Defend. · Security & trust

Built to pass your security review.

We hold ourselves to the standard we help you meet. Here is exactly where Detekta stands on security and privacy — stated plainly, so your risk team can verify it.

detekta · trust posture
Australian Privacy Act · APPs (s.6EA)committed · OAIC
Infrastructure · SOC 2 Type II1certified
Infrastructure · ISO 270011certified
Detekta · SOC 2 Type IIin progress
GDPR · LGPDaligned
Data residency · BR · EU · AUsupported
1 Certifications held by Detekta's cloud & database infrastructure provider.
🇦🇺 Australian Privacy Principles · confirmed with the OAIC
"Detekta elects to be treated as an ‘organisation’ under section 6EA of the Privacy Act 1988 (Cth) and complies with the Australian Privacy Principles (APPs)."
We voluntarily opted in to regulation under Australia's Privacy Act — confirmed by the Office of the Australian Information Commissioner. Most vendors our size aren't bound by the APPs at all. We chose to be.
How your data is protected

The controls a risk team expects.

The architecture is built to the security baseline regulated buyers require — and the certified infrastructure underneath it.

🔐

Encrypted everywhere

TLS in transit and AES-256 at rest, on infrastructure certified to SOC 2 Type II and ISO 27001.

🧱

Per-tenant isolation

Each customer's data is logically isolated — never commingled across tenants.

🔑

Least-privilege access

Role-based access control and MFA/SSO; access scoped to the minimum, by default.

🧾

Audit logging

Every access and action logged to an immutable, reviewable trail.

🌍

Data residency

Host data in BR, EU or AU regions — kept where your regulator expects it.

💾

Backups & recovery

Encrypted, regularly tested backups with point-in-time recovery.

🛡️

Vulnerability management

Dependencies and infrastructure continuously monitored and patched.

🗝️

Secret management

Keys and credentials held in a managed vault — never in code or config.

AI & data handling

Your data stays yours.

🔒

Not our training data

We do not train models on your customers' data. Your book is used to serve you, and only you.

✍️

Human-in-the-loop

Agents investigate and draft; a named person signs every decision. No silent automation.

🔍

Explainable & reconstructable

Every score traces to the signals behind it, and every decision is replayable for an examiner.

Running a vendor security review?

We'll share our security package — architecture overview, sub-processors, data-flow and our infrastructure certifications — and walk your team through it.

Request the package
Detect. Decide. Defend.

Trust, stated plainly.

No badge we haven't earned, no claim your team can't verify. That's the posture a compliance buyer should expect from a compliance vendor.