Security and procurement
Credible, honest information for buyers evaluating JEGASEC as an early-stage vendor — what we do today, and what's agreed on a per-deployment basis.
Security approach
JEGASEC applies secure-by-design development principles, least privilege, separation of environments, logging and controlled access appropriate to the system being developed. As an early-stage business, we do not hold ISO 27001, IRAP, DISP, SOC 2, Essential Eight maturity, or any other formal security certification — we won't claim one we don't have. Where a customer's engagement genuinely requires a certified control set, we'll say so directly rather than imply coverage we can't stand behind.
Data ownership
Customers retain ownership of the operational data they provide. Contract-specific data handling, retention, deletion and export arrangements are documented before deployment.
Data residency
Hosting location and data-residency requirements are agreed for each deployment. Australian-hosted environments may be used where required and technically available. We don't claim Australian-only hosting as a blanket policy — it's confirmed per engagement.
Sensitive information
JEGASEC does not request classified information through its public website or standard demonstration environments. Spectrum Sentry and its demonstrations use synthetic or authorised data only.
Incident management
Security incidents affecting a customer environment would be assessed, contained, documented and communicated in accordance with the contractual obligations agreed for that engagement.
Procurement readiness
JEGASEC can support standard early-stage procurement processes, including:
- Statements of work
- Confidentiality agreements
- Pilot agreements
- Invoices and purchase orders
- Security questionnaires
- Data-processing schedules
- Defined acceptance criteria
- Implementation planning
These are provided on request as part of a genuine engagement — this page isn't a claim that every document exists in advance for every deployment.
Responsible disclosure
If you believe you've found a security issue affecting JEGASEC's public website or product demonstration environments, contact hello@jegasec.com with enough detail to reproduce it. Please don't include classified, protected or operationally sensitive information in that report.