Security & Trust Centre
Trust is not asserted. It is demonstrated.
This is where UniMatter shows its work: the frameworks it aligns to, the controls it operates, the policies that govern it, and the third parties it relies on. Where a control is operational, it is marked operational. Where it is maturing, it is marked maturing. Nothing here is a badge the work has not earned.
What we align to.
Recognised Australian and international frameworks, with an honest status against each. Operational means it runs today; aligned means the controls are operated to the standard and certification is not claimed. Nothing is badged that the work has not earned.
Australian Privacy Principles
Operational
Personal information is handled under the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles.
Notifiable Data Breaches
Operational
An eligible-data-breach assessment and notification process under Part IIIC of the Privacy Act 1988 (Cth).
Australian data residency
Operational
Data is held in Australian jurisdiction by default; any cross-border handling is disclosed and controlled.
ISO/IEC 27001
Aligned
Information-security management aligned to the ISO/IEC 27001 control set. The controls are operated now; certification is not claimed.
ACSC Essential Eight
Maturing
Mitigation strategies from the Australian Cyber Security Centre’s Essential Eight, implemented and maturing towards target levels.
SOC 2
Roadmap
The underlying controls — access, change, and monitoring — operate today. A SOC 2 report is not claimed.
What we operate.
The control environment behind every engagement. Each control is run as a matter of course, not assembled in advance of an audit.
Access control
Least-privilege access, multi-factor authentication, and periodic access review. Access follows the need to perform the work, and no further.
Encryption
Data encrypted in transit and at rest using current, standard algorithms. Keys are managed and rotated.
Logging & monitoring
Material actions are logged; anomalies are reviewed. The system can account for what was done within it.
Secure development
Change control, review, and mechanical screening before release. Whatever can be checked by rule is checked by rule.
Vendor & sub-processor management
Third parties are selected and reviewed against this same posture. A current register is maintained.
Incident response
Defined detection, containment, and response — including eligible-data-breach assessment under the NDB scheme.
Data lifecycle
Minimisation at intake, residency by default, defined retention, and controlled disposal at end of life.
Business continuity
Backups taken and recovery tested, so the work survives the loss of any single component.
The policies that govern it.
The standing policies behind the posture. Each is current and binding on UniMatter.
Privacy Policy
Information Security Policy
Responsible Disclosure Policy
Terms & Conditions
Acceptable Use Policy
Data Retention & Deletion Policy
Access Control Policy
Incident Response Policy
Business Continuity & Disaster Recovery Policy
Artificial Intelligence & Automated Decision-Making Policy
Third-Party & Vendor Risk Policy
Cookie & Tracking Policy
Who we rely on.
Where UniMatter relies on third parties, they are selected and reviewed against this same posture.
| Function | Purpose | Data residency |
|---|---|---|
| Cloud infrastructure & hosting | Application hosting and compute | Global edge, AU origin |
| Email & productivity | Correspondence and document handling | Australia |
| Web delivery & protection | Content delivery and edge security | Global edge, AU origin |
A current, named sub-processor register is maintained and provided to clients and prospective clients on request. Material changes are notified in accordance with the Privacy Policy.
Found a vulnerability, or need the full documentation?
Report security issues under the Responsible Disclosure Policy. Request the full security pack — including the named sub-processor register and control evidence — by starting a conversation; it is provided to clients and prospective clients on request.
security@unimatter.com.au