Security & Procurement

Security and procurement

Credible, honest information for buyers evaluating JEGASEC as an early-stage vendor — what we do today, and what's agreed on a per-deployment basis.

Security approach

JEGASEC applies secure-by-design development principles, least privilege, separation of environments, logging and controlled access appropriate to the system being developed. As an early-stage business, we do not hold ISO 27001, IRAP, DISP, SOC 2, Essential Eight maturity, or any other formal security certification — we won't claim one we don't have. Where a customer's engagement genuinely requires a certified control set, we'll say so directly rather than imply coverage we can't stand behind.

Data ownership

Customers retain ownership of the operational data they provide. Contract-specific data handling, retention, deletion and export arrangements are documented before deployment.

Data residency

Hosting location and data-residency requirements are agreed for each deployment. Australian-hosted environments may be used where required and technically available. We don't claim Australian-only hosting as a blanket policy — it's confirmed per engagement.

Sensitive information

JEGASEC does not request classified information through its public website or standard demonstration environments. Spectrum Sentry and its demonstrations use synthetic or authorised data only.

Incident management

Security incidents affecting a customer environment would be assessed, contained, documented and communicated in accordance with the contractual obligations agreed for that engagement.

Procurement readiness

JEGASEC can support standard early-stage procurement processes, including:

  • Statements of work
  • Confidentiality agreements
  • Pilot agreements
  • Invoices and purchase orders
  • Security questionnaires
  • Data-processing schedules
  • Defined acceptance criteria
  • Implementation planning

These are provided on request as part of a genuine engagement — this page isn't a claim that every document exists in advance for every deployment.

Responsible disclosure

If you believe you've found a security issue affecting JEGASEC's public website or product demonstration environments, contact hello@jegasec.com with enough detail to reproduce it. Please don't include classified, protected or operationally sensitive information in that report.