Security & Privacy
Your data security and privacy are core platform concerns. XIntelliSync AI is built on partner-certified infrastructure with Australian-first privacy controls and globally aware security practices.
Security at a Glance
Security Features
End-to-End Encryption
All data encrypted in transit and at rest using industry-standard encryption
Implementation:
TLS 1.3 for data in transit, AES-256 encryption at rest via our certified database partner
Network Protection
DDoS protection, WAF, and global CDN delivered through our ISO 27001 and SOC 2 certified network protection partner
Implementation:
Partner-managed DDoS mitigation, Web Application Firewall, and SSL/TLS
Database Security
Row-Level Security, automated backups, and encryption powered by our SOC 2 Type II certified database partner
Implementation:
Partner-enforced RLS policies, AES-256 encryption, automated daily backups with point-in-time recovery
Role-Based Access Control
Granular permissions and access controls for team members with principle of least privilege
Implementation:
RBAC with multi-factor authentication, session management, and access logging
Security Assessments
Continuous automated security monitoring with regular vulnerability assessments
Implementation:
Automated vulnerability scanning, dependency auditing, and security monitoring
Privacy & Compliance
Privacy controls aligned with Australian Privacy Principles. Customers retain responsibility for their own APP and GDPR obligations.
Implementation:
Privacy by design, data minimisation, breach response preparation, and OAIC complaint-path support
Compliance & Certifications
Australian Privacy Act 1988
Platform incorporates controls aligned with the APPs. Customers are responsible for their own Privacy Act compliance obligations when processing personal information through the Platform.
Coverage: Customer Responsible
SOC 2 Type II Infrastructure
Built on SOC 2 Type II certified infrastructure partners
Coverage: Via Infrastructure Partners
ISO 27001 Network Security
Network protection through our ISO 27001 certified network protection partner
Coverage: Via Network Partner
PCI DSS Level 1 Payments
Payment processing through our PCI DSS Level 1 certified payments partner
Coverage: Via Payments Partner
GDPR Awareness
Platform provides data subject request handling and consent-aware workflows. XIntelliSync does not represent GDPR compliance. Customers subject to GDPR retain their own compliance obligations.
Coverage: Customer Responsible
ACSC Essential Eight
Security practices aligned with the Australian Cyber Security Centre Essential Eight framework
Coverage: Ongoing
OWASP Top 10
Application security controls protecting against the OWASP Top 10 vulnerabilities
Coverage: Ongoing
NDB Scheme
Notifiable Data Breaches response procedures aligned to OAIC notification expectations
Coverage: Operational
Data Protection Measures
Data Classification
All data is classified and handled according to sensitivity levels
Access Logging
Comprehensive audit trails for all data access and modifications
Data Backup
Automated backups with point-in-time recovery via our certified database partner
Incident Response
Defined incident response procedures with regulatory notification
Security Policies
Data Retention Policy
Clear guidelines on how long different types of data are retained
- Customer data retained per subscription terms
- Logs retained for 90 days for standard customers
- Automated deletion of expired data
- Data export available before deletion
Access Control Policy
Strict controls on who can access what data and systems
- Multi-factor authentication supported
- Role-based access with least privilege
- Regular access reviews and deprovisioning
- Privileged access monitoring
Incident Response Policy
Procedures for detecting, responding to, and recovering from security incidents
- Automated security monitoring and alerting
- Defined escalation procedures
- OAIC and customer notification where required by law
- Post-incident analysis and improvement
Vendor Security Policy
Security requirements for all third-party infrastructure partners
- All infrastructure partners hold SOC 2 or ISO 27001 certifications
- Contractual data processing agreements
- Regular vendor security reviews
- Australian Privacy Act compliance requirements
Threat Protection Matrix
Comprehensive protection against common security threats
DDoS Attacks
ProtectedPartner DDoS Protection & WAF
SQL Injection
ProtectedParameterized queries + Row-Level Security
Cross-Site Scripting
ProtectedContent Security Policy + Input validation
Brute Force Attacks
ProtectedRate limiting + Account lockout
Data Interception
ProtectedTLS 1.3 encryption + partner-managed SSL
Unauthorised Access
ProtectedRBAC + Row-Level Security + MFA
Enterprise Infrastructure Partners
Built on certified infrastructure from security partners
Database, Auth, RLS, Backups
CDN, DDoS, WAF, SSL/TLS
Payment Processing
Hosting Infrastructure
Security Questions?
Have security concerns or need to report a vulnerability? Our security team is here to help.
Security vulnerabilities: [email protected]
Security certifications referenced on this page (SOC 2 Type II, ISO 27001, PCI DSS Level 1) are held by the specialist infrastructure providers that underpin parts of our platform and cover the respective services they provide. XIntelliSync AI Pty Ltd implements security controls aligned with these frameworks and the ACSC Essential Eight, and maintains an Australian-first privacy program designed around the Privacy Act 1988 (Cth) and the Australian Privacy Principles.