Security
Your clients trust you with sensitive data. We help make sure you don’t let them down.
Secure document collection, certified to ISO/IEC 27001:2022. Encrypted, auditable, and hosted in Australia.
ISO/IEC 27001:2022 certified
independently audited, not self-declared
Hosted in Australia on AWS
Australian data centres only
TLS 1.2 and AES-256
in transit and at rest
Auditable document activity
logged and timestamped
How we prioritise security
At Gatheroo, security isn’t an afterthought.
It’s built into every layer of the platform, from the infrastructure we run on, to the people who maintain it, to the independent certification that verifies our standards.
Certification
More than a promise: independently verified.
ISO/IEC 27001:2022 certified, and Gatheroo is inside the scope
Any software company can claim they take security seriously. We’ve had ours independently audited and verified.
Gatheroo is built and operated within an information security management system certified to ISO/IEC 27001:2022 — certificate 1357-I-1, issued by Global Compliance Certification under JAS-ANZ accreditation.
Our controls are assessed against a rigorous global benchmark and renewed through ongoing surveillance, not a one-time tick-box.
ISO/IEC 27001:2022
Certified scope: the provision of SaaS products, and website planning, design and development.
Access controls
Documented policies
Risk management
Incident response
Continuous improvement

Data residency
Your data stays in Australia. Full stop.
Australian-hosted document storage on AWS infrastructure
Gatheroo runs on Amazon Web Services (AWS), with all data centres located in Australia.
Your data stays local and is backed by AWS’s enterprise-grade physical and network security, and subject to Australian data sovereignty laws.
Encryption
Encrypted in transit, and encrypted at rest.
Bank-grade AES-128-GCM and TLS 1.2 data encryption. Every request is protected in transit, and the fields that matter most are protected at rest too.
In Transit
Everything, every time
All data moving to and from Gatheroo, files and form submissions alike, is protected using TLS 1.2. Nothing travels in the clear.
File Uploads
Protected the moment as its sent
Every file transferred through Gatheroo, documents and sensitive records alike, is protected in transit using TLS 1.2, from upload through to download.
Text Fields
Even the words your clients type
Sensitive fields like a Tax File Number can be encrypted at rest with field-level AES-128-GCM, so they are never stored as plain text. Decrypted only when your team views them.
Need this in writing?
We describe encryption exactly as it works today. If your security team needs it in a document they can file, we’ll put it together for them.
How we operate
Security is a practice, not a page.
The controls that matter most are the ones that run every day, whether or not anyone is looking.
We find the vulnerabilities before others do
Every code change goes through peer review as part of our sprint process. We run regular automated security testing using AWS-native tools, within our certified management system. Issues are identified and resolved before new code goes live.
The people behind the platform take security personally
Every Gatheroo team member is bound by a confidentiality agreement and receives regular training on our security protocols. As the threat landscape evolves, so does our training.
We never hold your card details
All payments are processed through Stripe. Card and payment information is never stored on Gatheroo systems.
Data Processing Agreement
A Data Processing Agreement, already in place.
Included in our Terms and Conditions, no separate document to chase
If your business needs a Data Processing Agreement to formalise how Gatheroo handles personal information on your behalf, it’s already there. Our DPA forms Part B of our Terms and Conditions and applies automatically, no separate document to negotiate or sign before you can rely on it.
If your organisation needs a signed, standalone copy for procurement or vendor onboarding, just ask.
What the DPA sets out
Your role as Data Controller, and ours as Data Processor, acting only on your instructions
A named, published list of every sub-processor we use, and exactly what each one does and doesn’t touch
A 72-hour breach notification commitment if a security incident ever affects your data
A clear retention and deletion schedule for your account and the data your clients have submitted
A commitment that your Customer Data doesn’t leave Australia in the ordinary course of operating the Service
FAQ
Questions we get asked a lot.
Security FAQs: ISO 27001, encryption, data hosting and more.
Compliance & Certification
Is Gatheroo ISO 27001 certified?
Yes. Gatheroo is built and operated within an information security management system certified to ISO/IEC 27001:2022, certificate 1357-I-1, issued to Kicking Pixels Pty Ltd by Global Compliance Certification Pty Ltd under JAS-ANZ accreditation.
The certified scope covers the provision of SaaS products and website planning, design and development, so Gatheroo sits inside the certification rather than alongside it. The certificate was issued on 26 March 2025 and runs to 25 March 2028, maintained through annual surveillance audits, with the next scheduled for Q1 2027.
ISO 27001 certifies how an organisation manages information security, not a software product in isolation. Gatheroo supports your compliance obligations; it doesn’t discharge them for you. A copy of the certificate is available on request.
Can we see your ISO 27001 certificate and Statement of Applicability?
A copy of our ISO/IEC 27001:2022 certificate is available on request, along with extracts from our Statement of Applicability. We don’t publish the full Statement of Applicability because it details our internal control implementation, but we’ll walk your security team through the parts relevant to your assessment. Email security@gatheroo.io.
How is your management system audited and reviewed?
On three levels. We run our own internal audit programme across the year, our leadership team formally reviews security performance and risk at management review, and an external certification body audits us annually. Findings from any of these are tracked as corrective actions through to closure.
Do you carry out penetration testing?
We don’t run penetration tests on a fixed schedule. We run continuous automated security testing using AWS-native tooling, every code change is peer reviewed before release, and our controls are independently audited each year to maintain ISO 27001 certification. Where a client’s procurement process requires an independent penetration test, we’ll arrange one – talk to us at security@gatheroo.io.
Do you complete security questionnaires and vendor due diligence forms?
Yes. We regularly complete vendor security questionnaires as part of client procurement. Send yours to security@gatheroo.io and we’ll return it completed, with supporting evidence where we can provide it.
Does Gatheroo support AML/CTF compliance obligations?
Gatheroo gives you a secure, auditable client intake process. Australian data storage, encryption, two-factor access control and a full activity trail, supporting your obligations under Australian privacy and AML/CTF legislation.
If your business is in accounting, conveyancing, legal, mortgage broking or financial services, Tranche 2 of Australia’s AML/CTF reforms extends formal obligations to you. A documented, auditable KYC and client intake process isn’t an optional extra under that framework, it’s a baseline requirement.
Gatheroo doesn’t make your business compliant on its own. What it does is give you the structured intake process, the audit trail and the security controls that compliance requires, and that you can demonstrate clearly if you’re ever asked.
What happens if I have a question about security that isn’t answered here?
Contact us directly. We’d rather answer a specific question than have you decide on incomplete information.
For security, compliance or procurement questions (questionnaires, certificate copies, due diligence) email security@gatheroo.io. For general support, email help@gatheroo.io or book a chat.
Security & Access
Is Gatheroo secure?
Yes, and we’re specific about what that means.
All data in transit (files and form submissions alike) is encrypted using TLS 1.2. Sensitive text fields such as Tax File Numbers are additionally encrypted at rest using field-level AES-128-GCM, decrypted only when your team views them.
Uploaded files are encrypted at rest with AES-256 on Australian AWS storage. EC2 volumes and S3 are additionally encrypted at rest using AES-256 via AWS-managed keys.
Strong passwords are mandatory. Two-factor authentication is available on all plans by email passcode, and by SMS on Large plans.
Gatheroo is hosted on Amazon Web Services with all data stored in Australia. Access to production is role-based, least-privilege, multi-factor authenticated and logged.
Every code change is peer reviewed before release, and we run continuous automated security monitoring using AWS-native tooling including Inspector and GuardDuty. All of this operates inside our ISO/IEC 27001:2022 certified management system.
Does Gatheroo support two-factor authentication?
Yes. 2FA is available for both your team and your clients.
For your team, 2FA can be enabled from the My Account > 2FA section in your account settings. Once enabled, a 6-digit code is sent to your verified email address each time you log in.
For your clients, optional 2FA on a request via email is available on all plans. SMS-based 2FA is available on Large plans. This ensures that only the intended recipient can access a sensitive request and that access is recorded.
Can my clients access Gatheroo securely?
Each client receives a unique secure link to their portal. There are no shared logins, no shared access, and no version confusion between clients.
You can require clients to verify their identity via two-factor authentication (either by email code or if you are on a large plan you can opt to send this code by SMS) before they can access or submit any information. This means you always have a record of who accessed what and when, which is particularly relevant for businesses with KYC or identity verification obligations.
How are passwords stored and protected?
Passwords are never stored in readable form. They’re stored as salted one-way hashes, so they can’t be reversed or retrieved by anyone, including us. Strong passwords are enforced at sign-up, and we recommend enabling two-factor authentication on top.
Do you support single sign-on (SSO)?
Not currently. Gatheroo uses email and password with mandatory strong passwords, plus two-factor authentication by email on all plans and by SMS on Large plans. If SSO is a requirement for your organisation, tell us, it helps us prioritise.
How do you vet the people who work on Gatheroo?
Everyone who works on Gatheroo is a Kicking Pixels team member, not a subcontracted third party. Anyone granted privileged access to production is screened beforehand, including reference checks and verification of employment history. All personnel sign confidentiality agreements and complete security awareness training, refreshed as the threat landscape changes.
How quickly is access removed when someone leaves?
Access is revoked within 24 hours of a person leaving or changing role, and all assets are returned. Access rights across production systems are also reviewed on a scheduled basis, so accounts don’t quietly outlive the reason they were created.
Does Gatheroo have an audit trail?
Yes. Every request carries a timestamped activity log. It records when a request was sent, when it was opened by the client, what was answered and when, and every comment or update made along the way.
That record builds itself as a natural output of your process. Nobody has to remember to document it. If you’re ever asked to demonstrate your client intake process to an auditor, a regulator, or your own leadership, that record is ready to produce with minimal preparation.
For businesses with AML/CTF obligations, KYC requirements, or simply an expectation that they can account for what was requested and received, that’s not a feature. It’s the point.