How SurePact keeps your data secure
Best practice data storage backed by leading platforms
SurePact prioritises data security using Microsoft Azure, a leading cloud platform, to host our infrastructure in Australia. We employ robust measures, including data encryption at rest and mandatory SSL encryption for all network communications. This ensures your information remains protected during storage and transmission, adhering to industry best practices for data security and privacy. SSO is available to provide additional access security on the user’s end.
Regular testing and proactive reviews
We conduct regular security audits, including internal reviews and vulnerability scans, focusing on various aspects of our security framework. We carefully vet third-party vendors to meet our stringent security standards. Our cybersecurity measures include advanced logging and alerting systems, plus centralised management and monitoring of endpoint devices using enterprise-grade EDR solutions.
Staff training and access controls
Following the “Principle of Least Privilege” (POLP), we configure each account with only necessary permissions. Employees undergo mandatory cybersecurity training during induction and annual refresher courses. We assess these initiatives through simulated incidents like phishing campaigns and disaster recovery tests, ensuring our team is prepared for security challenges and maintains cybersecurity as a top priority.
What happens in the event of a suspected data breach
In the unlikely event of a suspected data breach, we have comprehensive procedures in place to respond swiftly and effectively:
Immediate Response
- We follow our documented incident response procedures and notification protocols as outlined in our cybersecurity risk management and IT policies.
- Our team employs advanced logging and monitoring systems to detect potential security threats promptly.
Assessment and Containment
- We quickly determine the scope and impact of the potential breach using our Information Security Management System (ISMS).
- Our data classification processes help identify the extent and nature of any compromised data.
Notification Process
- We have clear criteria for deciding when and how to notify affected customers, regulators, and other stakeholders about a confirmed breach.
- Our approach ensures consistent and practical management of information system incidents, from preparation to recovery.
- For high-severity incidents, we promptly notify affected customers as defined in our Incident Response Process.
- All data breach notifications comply with relevant privacy and data protection regulations, guided by our Incident Response Policy and Notifiable Data Breach Incident Response Plan.
Backup and Recovery
- Regular backups and disaster recovery procedures are in place to protect customer data.
- We conduct periodic backup and disaster recovery testing to ensure the effectiveness of our protection measures.
Certifications
SurePact’s information security management system, encompassing the SurePact platform, is ISO 27001:2022 certified
FAQ
Where is your data hosted?
SurePact data is hosted securely within Australia, and encrypted at rest with SSL security required for all network communication.
What are your data retention and deletion policies for customer data?
SurePact, on the expiry of 6 months after the termination of a contract, will delete or destroy all customer data.