We hold ourselves to the standard we help you meet. Here is exactly where Detekta stands on security and privacy — stated plainly, so your risk team can verify it.
"Detekta elects to be treated as an ‘organisation’ under section 6EA of the Privacy Act 1988 (Cth) and complies with the Australian Privacy Principles (APPs)."
The architecture is built to the security baseline regulated buyers require — and the certified infrastructure underneath it.
TLS in transit and AES-256 at rest, on infrastructure certified to SOC 2 Type II and ISO 27001.
Each customer's data is logically isolated — never commingled across tenants.
Role-based access control and MFA/SSO; access scoped to the minimum, by default.
Every access and action logged to an immutable, reviewable trail.
Host data in BR, EU or AU regions — kept where your regulator expects it.
Encrypted, regularly tested backups with point-in-time recovery.
Dependencies and infrastructure continuously monitored and patched.
Keys and credentials held in a managed vault — never in code or config.
We do not train models on your customers' data. Your book is used to serve you, and only you.
Agents investigate and draft; a named person signs every decision. No silent automation.
Every score traces to the signals behind it, and every decision is replayable for an examiner.
We'll share our security package — architecture overview, sub-processors, data-flow and our infrastructure certifications — and walk your team through it.
No badge we haven't earned, no claim your team can't verify. That's the posture a compliance buyer should expect from a compliance vendor.