Trust Center

Australian-owned. Australian-hosted. No data leaves the country.

Security is not a feature; it is the foundation. Every architectural decision, every access control, every encryption choice was made with Australian government data in mind.

Read the full security whitepaper
AES-256-GCM at rest
TLS 1.3 in transit
MFA mandatory
Melbourne data centre
Annual pen testing
$10M PI insurance
Data Sovereignty

Your data never
leaves Australian soil

Lattice Look is hosted entirely within Australia. Our primary data centre is located in Melbourne, with a geographically separated hot standby for disaster recovery. No data replication, no backup copies, no processing. Nothing ever crosses the border.

  • Primary data centre: Melbourne, Victoria
  • Disaster recovery: Hot standby, separate geographic zone, Australia
  • Data residency: 100% Australian infrastructure, no offshore processing
  • Subprocessors: All vetted: Australian entities only for data handling

Infrastructure map

All zones: Australia only

Primary

Melbourne, VIC

Active

DR Standby

Sydney, NSW

Hot standby

Backups

Australia (encrypted)

Automated daily

No data ever processed outside Australia

Encryption

Encrypted at rest.
Encrypted in transit.
Keys rotated automatically.

We use the strongest commercially available encryption algorithms. There is no plaintext path to your data.

AES-256-GCM at rest

All data stored on disk (databases, backups, file attachments) is encrypted with AES-256-GCM. Authenticated encryption prevents silent data tampering.

TLS 1.3 in transit

All communication between your browser and our servers uses TLS 1.3 exclusively. Legacy TLS 1.0 and 1.1 are disabled. Perfect forward secrecy is enforced.

Automatic key rotation

Encryption keys are rotated on a scheduled basis. Keys are managed via a dedicated key management service, never stored alongside the data they protect.

Access Control

MFA mandatory.
Zero-trust at every layer.

Every administrative and privileged account requires multi-factor authentication, with no exceptions. Tenant isolation is enforced at the database level, not just the application layer.

MFA mandatory

TOTP (authenticator app), WebAuthn hardware keys, and enterprise SSO: all supported. MFA cannot be disabled for admin roles.

Row-Level Security

PostgreSQL Row-Level Security enforces tenant isolation at the database layer. One tenant cannot access another tenant's data, even if application-level controls were bypassed.

Role-based permissions

Five distinct roles: Platform Admin, Auditor, Organisation Admin, Department Manager, Viewer. Principle of least privilege enforced throughout.

Session management

Short-lived access tokens (15 minutes) with automatic refresh. Sessions invalidated on logout across all devices.

Supported MFA methods

TOTP Authenticator Recommended

Google Authenticator, Authy, Microsoft Authenticator

WebAuthn / Passkeys Most secure

Hardware security keys, biometric unlock

Enterprise SSO Enterprise

SAML 2.0, Azure AD, Okta integration

Tenant isolation enforced at

Application layerAPI layerDatabase layer (RLS)
Penetration Testing

Tested relentlessly.
By us and independent experts.

Security testing is not a one-time exercise. We run automated vulnerability scans weekly and commission independent third-party penetration tests annually.

Weekly automated scans

  • OWASP Top 10 vulnerability scanning
  • Dependency and CVE monitoring
  • Infrastructure configuration audits
  • SSL/TLS configuration verification

Annual third-party audits

  • Independent penetration testing firm
  • Full application and API testing
  • Social engineering assessment
  • Findings remediated within SLA
Compliance Standards

Aligned to the frameworks
government trusts

Our security practices are designed to meet and exceed the standards expected of software handling sensitive government data.

ISO 27002 aligned Current

Our information security controls map to ISO/IEC 27002:2022. Gap assessment completed by independent auditor.

IRAP assessment In preparation

We are preparing for an Information Security Registered Assessors Program (IRAP) assessment to support federal and state government procurement.

Essential Eight Aligned

Controls aligned with the Australian Cyber Security Centre Essential Eight mitigation strategies.

Immutable Audit Trail

36-month retention

  • Every action timestamped and attributed (who, what, when, from where) to an append-only log
  • Tamper-evident: records sealed into an Ed25519-signed Merkle tree (RFC 6962-style Signed Tree Heads)
  • Continuously re-verified: any alteration, deletion, or reordering is cryptographically detectable
  • Signed roots anchored to independent, off-database storage and deliverable to you for independent verification
  • Retained 36 months per ISO 9001:2015 records management, aligned to ISO/IEC 27001 A.8.15 logging controls
  • Exportable in structured format for external auditors
  • Separate log store, isolated from application data

Insurance Coverage

Professional Indemnity $10,000,000 AUD
Public Liability $20,000,000 AUD

Certificates of currency available on request during procurement.

Ready to talk security in depth?

Request our security documentation pack, certificates of currency, or schedule a technical deep-dive with our team.