Operations
Security is embedded across Audere’s technology, operations and governance. Our control environment is designed to protect the confidentiality, integrity and availability of client data across the Audere Analytics platform and our wider service delivery.
Secure cloud infrastructure
Audere Analytics and its associated production data are hosted within Google Cloud Platform. The infrastructure is configured for resilience through cloud redundancy, availability zones and automated daily backups.
Data is encrypted in transit using TLS 1.2 or higher, with backup data encrypted both at rest and in transit.
Controlled access
Access to systems and data is restricted according to role and business need. Controls include:
Role-based and least-privilege access
Unique user credentials and multi-factor authentication
Conditional access policies
Restricted administrative permissions
Regular reviews of user and privileged access
Prompt removal of access when personnel leave the firm
Secure development
Platform changes are managed through a formal development and release process. Code changes are documented, tested in non-production environments and independently reviewed before deployment. Releases require approval and include defined rollback procedures.
Monitoring and incident management
Audere maintains layered network, endpoint and system-security controls designed to identify unauthorised access, malicious activity and other security threats.
Security events and operational incidents are logged, investigated and escalated through a documented incident-management framework. Business continuity and disaster-recovery arrangements are reviewed and tested regularly.
Independent assurance
Audere’s data, technology and information-security controls form part of its independently examined AAF 01/20 and ISAE 3402 control framework.
Clients, prospective clients and their auditors can request our latest assurance report and supporting security information by contacting compliance@auderesolutions.com. Access may be subject to eligibility, confidentiality requirements and acceptance of the independent service auditor’s terms.