Trust, transparency, and compliance
What we do, who we share data with, and how we're tracking against the certifications our customers care about.
Compliance posture
ISO/IEC 27001
AlignedAnnex A controls library implemented; row-level security on every database table, TOTP MFA, scoped admin access via warroom_admins, mission audit log, and security_audit_log table. Certification target Q4 2026.
Essential Eight (ACSC)
Self-assessedMFA enforced via Supabase TOTP, application control via row-level security, restricted admin privileges via warroom_admins table, regular patching cadence, daily backups via Supabase PITR. Maturity Level 2 across the eight controls.
NIST CSF 2.0
MappedGovern via Compliance Navigator advisor; Identify via Mission Gap Radar; Protect via security_audit_log + RLS; Detect via real-time mission audit; Respond via tactical execution tracker; Recover via Supabase PITR backups.
ISO/IEC 42001 (AI governance)
AlignedAI risk register, advisor instruction governance via admin panel, mission audit log capturing every AI interaction, prompt-injection guardrails, and de-identified output review process.
APRA CPS 234
MappedInformation-security capability commensurate with size and complexity, incident reporting via security@fortecyberx.au within 72 hours, and annual control testing aligned to APRA expectations.
SOCI Act / Cyber Security Act 2024
MappedCritical infrastructure obligations mapped via Compliance Navigator advisor; mandatory incident reporting workflows and risk-management programme documentation supported.
Privacy Act 1988 (Cth)
CompliantAPP 1–13 alignment; OAIC complaint pathway documented; full disclosures in our Privacy Policy.
GDPR
ReadyEU/UK addendum in Privacy Policy; DPA available on request; lawful basis register maintained for EU/UK data subjects.
Certification roadmap
SOC 2 Type I
ISO 27001 certification
IRAP assessment
Sub-processors
| Vendor | Region | Purpose |
|---|---|---|
| Supabase | Australia | Database, auth, storage, edge functions |
| Stripe | AU / US | Payment processing |
| Mailjet | EU | Transactional email |
| Resend | US | Transactional email (fallback) |
| OpenAI | US | LLM inference |
| Google AI | US | LLM inference (Gemini) |
| HubSpot | US | Support tickets, CRM |
| Cloud hosting & edge compute | Global edge | Application hosting and edge runtime |
| Amplitude | US | Product analytics |
| US | Marketing attribution |
Data Processing Agreement
DPA template available on request. Contact us via the support channel below.
Compliance enquiries: trust@fortecyberx.au