facebook-pixel
ISO/IEC 27001:2022 certified

independently audited, not self-declared

Hosted in Australia on AWS

Australian data centres only

TLS 1.2 and AES-256

in transit and at rest

Auditable document activity

logged and timestamped

How we prioritise security

At Gatheroo, security isn’t an afterthought.

It’s built into every layer of the platform, from the infrastructure we run on, to the people who maintain it, to the independent certification that verifies our standards.

Certification

More than a promise: independently verified.

ISO/IEC 27001:2022 certified, and Gatheroo is inside the scope

Any software company can claim they take security seriously. We’ve had ours independently audited and verified.

Gatheroo is built and operated within an information security management system certified to ISO/IEC 27001:2022 — certificate 1357-I-1, issued by Global Compliance Certification under JAS-ANZ accreditation.

Our controls are assessed against a rigorous global benchmark and renewed through ongoing surveillance, not a one-time tick-box.

ISO/IEC 27001:2022

Certified scope: the provision of SaaS products, and website planning, design and development.

Access controls

Documented policies

Risk management

Incident response

Continuous improvement

Data residency

Your data stays in Australia. Full stop.

Australian-hosted document storage on AWS infrastructure

Gatheroo runs on Amazon Web Services (AWS), with all data centres located in Australia.

Your data stays local and is backed by AWS’s enterprise-grade physical and network security, and subject to Australian data sovereignty laws.

Encryption

Encrypted in transit, and encrypted at rest.

Bank-grade AES-128-GCM and TLS 1.2 data encryption. Every request is protected in transit, and the fields that matter most are protected at rest too.

In Transit

Everything, every time

All data moving to and from Gatheroo, files and form submissions alike, is protected using TLS 1.2. Nothing travels in the clear.

File Uploads

Protected the moment as its sent

Every file transferred through Gatheroo, documents and sensitive records alike, is protected in transit using TLS 1.2, from upload through to download.

Text Fields

Even the words your clients type

Sensitive fields like a Tax File Number can be encrypted at rest with field-level AES-128-GCM, so they are never stored as plain text. Decrypted only when your team views them.

Need this in writing?

We describe encryption exactly as it works today. If your security team needs it in a document they can file, we’ll put it together for them.

How we operate

Security is a practice, not a page.

The controls that matter most are the ones that run every day, whether or not anyone is looking.

We find the vulnerabilities before others do

Every code change goes through peer review as part of our sprint process. We run regular automated security testing using AWS-native tools, within our certified management system. Issues are identified and resolved before new code goes live.

The people behind the platform take security personally

Every Gatheroo team member is bound by a confidentiality agreement and receives regular training on our security protocols. As the threat landscape evolves, so does our training.

We never hold your card details

All payments are processed through Stripe. Card and payment information is never stored on Gatheroo systems.

Data Processing Agreement

A Data Processing Agreement, already in place.

Included in our Terms and Conditions, no separate document to chase

If your business needs a Data Processing Agreement to formalise how Gatheroo handles personal information on your behalf, it’s already there. Our DPA forms Part B of our Terms and Conditions and applies automatically, no separate document to negotiate or sign before you can rely on it.

If your organisation needs a signed, standalone copy for procurement or vendor onboarding, just ask.

What the DPA sets out

Your role as Data Controller, and ours as Data Processor, acting only on your instructions

A named, published list of every sub-processor we use, and exactly what each one does and doesn’t touch

A 72-hour breach notification commitment if a security incident ever affects your data

A clear retention and deletion schedule for your account and the data your clients have submitted

A commitment that your Customer Data doesn’t leave Australia in the ordinary course of operating the Service

FAQ

Questions we get asked a lot.

Security FAQs: ISO 27001, encryption, data hosting and more.