Skip to content

Security & data governance

Your clients’ data deserves better than “100% secure”.

Every outsourcing provider says their systems are secure. Here is the specific list of controls we operate, what each one actually does, and where your obligations under the Privacy Act 2020 sit.

Control summary

At a glance
Transit
TLS 1.3, portal only
At rest
AES-256
Identity
Named accounts, MFA enforced
Access
Role-based, scoped to the job
Logging
Immutable, every file event
Email
No client documents, ever
Offboarding
Access revoked same day
Controls architecture

Twelve controls, and what each one does.

Written so your IT adviser can assess them properly, rather than so they sound reassuring.


Security controls and their technical or procedural implementation
RefControlImplementation
S‑01Multi-factor authenticationApp-based or hardware second factor enforced on every cloud system and every user, with no exemption path for convenience.
S‑02Individual named accountsNo shared or generic logins anywhere in the environment. Every action in a client file is attributable to one person.
S‑03Role-based access controlAccountants can open only the files assigned to their active jobs. Access to a client ends when the job does.
S‑04Encryption in transit and at restTLS 1.3 for everything moving between systems, AES-256 for everything stored.
S‑05Secure document exchangeFiles move through the portal only. Client documents are never sent or received as email attachments, in either direction.
S‑06Immutable audit loggingEvery upload, view, edit and download recorded with user, timestamp and file. Logs are write-once and cannot be edited by the team they record.
S‑07Download and media restrictionDownloads to unmanaged devices blocked, USB and removable storage disabled at the endpoint, and a clean desk policy in the delivery centre.
S‑08Confidentiality agreementsBinding confidentiality, intellectual property and data restraint terms signed by every staff member before any access is granted.
S‑09Ongoing security trainingRegular cyber security and data privacy training, including phishing simulation, for everyone who touches client data.
S‑10Offboarding and revocationSingle sign-on revocation triggered by the HR offboarding process, so access ends the same day a person does.
S‑11Backup and disaster recoveryContinuous encrypted cloud backup with documented recovery objectives and periodic restore testing. See continuity.
S‑12Incident and breach responseA documented response process aligned to the notifiable privacy breach requirements of the Privacy Act 2020. See breach notification.
Privacy Act 2020

Cross-border disclosure, and what it asks of you.

Our delivery team is in India, which means your client’s personal information is disclosed outside New Zealand. That engages Information Privacy Principle 12, and it is your practice that carries the obligation.

We would rather put this in front of you at the start than have it surface in a professional standards review later.

What IPP 12 requires

Under Information Privacy Principle 12, a New Zealand agency may disclose personal information to a foreign person or entity only where it is satisfied that comparable safeguards apply, or where another listed ground is met.

What we do to support it

  • Contractual undertakings requiring us to protect personal information to a standard comparable to the Privacy Act 2020
  • Written detail of where data is stored, who can reach it, and under what controls
  • Confidentiality and data restraint terms binding every individual with access
  • A named contact for privacy questions and for any request your client makes
  • Breach notification to your practice without delay, so you can meet your own obligations

What stays with your practice

  • Your privacy statement and engagement terms disclosing overseas processing
  • Your assessment that the arrangement satisfies IPP 12
  • Any notification the Privacy Commissioner or an affected person is entitled to

This page describes the controls we operate. It is not legal advice. Your own legal adviser and your professional body’s guidance should confirm how your engagement terms and privacy statement are worded.

Business continuity

If something fails.

Your deadlines do not move because our infrastructure had a bad day. Continuity is planned for and tested rather than assumed.

  • Continuous encrypted backup of all working data
  • Documented recovery time and recovery point objectives
  • Periodic restore testing, because an untested backup is a guess
  • Redundant connectivity and power at the delivery centre
  • Cross-trained staff, so one person’s absence does not stall your file
  • A documented plan for continuing work from an alternate location
Incident response

If something goes wrong.

A notifiable privacy breach is one that has caused, or is likely to cause, serious harm. Our process is built so your practice can meet its own notification duty in time.

IR 01

Contain

Access suspended and the affected system isolated immediately.

IR 02

Notify you

Your practice is told without delay, with what we know at that point.

IR 03

Assess

Scope, data involved and likelihood of serious harm established from the audit logs.

IR 04

Support notification

We give you what you need for the Privacy Commissioner and affected people.

IR 05

Remediate

Root cause fixed, controls changed, and a written report back to you.

Want your IT adviser to interrogate this?

Good. Book a security briefing and bring them. We will walk through the control list, the data flow and the contractual position in detail.

You manage the client. We help you manage the workload.

Start with one job. No retainer, no minimum term, no obligation to continue.