Security & Procurement

Security and procurement

Credible, honest information for buyers evaluating JEGASEC as an early-stage vendor: what we do today, and what's agreed on a per-deployment basis.

Security approach

JEGASEC applies secure-by-design development principles, least privilege, separation of environments, logging and controlled access appropriate to the system being developed. As an early-stage business, we do not hold ISO 27001, IRAP, DISP, SOC 2, Essential Eight maturity, or any other formal security certification. We won't claim one we don't have. Where a customer's engagement genuinely requires a certified control set, we'll say so directly rather than imply coverage we can't stand behind.

Data ownership

Customers retain ownership of the operational data they provide. Contract-specific data handling, retention, deletion and export arrangements are documented before deployment.

Data residency

Hosting location and data-residency requirements are agreed for each deployment. Australian-hosted environments may be used where required and technically available. We don't claim Australian-only hosting as a blanket policy, it's confirmed per engagement.

Sensitive information

JEGASEC does not request classified information through its public website or standard demonstration environments. Spectrum Sentry and its demonstrations use synthetic or authorised data only.

Incident management

Security incidents affecting a customer environment would be assessed, contained, documented and communicated in accordance with the contractual obligations agreed for that engagement.

Available during procurement

The following can be made available as part of a genuine procurement or pilot process. This page isn't a claim that every document is pre-approved or held on file in advance, each is prepared or finalised for the specific engagement, and none has been reviewed by a lawyer unless stated otherwise.

  • Mutual confidentiality agreement
  • Statement of work
  • Pilot agreement
  • Implementation plan
  • Acceptance criteria
  • Security questionnaire response
  • Data-processing schedule
  • Incident-notification contacts

These are provided on request as part of a genuine engagement, and are prepared per deployment rather than published in a generic, one-size-fits-all form.

Responsible disclosure

If you believe you've found a security issue affecting JEGASEC's public website or product demonstration environments, contact hello@jegasec.com with enough detail to reproduce it. Please don't include classified, protected or operationally sensitive information in that report.