You own your data. We hold it, in Australia, under audited controls.
Three questions decide whether a platform gets through a security review: who owns the record, where it lives, and who has independently checked that we run it properly. Sierra Acuity holds a current SOC 2 Type 2 attestation — the third question is answered before you ask it.
SOC 2 Type 2 Current
Held and current. Controls independently tested as operating across an observation period, not designed on a single day. The report is provided under NDA, with a bridge letter between periods.
Australian data centre
A named Australian facility, not a region label on a console. Customer data does not leave Australia.
The record is yours
Export in a machine-readable format at any time, free, during the term and 90 days after. We do not sell it.
In the language your reviewer uses.
| Domain | What we do | What you can verify |
|---|---|---|
| Access control | Role-based, least privilege, named accounts, MFA on every administrative path, quarterly reviews. | Control listing · review evidence |
| Encryption | TLS 1.2+ in transit; at rest on database and backups; keys managed separately. | Architecture description |
| Logging | Administrative and data-access events logged and alerted. The audit trail cannot be edited from the application. | Retention policy · alert workflow |
| Backup & recovery | Point-in-time recovery with a stated RPO and RTO, tested rather than assumed. | RPO / RTO · last restore test |
| Vulnerability | Dependency scanning, patch windows, periodic external penetration testing. | Pen-test summary |
| Subprocessors | A register naming every third party that can touch customer data, and what for. | The current register |
| Incident response | Severity model, named responders, a communications path that includes you. | IR plan · last exercise |
Where a row says ask us for, we mean it. Security questionnaire, architecture description, penetration-test summary, subprocessor register and the last restore-test result are available on request. We would rather send evidence than a logo.
Personal information
- A store that records who took what holds personal information, and we treat it that way rather than as machine data.
- Customer data does not leave Australia. If that were ever to change for a specific service, you would be told before it happened, not after.
- Notification obligations run in both directions and the committed timeframes sit in the Master Terms, where they are enforceable — not on a web page, where they are not.
If you are a responsible entity
- Tell us at scoping if this touches a critical infrastructure asset. It changes the assurance work, not the price.
- We complete your supplier assurance process and provide the governance and architecture documentation your own obligations require.
- Our regulatory position is maintained as a controlled document and reviewed on a schedule. Ask for it and your reviewer receives the current version.
We do not publish our legal or regulatory position as marketing copy. Obligations change, marketing pages do not, and a stale compliance claim is worse than none. What we commit to is in the Master Services & Licence Terms; how we meet it is in the governance and architecture documentation, provided to your reviewer under NDA and kept current.
Send this page to your security reviewer first.
They will have a questionnaire. We will complete it and send the evidence with it.