Security

    At Manifest Technologies, we take the security of your data seriously. This page outlines our commitment to protecting your information in accordance with Australian standards and best practices.

    Encryption

    All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption.

    Secure Infrastructure

    Our systems are hosted on enterprise-grade cloud infrastructure with SOC 2 compliance.

    Access Controls

    Role-based access controls and multi-factor authentication protect all systems.

    Employee Security

    All staff undergo background checks and regular security awareness training.

    Regular Audits

    We conduct regular security assessments and penetration testing.

    Incident Response

    24/7 monitoring and documented incident response procedures.

    Our Security Commitment

    We are committed to maintaining the highest standards of information security. Our security practices are aligned with the Australian Signals Directorate's Essential Eight, ISO 27001 principles, and the Australian Privacy Principles under the Privacy Act 1988 (Cth).

    Data Protection

    We implement comprehensive data protection measures including:

    • End-to-end encryption for all data transmissions
    • AES-256 encryption for data at rest
    • Secure key management practices
    • Regular backup and disaster recovery procedures
    • Data residency options for Australian clients

    Infrastructure Security

    Our infrastructure is designed with security as a priority:

    • Enterprise-grade cloud hosting with geographic redundancy
    • Network segmentation and firewalls
    • DDoS protection and web application firewalls
    • Continuous vulnerability scanning and patching
    • Intrusion detection and prevention systems

    Access Management

    We enforce strict access controls across all systems:

    • Principle of least privilege for all user access
    • Multi-factor authentication (MFA) required for all accounts
    • Regular access reviews and prompt offboarding procedures
    • Audit logging of all access and administrative actions
    • Secure password policies and credential management

    Compliance & Standards

    We align our security practices with recognised standards and regulations:

    • Privacy Act 1988 (Cth) and Australian Privacy Principles
    • Australian Signals Directorate Essential Eight
    • ISO 27001 Information Security Management principles
    • OWASP security guidelines for application development
    • Notifiable Data Breaches (NDB) scheme compliance

    AI-Specific Security

    As an AI solutions provider, we implement additional safeguards:

    • Strict data segregation between client environments
    • Model training data protection and governance
    • Secure API authentication and rate limiting
    • Regular AI model auditing for bias and security vulnerabilities
    • Clear data retention and deletion policies

    Incident Response

    We maintain a comprehensive incident response plan that includes detection, containment, eradication, recovery, and post-incident review. In accordance with the Notifiable Data Breaches scheme, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) of any eligible data breaches within the required timeframes.

    Vendor Security

    We carefully assess the security practices of all third-party vendors and require them to meet our security standards. Vendor agreements include appropriate confidentiality, data protection, and security requirements.

    Responsible Disclosure

    We welcome responsible disclosure of security vulnerabilities. If you discover a potential security issue, please report it to our security team at security@manifest.com.au. We commit to acknowledging reports within 48 hours and working with you to understand and address the issue.

    Contact

    For security-related enquiries, please contact:

    Manifest Technologies Limited

    Email: security@manifest.com.au

    Australia