facebook-pixel

Gatheroo is a product of Kicking Pixels Pty Ltd and is built and operated within an information security management system certified to ISO/IEC 27001:2022. Certificate 1357-I-1, issued by Global Compliance Certification Pty Ltd under JAS-ANZ accreditation, covering the provision of SaaS products and website planning, design and development. Issued 26 March 2025, valid to 25 March 2028, maintained through annual surveillance audits with the next scheduled for Q1 2027.

All Gatheroo customer data is stored in Australia and is never replicated offshore. A small number of Kicking Pixels personnel located outside Australia access production systems remotely through a dedicated VPN with multi-factor authentication, role-based least-privilege access, and full activity logging. They are screened, subject to the same policies as our Australian team, and their access is reviewed annually and revoked within 24 hours of any change.

A copy of our certificate, extracts from our Statement of Applicability, and completed security questionnaires are available on request. Contact security@gatheroo.io.

Subprocessors

Amazon Web Services

Infrastructure provider for Gatheroo. Primary infrastructure for the Gatheroo application. All data uploaded to Gatheroo is stored and processed with Amazon Web Services. Platform hosting, storage and backup.
Australia

Atlassian (Jira, Confluence, Bitbucket)

Version Control. Bitbucket is used to manage and store the Gatheroo source code. It enables secure version control and collaborative development across our team. Internal task management and internal document management.
USA

Growth360 (GoHighLevel)

Marketing. CRM and client communications.
USA

The full list is published in our Trust Centre, including what each provider does and where it's located. In short, Amazon Web Services hosts the platform in Australia and Stripe processes payments. Everything else we rely on is listed there with its role and location.

Yes. We give at least 30 days' notice before adding or replacing a sub-processor that handles customer data, so you have time to review it. The current list is always published in our Trust Centre.

Every supplier that touches customer data is risk assessed before we engage them - security posture, data location, certifications and contractual protections. Assessments are recorded in our vendor risk register and reviewed on an ongoing basis, not just at onboarding.

No. All payments are processed by Stripe. Card numbers never touch Gatheroo's systems and are never stored by us.

Governance & Certification

Control
Status
ISO/IEC 27001:2022 certified

Gatheroo is built and operated within an independently certified information security management system.

Documented policy framework

Fifteen information security policies cover governance, access, assets, physical security, third parties, people, data protection, cryptography, development and incident response. Each is reviewed at least annually.

Independent surveillance

The ISMS is audited annually by our accredited certification body.

Internal audit programme

A three-year audit schedule covers every applicable clause and control, with findings reported to management.

Management review

Security performance is reviewed quarterly against documented annual information security objectives.

Risk management

A documented risk assessment and treatment process is maintained, with a risk register reviewed annually and on significant change.

Data Protection & Privacy

Control
Status
Australian data residency

All customer data is stored in AWS Australian regions — Sydney primary, Melbourne for backup.

Transparent access model

Personnel located outside Australia access production only via dedicated VPN with MFA and full activity logging. No customer data is stored outside Australia.

Encryption in transit

TLS 1.2 or higher for all connections.

Encryption at rest

AWS storage-layer encryption is applied to all data.

Field-level encryption

Sensitive text fields such as tax file numbers carry additional AES-128-GCM encryption, so answers are stored encrypted even within our own database.

Data masking

Payment card details display the last four digits only. Passwords are never displayed.

Immediate deletion

Deleting a file removes it from active storage immediately, clears encrypted backups within seven days, and is recorded permanently in the activity log.

Retention and account closure

Data is retained for the life of your subscription and deleted 60 days after cancellation. Inactive trial accounts are deleted automatically after 60 days.

Privacy rights

Access requests answered within 30 days, corrections within 14 days, deletions assessed within 14 days and actioned within 30.

Australian Privacy Principles

Personal information is handled in accordance with the Privacy Act 1988 and the Notifiable Data Breaches scheme, aligned with GDPR principles where relevant.

Complete audit trail

Every request, submission, view, download and deletion is timestamped and logged.

Access & Identity

Control
Status
Two-factor authentication

Available to all Gatheroo users via email or SMS.

Role-based access in-product

Permissions ensure sensitive information stays with the people who need it.

No client accounts required

Your clients complete requests through a secure link, so there are no extra credentials to manage or lose.

Least privilege internally

Internal access is granted on a least-privilege basis, with management approval required for elevated access.

Access reviews

Internal access is reviewed annually and on every role change.

Privileged access

Production administrative access is restricted to named personnel with MFA enforced and credentials held in a managed secrets vault.

VPN-only remote access

All remote access to production requires a dedicated VPN with multi-factor authentication.

People & Personnel Security

Control
Status
Screening

Personnel with privileged access undergo reference checks and employment history verification before access is granted.

Confidentiality agreements

Signed before any system access is granted.

Security awareness training

Completed annually by all personnel, with additional annual secure coding training for developers.

Onboarding and offboarding

A security briefing is required before access is granted. All access is revoked within 24 hours of a person leaving.

Remote working

Documented home office security requirements apply, with VPN mandatory for production access and on public Wi-Fi.

Physical security

Our office is located in a professionally secured building with controlled access, monitoring, a visitor log and key register, operated under clear desk and clear screen practices.

Product & Application Security

Control
Status
Secure development lifecycle

Changes flow through local, staging, pre-flight and production, with security checks at each stage.

Peer-reviewed code

All changes to protected branches require pull request review and approval. Direct pushes are blocked and full history is retained as an audit trail.

Secure coding standards

Input validation, server-side authorisation, no secrets in code, generic error messages, and OWASP Top 10 applied throughout.

Password storage

Passwords are hashed using modern algorithms and never stored in readable form.

Synthetic test data only

Production customer data is never used in development, staging or pre-flight environments.

Vulnerability remediation

Critical and high severity findings are remediated within 30 days, medium within 90, low within 180. Emergency security patches are expedited within 7 days.

Security testing

OWASP-methodology testing, mandatory staging validation before every release, and an annual infrastructure security assessment. Independent penetration testing is available where a client’s procurement process requires it.

AI tooling controls

No customer data, personal data or source code is entered into AI tools. AI-assisted development is restricted, operates with privacy mode enforced, and all output is reviewed before reaching production.

Infrastructure & Operations

Control
Status
Managed AWS infrastructure

Hosted on AWS under a shared responsibility model. AWS holds ISO 27001 and SOC 2 Type II certification.

Environment separation

Distinct local, staging, pre-flight and production environments are maintained.

Endpoint security

Company devices use full-disk encryption, endpoint protection, automatic screen lock and current security patches.

Network segregation

A dedicated business network operates separately from building infrastructure, with guest traffic isolated.

Logging

AWS CloudTrail and system access logs are retained for a minimum of 12 months.

Monitoring

Automated alerting from AWS and hosting providers, reviewed monthly, with immediate escalation of alerts.

Removable media prohibited

USB and external media are prohibited on all company devices. Business data is stored only in approved cloud services.

Approved software only

Software installation on company systems is restricted to a maintained approved software list.

Resilience & Incident Response

Control
Status
Backups

Hourly database and instance snapshots with seven-day retention, plus continuous file versioning, held in a second Australian region.

Recovery objective

Target recovery time of one hour for Gatheroo.

Backup verification

Completion is checked monthly, schedules confirmed quarterly, and a full restoration test performed annually.

Documented incident response

A documented plan with severity classification and defined phases covering detection, investigation, containment, recovery and review.

Response timeframes

Incident reports are acknowledged within 4 business hours and containment initiated within 8 business hours.

Breach notification

Notifiable breaches are assessed under the NDB scheme. The OAIC is notified as soon as practicable and within 72 hours where serious harm is likely, and affected customers are notified directly.

Supplier & Sub-processor Management

Control
Status
Assessment before engagement

A security assessment is completed before engaging any vendor that will handle business or customer data.

Annual review

All active vendors are reviewed annually with certifications reconciled, plus a quarterly check for unrecorded changes.

Data processing terms

Data processing agreements or equivalent contractual terms are in place for vendors processing personal data.

30-day change notification

We publish our sub-processors and provide at least 30 days’ notice before adding or replacing any sub-processor that processes customer data.

Amazon Web Services

Infrastructure provider for Gatheroo. Primary infrastructure for the Gatheroo application. All data uploaded to Gatheroo is stored and processed with Amazon Web Services. Platform hosting, storage and backup.
Australia

Atlassian (Jira, Confluence, Bitbucket)

Version Control. Bitbucket is used to manage and store the Gatheroo source code. It enables secure version control and collaborative development across our team. Internal task management and internal document management.
USA

Growth360 (GoHighLevel)

Marketing. CRM and client communications.
USA

Microsoft 365

Document Management. Office365 is used to store, manage, and collaborate on documents and files securely across all Kicking Pixels Group brands.
USA

Stripe

Payment processor for billing. Billing data and email addresses are processed by Stripe to facilitate secure payments for all subscriptions.
USA

WPEngine

Website Hosting. Managed WordPress hosting, SSL, backups.
Australia

Compliance & Certification

Yes. Gatheroo is built and operated within an information security management system certified to ISO/IEC 27001:2022 — certificate 1357-I-1, issued to Kicking Pixels Pty Ltd by Global Compliance Certification Pty Ltd under JAS-ANZ accreditation.

The certified scope covers the provision of SaaS products and website planning, design and development, so Gatheroo sits inside the certification rather than alongside it. The certificate was issued on 26 March 2025 and runs to 25 March 2028, maintained through annual surveillance audits, with the next scheduled for Q1 2027.

ISO 27001 certifies how an organisation manages information security, not a software product in isolation. Gatheroo supports your compliance obligations; it doesn't discharge them for you. A copy of the certificate is available on request.

A copy of our ISO/IEC 27001:2022 certificate is available on request, along with extracts from our Statement of Applicability. We don't publish the full Statement of Applicability because it details our internal control implementation, but we'll walk your security team through the parts relevant to your assessment. Email security@gatheroo.io.

On three levels. We run our own internal audit programme across the year, our leadership team formally reviews security performance and risk at management review, and an external certification body audits us annually. Findings from any of these are tracked as corrective actions through to closure.

We don't run penetration tests on a fixed schedule. We run continuous automated security testing using AWS-native tooling, every code change is peer reviewed before release, and our controls are independently audited each year to maintain ISO 27001 certification. Where a client's procurement process requires an independent penetration test, we'll arrange one - talk to us at security@gatheroo.io.

Yes. We regularly complete vendor security questionnaires as part of client procurement. Send yours to security@gatheroo.io and we'll return it completed, with supporting evidence where we can provide it.

Gatheroo gives you a secure, auditable client intake process — Australian data storage, encryption, two-factor access control and a full activity trail — supporting your obligations under Australian privacy and AML/CTF legislation.

If your business is in accounting, conveyancing, legal, mortgage broking or financial services, Tranche 2 of Australia's AML/CTF reforms extends formal obligations to you. A documented, auditable KYC and client intake process isn't an optional extra under that framework, it's a baseline requirement.

Gatheroo doesn't make your business compliant on its own. What it does is give you the structured intake process, the audit trail and the security controls that compliance requires — and that you can demonstrate clearly if you're ever asked.

Contact us directly. We'd rather answer a specific question than have you decide on incomplete information.

For security, compliance or procurement questions — questionnaires, certificate copies, due diligence — email security@gatheroo.io. For general support, email help@gatheroo.io or book a chat.

Data Protection & Privacy

All Gatheroo customer data is stored in Australia on Amazon Web Services infrastructure. It is not replicated to, or hosted in, any other jurisdiction.

A small number of Kicking Pixels personnel located outside Australia access production systems remotely to build and support the platform. They connect through a dedicated VPN with multi-factor authentication and role-based least-privilege access, every session is logged, and they are bound by the same screening, confidentiality and security obligations as our Australian team. The data itself remains stored in Australia at all times.

For businesses in regulated industries — financial services, accounting, legal, mortgage broking, conveyancing — data sovereignty matters, and Australian storage is a non-negotiable part of how Gatheroo operates.

Yes. Everything moving to and from Gatheroo - files, form submissions and page traffic - is encrypted in transit using TLS 1.2 or higher. Nothing travels in the clear.

Sensitive text fields such as Tax File Numbers are additionally encrypted at rest with field-level AES-128-GCM and are never stored as plain text. They're decrypted only when your team views them, and always delivered back over an encrypted connection.

Uploaded files are stored on encrypted AWS storage located in Australia.

Then swap the page's hard-coded accordion for the same CPT-driven block used elsewhere.

You do. Your account data and everything your clients submit remain yours. We process it only to operate the service on your instructions, as set out in the Data Processing Agreement within our Terms and Conditions. We don't sell it, share it for marketing, or use it for anything you haven't asked for.

Yes. When you delete a request or a file in Gatheroo it is removed from the live platform immediately. There is no hidden archive and no soft-delete state you can't see.

Deleted data can persist briefly in our encrypted operational backups, which run on a rolling seven-day cycle and are then overwritten. Those backups exist so we can restore your account after a failure — they aren't searchable and aren't used to retrieve individual deleted items.

You control what is retained and when it is deleted. That supports your obligations under the Australian Privacy Act, which requires personal information to be destroyed or de-identified once it is no longer needed.

Your account and its data are deleted 60 days after cancellation, which gives you time to export anything you need. Once deleted, data is purged from live systems and ages out of our seven-day backup cycle shortly afterwards. If you need it removed sooner, ask and we'll action it.

Trial accounts are deleted automatically after 60 days of inactivity. Nothing is kept indefinitely just because a trial was started and abandoned.

No. We don't use your data or your clients' data to train AI models, and we don't provide it to third-party AI tools that would. Where our team uses AI tooling internally, our policy permits only approved tools that contractually exclude inputs from model training.

Yes, and you already have it. Our DPA forms Part B of our Terms and Conditions and applies automatically — there's nothing separate to negotiate or sign. It sets out your role as data controller and ours as processor, our sub-processors, breach notification, retention and deletion, and our commitment that customer data stays in Australia in the ordinary course of operating the service. If procurement needs a signed standalone copy, just ask.

Individuals can ask us to access, correct or delete personal information we hold about them. We respond to access requests within 30 days and correction requests within 14 days, and we assess deletion requests within 14 days and action them within 30. Where the information belongs to one of your clients, you are the controller - we'll refer the request to you and support you in responding. Email privacy@gatheroo.io

Security & Access

Yes, and we're specific about what that means.

All data in transit — files and form submissions alike — is encrypted using TLS 1.2. Sensitive text fields such as Tax File Numbers are additionally encrypted at rest using field-level AES-128-GCM, decrypted only when your team views them.
Strong passwords are mandatory. Two-factor authentication is available on all plans by email passcode, and by SMS on Large plans.

Gatheroo is hosted on Amazon Web Services with all data stored in Australia. Access to production is role-based, least-privilege, multi-factor authenticated and logged.

Every code change is peer reviewed before release, and we run continuous automated security monitoring using AWS-native tooling including Inspector and GuardDuty. All of this operates inside our ISO/IEC 27001:2022 certified management system.

Yes. 2FA is available for both your team and your clients.

For your team, 2FA can be enabled from the My Account > 2FA section in your account settings. Once enabled, a 6-digit code is sent to your verified email address each time you log in.

For your clients, optional 2FA on a request via email is available on all plans. SMS-based 2FA is available on Large plans. This ensures that only the intended recipient can access a sensitive request and that access is recorded.

Each client receives a unique secure link to their portal. There are no shared logins, no shared access, and no version confusion between clients.

You can require clients to verify their identity via two-factor authentication (either by email code or if you are on a large plan you can opt to send this code by SMS) before they can access or submit any information. This means you always have a record of who accessed what and when, which is particularly relevant for businesses with KYC or identity verification obligations.

Passwords are never stored in readable form. They're stored as salted one-way hashes, so they can't be reversed or retrieved by anyone, including us. Strong passwords are enforced at sign-up, and we recommend enabling two-factor authentication on top.

Not currently. Gatheroo uses email and password with mandatory strong passwords, plus two-factor authentication by email on all plans and by SMS on Large plans. If SSO is a requirement for your organisation, tell us — it helps us prioritise.

Everyone who works on Gatheroo is a Kicking Pixels team member, not a subcontracted third party. Anyone granted privileged access to production is screened beforehand, including reference checks and verification of employment history. All personnel sign confidentiality agreements and complete security awareness training, refreshed as the threat landscape changes.

Access is revoked within 24 hours of a person leaving or changing role, and all assets are returned. Access rights across production systems are also reviewed on a scheduled basis, so accounts don't quietly outlive the reason they were created.

Yes. Every request carries a timestamped activity log. It records when a request was sent, when it was opened by the client, what was answered and when, and every comment or update made along the way.

That record builds itself as a natural output of your process. Nobody has to remember to document it. If you’re ever asked to demonstrate your client intake process to an auditor, a regulator, or your own leadership, that record is ready to produce with minimal preparation.

For businesses with AML/CTF obligations, KYC requirements, or simply an expectation that they can account for what was requested and received, that’s not a feature. It’s the point.

Platform Operations

All traffic to Gatheroo passes through an Application Load Balancer before it reaches any application server. The servers themselves are not directly accessible from the internet - only the load balancer accepts incoming connections.

SSH administrative access is restricted to a single authorised IP address. No other inbound access to the server is permitted.

The database is not exposed to the network at all. It runs on the same isolated server as the application and is only accessible locally, there is no network port open for database connections.

All of this is enforced through AWS security groups, which act as a strict firewall, only explicitly permitted traffic is allowed, everything else is blocked by default.

Gatheroo maintains automated backups of the application database, the application server and all stored files. Backups are held in Australia, encrypted, and retained on a rolling seven-day cycle, so we can restore to a point in time within that window.

Backups are verified monthly, reviewed quarterly, and put through a full restore test annually as part of our certified management system. Our target recovery time for Gatheroo is one hour.

We remediate on defined timeframes: critical and high severity within 30 days, medium within 90 days, low within 180 days, and emergency patches for actively exploited issues within 7 days. We monitor continuously using AWS-native tooling and review dependencies for known vulnerabilities as part of our release process.

Every change is peer reviewed by our Technical Lead before it can be merged, then moves through separate local, staging and pre-production environments before reaching production. Changes are tracked and releases can be rolled back. Nothing goes to production straight from a developer's machine.

No. Testing uses synthetic or anonymised data only. Real client documents and real personal information are never copied into development, staging or test environments.

If a security incident affects your data, we'll tell you. We acknowledge reported incidents within 4 business hours and aim to contain them within 8 business hours. Our Terms and Conditions commit us to notifying you within 72 hours of becoming aware of a breach affecting your data. Separately, where an incident is an eligible data breach under the Australian Privacy Act, we assess it and notify the OAIC and affected individuals as required, working with you as the controller of your clients' information.

Suppliers & Sub-processors

The full list is published in our Trust Centre, including what each provider does and where it's located. In short, Amazon Web Services hosts the platform in Australia and Stripe processes payments. Everything else we rely on is listed there with its role and location.

Yes. We give at least 30 days' notice before adding or replacing a sub-processor that handles customer data, so you have time to review it. The current list is always published in our Trust Centre.

Every supplier that touches customer data is risk assessed before we engage them - security posture, data location, certifications and contractual protections. Assessments are recorded in our vendor risk register and reviewed on an ongoing basis, not just at onboarding.

No. All payments are processed by Stripe. Card numbers never touch Gatheroo's systems and are never stored by us.