Trust Center
We build incident-response software. We have strong opinions about how trust should be earned: with controls, evidence, and accountability — not slogans. Here’s our posture at a glance; the full detail is available to customers and prospects under NDA.
Encryption
AES-256-GCM
Tenant isolation
Row-level (RLS)
Primary region
AU (Sydney)
Audit trail
Tamper-evident
What we hold and what we’re working toward.
Honest about both. Compliance status pages that hide in-progress items aren’t trust signals — they’re marketing.
ISO/IEC 27001:2022
Information Security Management
ISMS established and Statement of Applicability complete (all 93 Annex A controls). External certification in preparation — no audit yet commenced. SoA available under NDA.
Australian Privacy Act 1988
APP-aligned data handling
Privacy Policy mapped to all 13 Australian Privacy Principles. Notifiable Data Breaches scheme process operational.
ASD Essential Eight
Self-assessed security baseline
Self-assessed: strong on MFA, restricting administrative privileges, and backups. Endpoint mitigations (application control, patching) being formalised via device management.
NIST CSF 2.0
Cybersecurity framework alignment
Security program aligned to all six CSF functions (Govern, Identify, Protect, Detect, Respond, Recover). ISO 27001 → CSF crosswalk being published.
The principles, at a glance.
The essentials every security buyer wants to confirm. Full control-level detail, architecture, and evidence are available under NDA — see below.
Encrypted before it reaches us
Evidence is encrypted in your browser with per-organisation keys before upload. We hold ciphertext, not your plaintext.
Isolated per tenant
Your data is separated from every other customer at the database layer, enforced by the database itself.
Hosted in Australia
Primary customer data resides in Sydney. Any overseas subprocessors are disclosed under NDA on request.
Independently tested
Third-party penetration tested and covered by an internal pre-launch security audit.
Every action audited
A tamper-evident, append-only audit trail records who did what, and when.
MFA, enforceable org-wide
Multi-factor authentication is available to every account and can be mandated across your organisation.
Request our full security & trust package.
We don’t publish our control inventory, architecture, or subprocessor detail openly. We share them — with the people who need them — under a mutual NDA. Tell us what you need and we’ll be in touch.
Available under NDA
- 01Detailed controls inventory & supporting evidence
- 02ISO 27001 Statement of Applicability
- 03Penetration test summary (redacted)
- 04Architecture & data-flow diagrams
- 05Full subprocessor list & data-residency detail
- 06Data Processing Agreement (DPA)
- 07Completed vendor security questionnaire (CAIQ-Lite)
Public documents
Found something? Tell us first.
We don’t run a bug bounty yet, but we acknowledge every credible report inside one business day and credit researchers in our security log on disclosure.
- Security contactsecurity@cybergobag.com
- Disclosure policy90-day coordinated
- Status pagecybergobag.com/status
- security.txt/.well-known/security.txt