Security
Practical, auditable cyber security.
How we secure customer data, applications, and infrastructure. Effective April 2026.
- Australian Privacy Principles
- Notifiable Data Breaches scheme
- ACSC Essential Eight
- ISO/IEC 27001 principles
- OWASP Top 10
Our approach
SiteSherpa takes a proportionate, risk-based approach to cyber security aligned with the Australian Privacy Principles (Privacy Act 1988), the Notifiable Data Breaches scheme, and recognised frameworks including the ACSC Essential Eight and ISO/IEC 27001 principles. As a focused SaaS provider, our controls are deliberately practical, auditable, and consistent with how we build and operate.
Governance
Cyber security is owned by the SiteSherpa leadership team. A designated officer is accountable for policy, incident response, and annual review. All personnel acknowledge our internal policy on commencement and complete refresher training annually.
Access & identity
- Multi-factor authentication is enforced on all business-critical systems.
- Access is granted on a least-privilege, role-based basis and reviewed quarterly.
- Access is revoked immediately on role change or offboarding.
Data protection
- Customer data is encrypted in transit (TLS 1.2+) and at rest.
- Customer data is logically segregated and accessed on a need-to-know basis.
- Backups are taken daily, encrypted, and restoration is tested on a scheduled basis.
- Personal information is handled in line with the Australian Privacy Principles.
Secure development
- All code changes pass documented peer review before release.
- Every change undergoes automated security review before merge, covering common vulnerability classes including the OWASP Top 10.
- Third-party dependencies are monitored for known vulnerabilities and patched on a defined cadence.
Third-party & vendor management
We engage a limited set of reputable cloud and identity providers, giving preference to vendors holding recognised certifications such as SOC 2 or ISO/IEC 27001. Vendors are assessed before engagement and reviewed annually.
Incident response & notification
SiteSherpa maintains a documented incident response plan with defined roles, escalation paths, and notification timelines. Where an incident meets the eligible data breach threshold under the Notifiable Data Breaches scheme, SiteSherpa will notify the OAIC and affected individuals within statutory timeframes. Affected customers will be notified without undue delay, consistent with contractual obligations.
Business continuity
Our SaaS platform runs on resilient, managed cloud infrastructure with regional redundancy. Recovery Time Objective (RTO) and Recovery Point Objective (RPO) targets are defined in our full policy and reviewed annually.
People
All personnel complete cyber security awareness training on commencement and annually thereafter. Confidentiality obligations are built into every engagement agreement.
Continuous improvement
This policy is reviewed at least annually, and after any material incident or significant change to our operating environment.
Need the full policy?
The full SiteSherpa Cyber Security Policy (v1.0) is available to current and prospective customers under NDA. Contact your SiteSherpa representative or get in touch.
See also our Trust Centre, Privacy & Cookies Policy, and Terms & Conditions.