Trust Centre

CC1
Control Environment
CC.01.01
Board Oversight

The Board of Directors meets at least annually, dependent on organisational needs, and exercises oversight of the development and implementation of internal controls.

CC.01.02
Management Oversight

Company management meets monthly against a recommended agenda to oversee the company's objectives.

CC.01.03
Organisational Structure

The company has defined structures and reporting lines with assigned authority and responsibilities in order to appropriately meet security requirements.

CC.01.04
Policies & Procedures

Formal policies and procedures are documented, reviewed, and approved annually by management, and are available to employees.

CC.01.05
Code of Conduct

Employees and contractors are required to read and accept the Code of Conduct and Acceptable Use Policy. Signed employment agreements contain a confidentiality clause, and management monitors compliance.

CC.01.07
Background Screening

The company conducts pre-employment screening checks commensurate with the role, in accordance with local laws and the HR policy. The same process is followed for contractors.

CC.01.08
Onboarding

New employees and contractors complete an onboarding process covering role responsibilities, organisational policies, and provisioning of relevant access.

CC.01.09
Training & Competency

The company provides education and training to ensure the skill sets and technical competency of relevant employees are developed and maintained.

CC.01.10
Performance Reviews

The company performs an annual performance review of all employees with 12 or more months of tenure, evaluated in alignment with the company's objectives.

CC.01.11
Disciplinary Process

A disciplinary process is established and communicated to take action against personnel and other relevant parties who violate information security policy.

CC2
Communication & Information
CC.02.01
System Documentation

A detailed description of the product architecture and system boundaries is documented and available internally to the company's employees.

CC.02.02
Awareness Training

The company maintains a Security and Privacy Awareness Training program that all employees are required to complete every year.

CC.02.03
Internal Knowledge Base

The company maintains an internal knowledge base describing its environment, boundaries, user responsibilities, and services.

CC.02.04
Incident Communication

Detected security incidents are communicated to and reviewed by the individual responsible for security management in the company.

CC.02.05
External Documentation

The company maintains external documentation describing product features, system boundaries, and user guides.

CC.02.06
Release Communication

New features are communicated to customers in the documentation portal to keep them updated on major product releases.

CC.02.08
Status Page

Service interruptions are communicated to customers via the status page.

CC.02.09
Support Tooling

Client issues are reported via a dedicated support tool and handled using a ticketing system.

CC.02.11
Support Channels

Customer support issues are handled through the relevant communication channels.

CC3
Risk Assessment
CC.03.01
Risk Management Program

The company maintains a formal risk management program to assess information security risks affecting its business objectives, regulatory requirements, and customers. Treatment options include acceptance, avoidance, mitigation, and transfer.

CC.03.03
Annual Risk Assessment

The annual risk assessment summary is presented to senior management for review, comment, and approval. Minutes and action items are documented.

CC.03.04
Asset Inventory

The company identifies, classifies, and manages an inventory of information assets, which is reviewed by management on an annual basis.

CC4
Monitoring Activities
CC.04.01
Penetration Testing

An external web application penetration test is conducted annually to identify gaps and vulnerabilities.

CC6
Logical Access & Encryption
CC.06.01
Access Approval

All access requests to organisational systems, including administrator accounts, are approved prior to access provisioning.

CC.06.02
Access Control Matrix

The company manages access governance through a group-based access control matrix that reflects the minimum access required to perform each business function.

CC.06.03
Password Standard

A formal password standard governs authentication: a minimum of 8 characters, mixed character types, reuse prevention where possible, expiry of at most 365 days where technically possible, and mandatory two-factor authentication.

CC.06.05
Identity Management Access

Access to the identity management tool uses two-factor authentication and is restricted to authorised personnel.

CC.06.06
Production Console Access

Access to the production environment console is restricted to authorised personnel and uses a two-factor authentication method.

CC.06.09
Source Control Access

Access to the source control tool uses two-factor authentication and is restricted to authorised personnel.

CC.06.10
Production Server Access

Access to the production server is performed using an SSH key and is restricted to authorised personnel.

CC.06.11
Backup Access

The ability to alter and delete backups is restricted to authorised users and uses two-factor authentication.

CC.06.13
Key Management

An established key management process supports the use of cryptographic techniques. Generating, storing, using, rotating, and destroying encryption keys is defined in the Encryption policy.

CC.06.14
User Provisioning

Provisioning of new user access is performed as part of the onboarding process, documented and collaborated on in a GitHub Issue ticket.

CC.06.16
Deprovisioning

User accounts for terminated users are disabled or deleted in a timely manner upon notification of termination. Organisational assets are returned and wiped clean.

CC.06.17
Quarterly Access Reviews

User access and permissions in restricted environments are reviewed and approved by management on a quarterly basis.

CC.06.21
Network Security Groups

Inbound and outbound traffic rules are configured via network security groups in the production environment.

CC.06.22
Password Protection

Customer passwords are protected through hashing and salting.

CC.06.23
Encryption in Transit

Communication between customers and company assets is encrypted using a valid HTTPS TLS 1.2 (or above) authenticated certificate.

CC.06.24
Encryption at Rest

Restricted information assets containing sensitive customer data on databases, storage, and backups are at least disk-level encrypted.

CC.06.25
Device Hardening

Employee devices are secured with OS-appropriate settings: Windows via Intune (disk encryption, auto-patching, auto screen-lock); macOS (disk encryption, automatic updates, lock screen); Linux (disk encryption, lock screen).

CC.06.29
Malware Protection

Windows endpoints are centrally configured with Microsoft Defender; macOS endpoints use XProtect and Gatekeeper to protect against malware.

CC.6.5.DD
Device Data Disposal

A procedure ensures data and software stored on organisational devices is identified and disposed of in an appropriate manner.

CC7
System Operations
CC.07.02
Audit Logging

An audit trail of security logs runs continuously in the production environment, capturing actions made to cloud resources and object-level storage actions.

CC.07.03
Log Retention

Audit trail security logs are configured to be retained for a minimum of 7 days.

CC.07.04
Threat Detection

A detection service continuously monitors the production environment for malicious and unexpected activity. Alerts are sent to relevant stakeholders, and incidents are reviewed and resolved per the vulnerability and threat management policy.

CC.07.06
Incident Response Policy

A Security Incident Response Policy governs response to security incidents and personal data breaches in accordance with applicable laws and regulations. Data restoration checks are performed annually.

CC.07.07
Contingency Playbooks

Contingency planning and incident response playbooks are maintained and updated to reflect emerging continuity risks and lessons learned from past incidents.

CC.07.08
Root Cause Analysis

A root cause analysis is prepared and reviewed by management for high-severity incidents, with change requests raised for remediation and resolution.

CC8
Change Management
CC.08.01
Change Tracking

Change requests are documented as tickets in the change management system, with pull requests and change tickets linked so each code change can be tracked.

CC.08.04
Code Review

Code changes must be reviewed and approved in order to progress through the SDLC and deploy a version to production.

CC.08.05
Dependency Scanning

Source code dependencies and packages are scanned on an ongoing basis for vulnerabilities. Detected issues trigger an update pull request and are logged and resolved per policy.

CC.08.07
Test Gating

A successful test result is mandatory to continue the SDLC and deploy to production. On test failure, the build is stopped and does not deploy.

CC.08.11
Environment Segregation

Production and non-production environments are segregated to enforce the confidentiality and privacy of customer data.

CC9
Vendor Management
CC.09.02
Vendor Risk Assessment

The company assesses, on an annual basis, the risks that vendors and business partners represent to the achievement of its objectives.

CC.09.04
Vendor SOC 2 Review

The company reviews critical vendors' SOC 2 reports annually, documenting the controls in place to address CUECs, any noted deviations, and the auditor's opinion.

CC.09.05
Vendor Commitments

IT vendors that engage with the company are subject to information security, confidentiality, and privacy commitments as part of their agreements.

AV
Availability & Resilience
AV.01.03
Backup Zone Isolation

Critical system components are deployed within a single availability zone, with backups stored in a different availability zone to address the risk of zone loss.

AV.03.01
Disaster Recovery Plan

A Disaster Recovery Plan is maintained to continue providing critical services in the event of a disaster, and is reviewed on an annual basis.

AV.03.02
DR Testing

Disaster recovery testing is conducted annually. Participating teams develop test plans and post-mortems documenting the results and lessons learned.

CO
Confidentiality
CO.01.01
Data Identification

Data assets containing customer and confidential information are identified and protected, with retention based on asset type and management commitments.

CO.01.02
Data Tracking

The company can track and identify customer data across its assets, including databases, storage, and backups.

CO.02.02
Secure Disposal

Procedures are in place to dispose of confidential information in accordance with the company's data retention and disposal policy.