IT Security & Privacy Statement

Effective Date: 14 August 2025

At AI Readiness Audit, we take information security seriously. This IT Security & Privacy Statement outlines the security controls and procedures we have in place to safeguard your personal data, ensure system integrity, and uphold client confidentiality across all our services and platforms.

1. Commitment to Security

We are committed to protecting the confidentiality, integrity, and availability of data collected through aireadinessaudit.com.au. We apply industry best practices and continually monitor and upgrade our systems to defend against unauthorised access, data loss, or malicious activity.

2. Data Encryption & Storage

  • Data in Transit: All information transmitted between your browser and our servers is protected using SSL/TLS encryption.

  • Data at Rest: Sensitive data is encrypted and stored on secure cloud-based infrastructure compliant with ISO 27001SOC 2, and GDPR-aligned standards.

  • Backups: Regular, encrypted backups are maintained and stored securely to ensure business continuity.

3. Access Control & Authentication

  • We operate on a principle of least privilege, ensuring that only authorised personnel can access client or system data.

  • All internal systems require multi-factor authentication (MFA).

  • We log and monitor all access and user activity to detect anomalies or unauthorised access attempts.

4. Malware & Intrusion Protection

  • Our infrastructure is protected by up-to-date firewallsintrusion detection systems (IDS), and anti-malware solutions.

  • We regularly scan for known vulnerabilities and apply patches as part of our proactive security maintenance.

5. Secure Development Practices

  • All software and website features are developed using secure coding frameworks.

  • We perform code reviews, vulnerability assessments, and third-party penetration testing to identify and fix potential weaknesses.

  • Staging and production environments are segregated to prevent data leakage or cross-contamination.

6. Client Data Handling

  • We do not sell or trade client data under any circumstance.

  • All client information collected through audits, reports, or analytics remains strictly confidential.

  • If we engage third-party tools (e.g., analytics, API services), they are vetted for compliance with Australian Privacy Principles (APPs) and international data security regulations.

7. Incident Response Plan

In the event of a security incident or suspected breach:

  • We will immediately initiate our Incident Response Plan (IRP).

  • Affected parties will be notified within the legally required timeframe, in accordance with the Notifiable Data Breaches (NDB) scheme.

  • Root cause analysis will be conducted, and remediation measures will be implemented and documented.

8. Staff Training & Confidentiality

  • All team members undergo regular security awareness training.

  • Staff are required to sign confidentiality agreements and adhere to internal IT policies and ethical guidelines.

  • Access to client accounts or data is role-based and revoked upon staff offboarding.

9. Physical Security

  • We use secure cloud environments with Australian-based data centres (or equivalent secure jurisdictions).

  • Data centres are physically protected with 24/7 surveillance, biometric access control, and environmental safeguards.

10. Your Responsibility

While we take all reasonable steps to secure your data, users must also:

  • Use strong passwords

  • Keep their devices secure

  • Refrain from sharing login details

  • Notify us immediately of any suspicious activity

11. Questions or Concerns

If you have any questions about our security practices or suspect a breach, please contact us.

By using aireadinessaudit.com.au, you acknowledge and agree to the measures outlined in this IT Security & Privacy Statement.