Security & Compliance
We take security and compliance seriously — here's everything you need to know about how SCX keeps your data safe, who we work with, and what standards we hold ourselves to.
Certifications & compliance

SOC 2 Type I
CertifiedAudited annually by an independent third party.
ISO 27001:2022
CertifiedInternationally recognised information security standard.
Data Processing Addendum
Available on requestAvailable for customers who process personal data under GDPR/APPs.
Compliance documentation
Download or request the documents you need. Can't find what you're looking for? Reach out at [email protected].

SOC 2 Type I
Annual third-party audit report
ISO 27001:2022
International information security certificate
DPA
Data Processing Addendum (GDPR / APPs)
Security controls
A summary of the controls SCX maintains across our organisation, products, and infrastructure.
Organisational security
- Anti-malware technology utilised
- Employee background checks performed
- Code of Conduct acknowledged by employees and enforced
Product security
- Control self-assessments conducted
- Penetration testing performed
- Data transmission encrypted
Internal security procedures
- Continuity and Disaster Recovery plans established
- Cybersecurity insurance maintained
- Configuration management system established
Data and privacy
- Data retention procedures established
- Customer data deleted upon request
- Data classification policy established
Infrastructure security
- Unique production database authentication enforced
- Unique account authentication enforced
- Key management
Sub-processors
We work with a limited number of trusted sub-processors. All are vetted for security and compliance, and none are based outside Australia.
| Vendor |
|---|
Contact
For security disclosures, compliance questions, or audit requests:
[email protected]