Security at CyberNinja
We advise on security for a living — and we hold ourselves to the same standards we audit against.
ISO 27001
Certification in progress — audit expected 2026
Data residency
Compliance Desk customer data stays in Australia (Sydney)
Responsible disclosure
security@cyberninja.au — acknowledged within 2 business days
Subprocessors
11 vendors, security-reviewed and listed below
Last updated: August 2026
Compliance & Certifications
ISO/IEC 27001
Information security management system (ISMS)
We are implementing an ISO 27001-aligned ISMS and expect to complete our certification audit in 2026. The same risk assessments, policies, and control frameworks we build for clients are applied internally.
Essential 8
ACSC mitigation strategies
Our internal environment is hardened in line with the Australian Cyber Security Centre's Essential Eight.
ISO/IEC 42001
AI management system (AIMS)
Where we use AI internally, we manage it under an AI management system aligned with ISO 42001.
Data Residency
Compliance Desk — our compliance management platform — stores all customer data in Australia. Application infrastructure and databases run in the AWS Sydney region (ap-southeast-2), and no customer data is transferred offshore.
This marketing website is hosted on Vercel’s global edge network. It stores no client engagement data; the only personal information it processes is what you submit through our forms (see our Privacy Policy).
Security Practices
Application security
- Encryption in transit everywhere (TLS) with HSTS enforced.
- Encryption at rest for stored data and backups.
- Strict Content Security Policy, X-Frame-Options, and related security headers on all pages.
- Cloudflare Turnstile bot protection and IP-based rate limiting on every public form and API endpoint.
- Server-side validation of all user input (Zod schemas) and HTML-escaping of user content in outbound emails.
- Dependency security: patched versions of vulnerable transitive packages are pinned and reviewed.
Organisational security
- Multi-factor authentication required on all company accounts.
- Least-privilege access — staff only have access to the systems and data their role requires.
- Full-disk encryption on all company devices.
- Regular review of access, controls, and subprocessors.
Subprocessors
We use a small number of third-party providers to operate our business and deliver services. We review each provider’s security posture before adoption and on an ongoing basis.
Compliance Desk Customer data — Australia
| Vendor | Purpose | Data location |
|---|---|---|
| Amazon Web Services | Application hosting and infrastructure | Australia (Sydney, ap-southeast-2) |
| Neon | Managed PostgreSQL database | Australia (Sydney, ap-southeast-2) |
Website & business operations
These providers may process business contact details (e.g. your name and email when you contact us), but do not store Compliance Desk customer data.
| Vendor | Purpose | Data location |
|---|---|---|
| Vercel Inc. | Marketing website hosting and CDN | United States / global edge |
| Cloudflare | CAPTCHA bot protection (Turnstile) | Global |
| Resend Inc. | Transactional email delivery | United States |
| Google Workspace | Email, documents, and collaboration | United States / global |
| Slack | Internal communications | United States |
| Zoom | Video meetings and scheduling | United States / global |
| Atlassian | Project tracking and documentation | United States / global |
| Qwilr | Proposals and quotes | Australia / United States |
| PandaDoc | Contracts and e-signatures | United States |
Responsible Disclosure
If you believe you have found a security vulnerability in any CyberNinja system, we want to hear from you. Please report it to security@cyberninja.au. We will acknowledge your report within 2 business days and keep you informed as we investigate and remediate. We ask that you give us reasonable time to address the issue before any public disclosure.
Our disclosure policy metadata is published at /.well-known/security.txt.
Questions about our security?
Doing due diligence on us? We’re happy to walk you through our controls, policies, or anything on this page.