Security at Advoc8
Protecting customer data is an important part of how Advoc8 is designed, operated and maintained. We take a risk-based approach to information security, supported by documented policies, technical controls, independent testing and ongoing review.
ISO 27001 certified
Advoc8 is ISO 27001 certified. Our Information Security Management System (ISMS) provides a structured framework for identifying, assessing and managing information security risks across our organisation, technology and operations.
Our certification provides independent assurance that we maintain a systematic approach to information security and continually review and improve our security practices.
Hosted in Australia
Advoc8 and customer data are hosted in Australia. Our production infrastructure is hosted on Amazon Web Services (AWS) within Australian data centres, providing customers with Australian data residency.
AWS provides the underlying physical and cloud infrastructure, while Advoc8 is responsible for the security and operation of our application and environment.
Access to production systems is restricted to authorised personnel and protected by appropriate access controls. We continuously monitor our infrastructure and application for security, availability and operational issues.
Protecting customer data
Data transmitted between users and Advoc8 is encrypted using modern TLS encryption. Customer data, backups and credentials are protected using appropriate encryption and secure storage practices.
We apply controls around authentication, access management and the handling of customer information to reduce the risk of unauthorised access.
Application security
Security is incorporated throughout our software development and operational processes.
We use automated vulnerability scanning and dependency monitoring to identify security issues on an ongoing basis. Changes to the application are subject to code review and automated testing before being released to production.
Advoc8 also engages an independent cybersecurity firm to conduct annual penetration testing of our application and infrastructure. Identified vulnerabilities are assessed and remediated, with issues independently retested where appropriate.
These practices form part of the broader information security program maintained under our ISO 27001-certified ISMS.
Monitoring, backups and resilience
We continuously monitor the availability and operation of Advoc8 and maintain processes for responding to security and operational incidents.
Automated backups are securely stored and encrypted within Australia, and we maintain recovery procedures designed to support the continued availability and integrity of customer data.
Ongoing security management
Information security is an ongoing process. We regularly review security risks and controls, maintain our software dependencies, assess vulnerabilities and improve our security practices as our platform and the security environment evolve.
Customers undertaking security, risk or procurement reviews can contact us for additional information about our security practices, Australian data residency and ISO 27001 certification.