Gridware Logo

Security assurance

Trust Centre

How Gridware protects client information and personal data, the controls behind it, and the documents available for your due diligence.

Certifications

Certified by GCC and accredited by JAS-ANZ. www.jas-anz.org/register

JAS-ANZ accreditation symbol
  • ISO 27001 Certified

    ISO/IEC 27001

    Information security management system

  • ISO/IEC 27701 Certified

    ISO/IEC 27701

    Privacy information management system

Security program

Control coverage

The control areas within Gridware’s security program. Each area groups a number of individual controls from our Statement of Applicability, summarised at a level that supports due diligence. Implementation detail and evidence are not published here.

All control areas in place

Organisational security

  • Security governance

    Security policies, ownership and review responsibilities.

    In place
  • Personnel security and training

    Staff screening, onboarding, security awareness and offboarding.

    In place
  • Supplier risk management

    Risk-based assessment of suppliers and service providers.

    In place

Access and endpoint security

  • Identity and access management

    Access provisioning, authentication and periodic review.

    In place
  • Endpoint security

    Managed safeguards for corporate endpoints.

    In place

Data and privacy

  • Data protection and encryption

    Safeguards for sensitive information throughout its lifecycle.

    In place

Operational resilience

  • Vulnerability management

    Identification, assessment and remediation of security weaknesses.

    In place
  • Incident response

    Processes for preparing for and responding to security events.

    In place
  • Business continuity

    Resilience and recovery planning for important operations.

    In place

Service delivery

  • Secure client engagement delivery

    Security requirements applied to client engagements.

    In place

Documents

Request documents

These documents support most client due-diligence reviews. Request any of them using the form.

  • Certificate

    ISO/IEC 27001 certificate

    Gridware’s current information security certificate, including its certified scope and validity period.

  • Certificate

    ISO/IEC 27701 certificate

    Gridware’s current privacy information management certificate, including its certified scope and validity period.

  • FAQ

    Security and privacy FAQ

    Answers to the questions clients most often ask about Gridware’s security, privacy and resilience practices.

Other assurance questions? Contact us.

Request form

Tell us which documents you need and where to send them.

Requests are handled under our Privacy Policy. Marketing consent is not required to receive these documents.