Skip to content
All systems operationalPosture last reviewed 2026-08-17

Trust Center

We build incident-response software. We have strong opinions about how trust should be earned: with controls, evidence, and accountability — not slogans. Here’s our posture at a glance; the full detail is available to customers and prospects under NDA.

Encryption

AES-256-GCM

Tenant isolation

Row-level (RLS)

Primary region

AU (Sydney)

Audit trail

Tamper-evident

01Certifications

What we hold and what we’re working toward.

Honest about both. Compliance status pages that hide in-progress items aren’t trust signals — they’re marketing.

ISO/IEC 27001:2022

Information Security Management

ISMS established and Statement of Applicability complete (all 93 Annex A controls). External certification in preparation — no audit yet commenced. SoA available under NDA.

In preparation

Australian Privacy Act 1988

APP-aligned data handling

Privacy Policy mapped to all 13 Australian Privacy Principles. Notifiable Data Breaches scheme process operational.

Compliant

ASD Essential Eight

Self-assessed security baseline

Self-assessed: strong on MFA, restricting administrative privileges, and backups. Endpoint mitigations (application control, patching) being formalised via device management.

Self-assessed

NIST CSF 2.0

Cybersecurity framework alignment

Security program aligned to all six CSF functions (Govern, Identify, Protect, Detect, Respond, Recover). ISO 27001 → CSF crosswalk being published.

Aligned (in progress)
02How we protect your data

The principles, at a glance.

The essentials every security buyer wants to confirm. Full control-level detail, architecture, and evidence are available under NDA — see below.

Encrypted before it reaches us

Evidence is encrypted in your browser with per-organisation keys before upload. We hold ciphertext, not your plaintext.

Isolated per tenant

Your data is separated from every other customer at the database layer, enforced by the database itself.

Hosted in Australia

Primary customer data resides in Sydney. Any overseas subprocessors are disclosed under NDA on request.

Independently tested

Third-party penetration tested and covered by an internal pre-launch security audit.

Every action audited

A tamper-evident, append-only audit trail records who did what, and when.

MFA, enforceable org-wide

Multi-factor authentication is available to every account and can be mandated across your organisation.

03Documentation

Request our full security & trust package.

We don’t publish our control inventory, architecture, or subprocessor detail openly. We share them — with the people who need them — under a mutual NDA. Tell us what you need and we’ll be in touch.

Available under NDA

  1. 01Detailed controls inventory & supporting evidence
  2. 02ISO 27001 Statement of Applicability
  3. 03Penetration test summary (redacted)
  4. 04Architecture & data-flow diagrams
  5. 05Full subprocessor list & data-residency detail
  6. 06Data Processing Agreement (DPA)
  7. 07Completed vendor security questionnaire (CAIQ-Lite)

Detailed materials are shared under a mutual NDA, which our team will arrange by email. We use your details only to respond to this request.

or email security@cybergobag.com
04Disclosure

Found something? Tell us first.

We don’t run a bug bounty yet, but we acknowledge every credible report inside one business day and credit researchers in our security log on disclosure.