acknowledging within 48 hours, triaging within 5 business days, and keeping you informed through to remediation.
For APRA-regulated customers, government tenders, and enterprise security reviews, we provide a detailed trust pack under NDA - covering the Information Security Management System summary, security architecture documentation, sub-processor list with DPA references, penetration test reports, and relevant policy documents. Available to verified prospects in active evaluation.