Security at ArchZen

Security

How ArchZen approaches identity, data protection, secure operations, resilience and responsible technology delivery.

Effective date: 7 July 2026

Our commitments

Clear principles, practical safeguards.

Security by design

Security is considered from discovery and architecture through implementation, support and continuous improvement.

Identity first

Strong authentication, controlled access and least privilege are central to reducing business risk.

Operational resilience

Monitoring, backups, patching and recovery planning support reliable and secure service delivery.

Continuous visibility

Logs, alerts and security reviews help identify issues, support response and improve controls over time.

1

Our security approach

ArchZen delivers managed IT, cybersecurity, cloud, AI and automation services with security built into the way solutions are assessed, designed and operated.

Our approach is risk-based. Controls are selected according to the organisation, information involved, platforms used, operational impact and applicable obligations.

2

Identity and access management

  • Multi-factor authentication where available and appropriate.
  • Role-based access and least-privilege principles.
  • Controlled administrator access and separation of duties where practical.
  • Joiner, mover and leaver processes to reduce unmanaged access.
  • Review of authentication, session and access risks.
3

Endpoint security

  • Endpoint protection and security monitoring.
  • Supported operating systems and critical security updates.
  • Encryption and secure configuration where appropriate.
  • Secure remote support using controlled and auditable methods.
  • Device visibility and risk-based remediation.
4

Cloud and platform security

We consider platform permissions, identity configuration, data flows, integration security, administrative access, logging and resilience when working with cloud services.

  • Secure configuration of Microsoft 365, Google Workspace and cloud platforms.
  • Review of domain, DNS, email authentication and external exposure where relevant.
  • Security controls appropriate to the service and client environment.
5

Data protection

  • Encryption where appropriate in transit and at rest.
  • Access controls based on business need.
  • Secure backup and recovery arrangements.
  • Data minimisation and controlled handling of sensitive information.
  • Retention and deletion practices aligned to operational and legal requirements.
6

Monitoring and logging

Where reasonably necessary, systems, logs and service activity may be monitored to maintain reliability, investigate incidents, prevent misuse, meet legal obligations and protect clients and infrastructure.

Monitoring is performed in accordance with applicable privacy obligations and contractual arrangements.

7

Patching and vulnerability management

Supported software, timely security updates and remediation of material weaknesses are important parts of maintaining a secure environment.

We may recommend replacing unsupported systems, applying critical updates or implementing additional controls based on identified risk.

8

Backup and recovery

Backups and recovery processes help reduce operational impact from accidental deletion, system failure, cyber incidents and other disruptions.

Backup scope, retention, testing and recovery expectations depend on the service agreement and client requirements.

9

Secure AI and automation

  • Review of data sources, permissions, integrations and system boundaries.
  • Human oversight and escalation for higher-risk workflows.
  • Testing of normal cases, exceptions, failures and unauthorised actions.
  • Logging and accountability appropriate to the solution.
  • Vendor and platform assessment before business use.
10

Third-party providers

ArchZen works with established technology providers for cloud, productivity, security, backup, monitoring and related services.

We consider business suitability, security controls, privacy practices, access requirements and service dependencies when selecting or recommending providers.

11

Security incidents

Potential incidents are assessed according to their nature, impact, available evidence and contractual responsibilities.

Response may include containment, investigation, remediation, recovery, documentation and client communication. Regulatory or legal notification requirements are assessed where applicable.

12

Client security responsibilities

Security is a shared responsibility. Clients are expected to protect credentials, use authorised services responsibly and cooperate with reasonable security recommendations.

  • Enable MFA where available.
  • Apply critical updates and maintain supported systems.
  • Notify ArchZen promptly of suspected compromise.
  • Control authorised users and protect authentication devices.
  • Review and act on material security recommendations.
13

Security limitations

No technology environment can be guaranteed to be completely secure. Threats, software, human behaviour and third-party services change continuously.

ArchZen applies reasonable controls based on the agreed scope, but outcomes also depend on client decisions, implementation timing, licensing, user behaviour and external providers.

14

Reporting a security concern

To report a suspected security issue involving ArchZen systems or services, contact security@archzen.com.au with a clear description and relevant evidence. Do not access data, disrupt services or perform testing without written authorisation.

ArchZen Pty Ltd

Need to report a security concern?

Contact our team for clarification, privacy requests, security enquiries or policy-related questions.

security@archzen.com.au