Kode-1

Security

Last updated: 29 July 2026

Security is the work we do — and the standard we hold ourselves to. Our internal practices align to the NIST Cybersecurity Framework and the ISO 27001 control families, and we keep the documentation that evidences them.

Data handling

Client information is encrypted in transit (TLS 1.2+) and at rest. We classify information in three tiers — public, internal, confidential — and handle each accordingly. Retention follows the terms of the governing engagement agreement, and client information is destroyed or returned at engagement completion unless we are legally required to retain it.

Access controls

Internal systems operate on least privilege with multi-factor authentication required, single sign-on by default, and access reviews each quarter. Access to client systems is time-bounded, role-scoped, and audit-logged, and we retain no client credentials beyond the engagement period.

AI-use controls

Our internal use of AI tools is routed through governed gateways with policy enforcement and trace capture. Sensitive client information is not sent to third-party model providers. The same disciplines we advise on — approval boundaries, evaluation, and logging — govern our own AI use.

Incident response

We maintain a documented incident-response plan covering detection through post-incident review, with named roles and tested procedures. If an incident affects your information, we notify you without delay.

Vendor management

Vendors are assessed against standard criteria before engagement and re-assessed annually, including security posture, sub-processor lists, data residency, and incident history.

Compliance

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (see our Privacy Policy), and our practices are designed to support client obligations under frameworks including APRA CPS 234, ISO 42001, and the NIST AI RMF.

Reporting a vulnerability

If you believe you have found a security vulnerability in this site or our systems, contact partner@kode-1.com. We acknowledge reports within two business days and provide a substantive update within ten. We will not pursue legal action against researchers acting in good faith under responsible disclosure.