Skip to content

Security

Security isn’t just what we build — it’s how we build it.

Our ISO 27001:2022 certification is in preparation, and the controls behind it — database-enforced tenant isolation, encrypted evidence, and a tamper-evident audit trail — are live today.

Certifications & compliance

ISO/IEC 27001:2022

ISMS established; Statement of Applicability complete (all 93 Annex A controls). External certification in preparation — no audit yet commenced.

In preparation

Australian Privacy Act 1988

Handling aligned to the 13 APPs.

Compliant

ASD Essential Eight

Self-assessed against the ASD baseline.

Self-assessed

NIST CSF 2.0

Aligned across all six functions.

Aligned (in progress)

ISO 27001 scope: design, development, and operation of the CyberGoBag SaaS platform.

Ask about our audit progress →

Documentation

The detail is available — under NDA.

We don't publish our controls inventory, infrastructure and data-flow architecture, data-residency detail, or subprocessor list openly. Customers, prospects, and procurement teams can request the full security & trust package — including our ISO 27001 Statement of Applicability, penetration test summary, and DPA — which we share under a mutual NDA.

Request access

One form, a mutual NDA, and the package is on its way — usually within two business days.

Responsible disclosure

We welcome security researchers who help us keep CyberGoBag secure. If you discover a vulnerability, please report it to security@cybergobag.com.

We do not currently offer a bug bounty program.

We commit to

  1. 01Acknowledging receipt within 24 hours.
  2. 02Providing an initial assessment within 72 hours.
  3. 03Not pursuing legal action against good-faith researchers.

Frequently asked questions

Are you ISO 27001 certified?

Not yet. We have built our ISO/IEC 27001:2022 ISMS and completed the Statement of Applicability across all 93 Annex A controls; external certification is in preparation and no audit has commenced. Contact security@cybergobag.com for the current Statement of Applicability or to schedule a security review.

Where is my data stored?

Your customer data, evidence, and audit logs are hosted in Australia (Supabase, Sydney — ap-southeast-2). Some subprocessors (email delivery, error monitoring) operate in the United States; these are disclosed on our Trust page. Alternative data-residency arrangements are available on request.

Do you use subprocessors?

Yes. A current list of subprocessors is available on request. Changes are communicated 30 days in advance.

How do you handle data deletion?

Data can be exported or permanently deleted on request. Deletion is confirmed within 30 days and includes backups within retention period.

Questions about our security practices?