Skip to content

Security at CyberNinja

We advise on security for a living — and we hold ourselves to the same standards we audit against.

ISO 27001

Certification in progress — audit expected 2026

Data residency

Compliance Desk customer data stays in Australia (Sydney)

Responsible disclosure

security@cyberninja.au — acknowledged within 2 business days

Subprocessors

11 vendors, security-reviewed and listed below

Last updated: August 2026

Compliance & Certifications

ISO/IEC 27001

Information security management system (ISMS)

In progress

We are implementing an ISO 27001-aligned ISMS and expect to complete our certification audit in 2026. The same risk assessments, policies, and control frameworks we build for clients are applied internally.

Essential 8

ACSC mitigation strategies

Aligned

Our internal environment is hardened in line with the Australian Cyber Security Centre's Essential Eight.

ISO/IEC 42001

AI management system (AIMS)

Aligned

Where we use AI internally, we manage it under an AI management system aligned with ISO 42001.

Data Residency

Compliance Desk — our compliance management platform — stores all customer data in Australia. Application infrastructure and databases run in the AWS Sydney region (ap-southeast-2), and no customer data is transferred offshore.

This marketing website is hosted on Vercel’s global edge network. It stores no client engagement data; the only personal information it processes is what you submit through our forms (see our Privacy Policy).

Security Practices

Application security

  • Encryption in transit everywhere (TLS) with HSTS enforced.
  • Encryption at rest for stored data and backups.
  • Strict Content Security Policy, X-Frame-Options, and related security headers on all pages.
  • Cloudflare Turnstile bot protection and IP-based rate limiting on every public form and API endpoint.
  • Server-side validation of all user input (Zod schemas) and HTML-escaping of user content in outbound emails.
  • Dependency security: patched versions of vulnerable transitive packages are pinned and reviewed.

Organisational security

  • Multi-factor authentication required on all company accounts.
  • Least-privilege access — staff only have access to the systems and data their role requires.
  • Full-disk encryption on all company devices.
  • Regular review of access, controls, and subprocessors.

Subprocessors

We use a small number of third-party providers to operate our business and deliver services. We review each provider’s security posture before adoption and on an ongoing basis.

Compliance Desk Customer data — Australia

VendorPurposeData location
Amazon Web ServicesApplication hosting and infrastructureAustralia (Sydney, ap-southeast-2)
NeonManaged PostgreSQL databaseAustralia (Sydney, ap-southeast-2)

Website & business operations

These providers may process business contact details (e.g. your name and email when you contact us), but do not store Compliance Desk customer data.

VendorPurposeData location
Vercel Inc.Marketing website hosting and CDNUnited States / global edge
CloudflareCAPTCHA bot protection (Turnstile)Global
Resend Inc.Transactional email deliveryUnited States
Google WorkspaceEmail, documents, and collaborationUnited States / global
SlackInternal communicationsUnited States
ZoomVideo meetings and schedulingUnited States / global
AtlassianProject tracking and documentationUnited States / global
QwilrProposals and quotesAustralia / United States
PandaDocContracts and e-signaturesUnited States

Responsible Disclosure

If you believe you have found a security vulnerability in any CyberNinja system, we want to hear from you. Please report it to security@cyberninja.au. We will acknowledge your report within 2 business days and keep you informed as we investigate and remediate. We ask that you give us reasonable time to address the issue before any public disclosure.

Our disclosure policy metadata is published at /.well-known/security.txt.

Questions about our security?

Doing due diligence on us? We’re happy to walk you through our controls, policies, or anything on this page.