Security & data

You own your data. We hold it, in Australia, under audited controls.

Three questions decide whether a platform gets through a security review: who owns the record, where it lives, and who has independently checked that we run it properly. Sierra Acuity holds a current SOC 2 Type 2 attestation — the third question is answered before you ask it.

Attestation

SOC 2 Type 2 Current

Held and current. Controls independently tested as operating across an observation period, not designed on a single day. The report is provided under NDA, with a bridge letter between periods.

Ask us forPeriod · scope · criteria · auditor
Residency

Australian data centre

A named Australian facility, not a region label on a console. Customer data does not leave Australia.

Ask us forFacility · its certifications · the responsibility split
Ownership

The record is yours

Export in a machine-readable format at any time, free, during the term and 90 days after. We do not sell it.

In the termsClause 3 of the Master Terms
The control set

In the language your reviewer uses.

DomainWhat we doWhat you can verify
Access controlRole-based, least privilege, named accounts, MFA on every administrative path, quarterly reviews.Control listing · review evidence
EncryptionTLS 1.2+ in transit; at rest on database and backups; keys managed separately.Architecture description
LoggingAdministrative and data-access events logged and alerted. The audit trail cannot be edited from the application.Retention policy · alert workflow
Backup & recoveryPoint-in-time recovery with a stated RPO and RTO, tested rather than assumed.RPO / RTO · last restore test
VulnerabilityDependency scanning, patch windows, periodic external penetration testing.Pen-test summary
SubprocessorsA register naming every third party that can touch customer data, and what for.The current register
Incident responseSeverity model, named responders, a communications path that includes you.IR plan · last exercise

Where a row says ask us for, we mean it. Security questionnaire, architecture description, penetration-test summary, subprocessor register and the last restore-test result are available on request. We would rather send evidence than a logo.

Privacy

Personal information

  • A store that records who took what holds personal information, and we treat it that way rather than as machine data.
  • Customer data does not leave Australia. If that were ever to change for a specific service, you would be told before it happened, not after.
  • Notification obligations run in both directions and the committed timeframes sit in the Master Terms, where they are enforceable — not on a web page, where they are not.
Critical infrastructure

If you are a responsible entity

  • Tell us at scoping if this touches a critical infrastructure asset. It changes the assurance work, not the price.
  • We complete your supplier assurance process and provide the governance and architecture documentation your own obligations require.
  • Our regulatory position is maintained as a controlled document and reviewed on a schedule. Ask for it and your reviewer receives the current version.

We do not publish our legal or regulatory position as marketing copy. Obligations change, marketing pages do not, and a stale compliance claim is worse than none. What we commit to is in the Master Services & Licence Terms; how we meet it is in the governance and architecture documentation, provided to your reviewer under NDA and kept current.

The next step

Send this page to your security reviewer first.

They will have a questionnaire. We will complete it and send the evidence with it.

Request the security pack Ways to begin
Call1300 850 563