quantivate

Security

How data is held, who can reach it, and how to report a problem.

Where data sits

All client data is held and processed in Australia, unless the agency agrees otherwise in its contract.

The hosting provider and region for each engagement are agreed with the agency, to meet its data sovereignty and residency obligations. We do not move client data to a different provider or region without the agency’s written agreement.

Access and personnel

All our people hold current Australian Government security clearances at the levels our work requires. We confirm levels to an agency directly rather than publishing them.

Access to client data follows zero trust principles as defined by NIST in SP 800-207, and we apply the Information Security Manual (ISM) controls for PROTECTED information, or higher where an engagement requires it. The detail of our controls is available to an agency on request.

Assurance

We do not yet hold ISO 27001 certification or an IRAP assessment. This page will say when either is under way.

We test security in line with ISM guidance for a cloud-hosted PROTECTED environment, scaled to the risks of each engagement. At minimum, testing runs once a year, after every major technical release, and out of cycle whenever a cyber event calls for it.

If a security incident affects an agency’s data, we notify that agency within 24 hours of becoming aware of it, then keep it informed until the incident is closed.

Reporting a vulnerability

If you think you have found a security problem in this site or in anything we operate, email security@quantivate.com.au. Describe what you found and how to reproduce it.

If you act in good faith — you access no more data than you need to show the problem, and you give us reasonable time to fix it before telling anyone else — we will not take legal action against you. We will tell you when we have received the report, keep you informed while we fix it, and credit you publicly if you want us to.