Back to Help Centre

iDecide Security Policy

Last Updated: 30 June 2025
8 min read

Bank-Level Security

This document outlines our comprehensive security framework and commitment to protecting your most sensitive information with military-grade encryption and industry-leading practices.

1. Security Overview

At iDecide, security is not an afterthought—it's the foundation upon which our entire platform is built. We understand that you're entrusting us with your most sensitive and important life information, and we take that responsibility seriously.

Our comprehensive security framework combines industry-leading technologies, best practices, and continuous monitoring to ensure your data remains protected at all times. We employ a multi-layered security approach that includes:

  • Military-grade encryption for all data, both in transit and at rest
  • Strict access controls and authentication protocols
  • Regular security audits and vulnerability assessments
  • 24/7 security monitoring and incident response capabilities
  • Compliance with international security standards and regulations

This security policy outlines our commitment to protecting your information and details the specific measures we have in place to maintain the highest levels of security and privacy.

2. Data Protection

Data Classification and Handling

We classify and handle different types of data according to their sensitivity level:

  • Highly Sensitive: Legal documents, medical records, financial information
  • Sensitive: Personal identification information, contact details
  • Internal: Account preferences, usage analytics
  • Public: Non-sensitive account information

Data Storage Security

All data is stored in highly secure, geographically distributed data centers with:

  • Physical security controls including biometric access, security guards, and surveillance
  • Environmental controls for temperature, humidity, and fire suppression
  • Redundant power systems and network connectivity
  • Regular backup procedures with encrypted off-site storage

Data Transmission Security

All data transmitted between your device and our servers is protected using:

  • TLS 1.3 encryption for all web communications
  • Certificate pinning to prevent man-in-the-middle attacks
  • End-to-end encryption for sensitive document storage
  • Secure API endpoints with rate limiting and DDoS protection

3. Encryption Standards

iDecide employs military-grade encryption standards to protect your data. Our encryption strategy covers all aspects of data handling, from storage to transmission to processing.

Encryption at Rest

  • AES-256 encryption for all stored data
  • Separate encryption keys for each customer's data
  • Hardware Security Modules (HSMs) for key management
  • Regular key rotation following industry best practices
  • Zero-knowledge architecture for highly sensitive documents

Encryption in Transit

  • TLS 1.3 for all web communications
  • Perfect Forward Secrecy to protect past communications
  • Certificate Authority validation and pinning
  • Secure WebSocket connections for real-time features

Encryption in Processing

  • Secure enclaves for sensitive data processing
  • Memory encryption during data manipulation
  • Encrypted database connections with certificate validation
  • Secure deletion of temporary data and cache

4. Access Controls

We implement strict access controls to ensure that only authorized individuals can access your data, and only when necessary for legitimate business purposes.

User Authentication

  • Multi-factor authentication (MFA) for all user accounts
  • Strong password requirements and breach detection
  • Session management with automatic timeout
  • Device fingerprinting and anomaly detection
  • Optional biometric authentication support

Employee Access

  • Principle of least privilege for all staff access
  • Role-based access controls with regular reviews
  • Mandatory background checks for all employees
  • Just-in-time access for administrative functions
  • All access activities logged and monitored

Administrative Controls

  • Segregation of duties for critical operations
  • Approval workflows for sensitive data access
  • Regular access rights reviews and cleanup
  • Automated deprovisioning when access is no longer needed

5. Infrastructure Security

Our infrastructure is built on industry-leading cloud platforms with additional security layers to protect against various types of attacks and ensure high availability.

Cloud Security

  • Deployment on SOC 2 Type II certified cloud infrastructure
  • Geographic data residency controls
  • Virtual private clouds (VPCs) with network isolation
  • Web Application Firewalls (WAF) for protection against common attacks
  • DDoS protection and traffic analysis

Network Security

  • Network segmentation and micro-segmentation
  • Intrusion detection and prevention systems (IDS/IPS)
  • Regular network penetration testing
  • VPN access for all remote administrative activities
  • Network traffic monitoring and analysis

Application Security

  • Secure software development lifecycle (SSDLC)
  • Regular security code reviews and static analysis
  • Dynamic application security testing (DAST)
  • Container security scanning and runtime protection
  • API security testing and rate limiting

6. Security Monitoring

We maintain 24/7 security monitoring to detect and respond to potential threats in real-time, ensuring rapid response to any security incidents.

24/7 Security Operations Center (SOC)

Our dedicated security team monitors all systems around the clock:

  • Real-time threat detection and analysis
  • Automated incident response and escalation
  • Security event correlation and investigation
  • Proactive threat hunting and research

Monitoring Capabilities

  • Security Information and Event Management (SIEM) system
  • User and Entity Behavior Analytics (UEBA)
  • File integrity monitoring (FIM)
  • Database activity monitoring (DAM)
  • Application performance and security monitoring

Threat Intelligence

  • Integration with global threat intelligence feeds
  • Custom threat indicators and rules
  • Automated threat response and blocking
  • Regular threat landscape analysis and reporting

7. Compliance Framework

iDecide maintains compliance with international security standards and regulations to ensure we meet the highest standards for data protection and privacy.

Security Standards

  • • ISO 27001 Information Security Management
  • • SOC 2 Type II Security Controls
  • • NIST Cybersecurity Framework
  • • OWASP Security Guidelines

Privacy Regulations

  • • GDPR (General Data Protection Regulation)
  • • CCPA (California Consumer Privacy Act)
  • • PIPEDA (Personal Information Protection)
  • • Australian Privacy Principles

Compliance Activities

  • Annual third-party security audits and assessments
  • Regular compliance monitoring and reporting
  • Data protection impact assessments (DPIAs)
  • Privacy by design implementation
  • Regular policy reviews and updates

8. Incident Response

We maintain a comprehensive incident response plan to quickly identify, contain, and resolve security incidents while minimizing impact to our users.

Incident Response Process

  1. Detection: Automated monitoring and manual reporting
  2. Analysis: Immediate assessment of severity and impact
  3. Containment: Isolate affected systems and prevent spread
  4. Eradication: Remove threats and vulnerabilities
  5. Recovery: Restore systems and monitor for recurrence
  6. Lessons Learned: Post-incident review and improvements

Response Team

  • Dedicated incident response team with 24/7 availability
  • Clear escalation procedures and communication protocols
  • External security experts and forensic specialists on retainer
  • Coordination with law enforcement when necessary

Communication

  • Timely notification to affected users
  • Transparent communication about incident status
  • Regulatory reporting as required by law
  • Post-incident reports with improvement recommendations

9. Security Auditing

Regular security audits and assessments help us identify potential vulnerabilities and ensure our security controls remain effective against evolving threats.

Internal Audits

  • Quarterly internal security assessments
  • Monthly vulnerability scans and assessments
  • Continuous security testing and monitoring
  • Regular access rights reviews and cleanup

External Audits

  • Annual third-party security audits
  • Penetration testing by certified ethical hackers
  • Cloud security posture assessments
  • Compliance audits for regulatory requirements

Continuous Improvement

  • Regular review and update of security policies
  • Implementation of security recommendations
  • Investment in new security technologies
  • Industry best practice benchmarking

10. Security Training

We believe that security is everyone's responsibility. Our comprehensive security training program ensures all team members understand their role in protecting your data.

Employee Training

  • Security awareness training for all new employees
  • Regular security updates and refresher training
  • Phishing simulation and response training
  • Role-specific security training programs
  • Security incident response training and drills

Security Culture

  • Security-first mindset in all business decisions
  • Regular security discussions and updates
  • Recognition programs for security contributions
  • Open communication channels for security concerns

11. Business Continuity

Our business continuity and disaster recovery plans ensure that your data remains accessible and protected even in the event of major disruptions.

Data Backup and Recovery

  • Automated daily backups with encryption
  • Geographically distributed backup storage
  • Regular backup integrity testing
  • Point-in-time recovery capabilities
  • Recovery time objectives (RTO) of less than 4 hours

Infrastructure Resilience

  • Multi-region deployment with automatic failover
  • Load balancing and auto-scaling capabilities
  • Redundant network connections and power systems
  • Regular disaster recovery testing and drills

12. Contact Information

If you have any questions about our security practices or wish to report a security concern, please contact our security team:

Security Team Email: compliance@idecide.co

Vulnerability Reports: security@hldgroup.org (HLD Group Security Team)

Business Hours: Monday-Friday, 9:00 AM - 5:00 PM AEST

Emergency Security Hotline: Available 24/7 for critical security incidents

We take all security reports seriously and will investigate any concerns promptly. For non-urgent security questions, please allow up to 48 hours for our response.

If you are a security researcher reporting a vulnerability, please read our Responsible Disclosure Policy first — it sets out scope, safe harbour and the response times you can expect.

iDecide Security Policy - Version 1.0
Last Updated: 30 June 2025
Effective Date: 30 June 2025