Security & data governance
Your clients’ data deserves better than “100% secure”.
Every outsourcing provider says their systems are secure. Here is the specific list of controls we operate, what each one actually does, and where your obligations under the Privacy Act 2020 sit.
Control summary
At a glance- Transit
- TLS 1.3, portal only
- At rest
- AES-256
- Identity
- Named accounts, MFA enforced
- Access
- Role-based, scoped to the job
- Logging
- Immutable, every file event
- No client documents, ever
- Offboarding
- Access revoked same day
Twelve controls, and what each one does.
Written so your IT adviser can assess them properly, rather than so they sound reassuring.
| Ref | Control | Implementation |
|---|---|---|
| S‑01 | Multi-factor authentication | App-based or hardware second factor enforced on every cloud system and every user, with no exemption path for convenience. |
| S‑02 | Individual named accounts | No shared or generic logins anywhere in the environment. Every action in a client file is attributable to one person. |
| S‑03 | Role-based access control | Accountants can open only the files assigned to their active jobs. Access to a client ends when the job does. |
| S‑04 | Encryption in transit and at rest | TLS 1.3 for everything moving between systems, AES-256 for everything stored. |
| S‑05 | Secure document exchange | Files move through the portal only. Client documents are never sent or received as email attachments, in either direction. |
| S‑06 | Immutable audit logging | Every upload, view, edit and download recorded with user, timestamp and file. Logs are write-once and cannot be edited by the team they record. |
| S‑07 | Download and media restriction | Downloads to unmanaged devices blocked, USB and removable storage disabled at the endpoint, and a clean desk policy in the delivery centre. |
| S‑08 | Confidentiality agreements | Binding confidentiality, intellectual property and data restraint terms signed by every staff member before any access is granted. |
| S‑09 | Ongoing security training | Regular cyber security and data privacy training, including phishing simulation, for everyone who touches client data. |
| S‑10 | Offboarding and revocation | Single sign-on revocation triggered by the HR offboarding process, so access ends the same day a person does. |
| S‑11 | Backup and disaster recovery | Continuous encrypted cloud backup with documented recovery objectives and periodic restore testing. See continuity. |
| S‑12 | Incident and breach response | A documented response process aligned to the notifiable privacy breach requirements of the Privacy Act 2020. See breach notification. |
Cross-border disclosure, and what it asks of you.
Our delivery team is in India, which means your client’s personal information is disclosed outside New Zealand. That engages Information Privacy Principle 12, and it is your practice that carries the obligation.
We would rather put this in front of you at the start than have it surface in a professional standards review later.
What IPP 12 requires
Under Information Privacy Principle 12, a New Zealand agency may disclose personal information to a foreign person or entity only where it is satisfied that comparable safeguards apply, or where another listed ground is met.
What we do to support it
- Contractual undertakings requiring us to protect personal information to a standard comparable to the Privacy Act 2020
- Written detail of where data is stored, who can reach it, and under what controls
- Confidentiality and data restraint terms binding every individual with access
- A named contact for privacy questions and for any request your client makes
- Breach notification to your practice without delay, so you can meet your own obligations
What stays with your practice
- Your privacy statement and engagement terms disclosing overseas processing
- Your assessment that the arrangement satisfies IPP 12
- Any notification the Privacy Commissioner or an affected person is entitled to
This page describes the controls we operate. It is not legal advice. Your own legal adviser and your professional body’s guidance should confirm how your engagement terms and privacy statement are worded.
If something fails.
Your deadlines do not move because our infrastructure had a bad day. Continuity is planned for and tested rather than assumed.
- Continuous encrypted backup of all working data
- Documented recovery time and recovery point objectives
- Periodic restore testing, because an untested backup is a guess
- Redundant connectivity and power at the delivery centre
- Cross-trained staff, so one person’s absence does not stall your file
- A documented plan for continuing work from an alternate location
If something goes wrong.
A notifiable privacy breach is one that has caused, or is likely to cause, serious harm. Our process is built so your practice can meet its own notification duty in time.
IR 01
Contain
Access suspended and the affected system isolated immediately.
IR 02
Notify you
Your practice is told without delay, with what we know at that point.
IR 03
Assess
Scope, data involved and likelihood of serious harm established from the audit logs.
IR 04
Support notification
We give you what you need for the Privacy Commissioner and affected people.
IR 05
Remediate
Root cause fixed, controls changed, and a written report back to you.
Want your IT adviser to interrogate this?
Good. Book a security briefing and bring them. We will walk through the control list, the data flow and the contractual position in detail.