Security

A proportionate approach to security, stated honestly.

Security is not treated as an afterthought or a marketing line. It is designed into the infrastructure from the start, aligned to a recognised national baseline, and described here plainly, including what it does not cover.

Our baseline: the Essential Eight

The Australian Cyber Security Centre's Essential Eight is a set of eight prioritised strategies for protecting systems against common cyber threats. It is deliberately proportionate: it defines four maturity levels, and only the highest levels are expected of large or high risk organisations. Maturity Level 1 is the realistic and appropriate baseline for a small organisation, and DataBytes AI designs and deploys infrastructure aligned to that level for every engagement.

This is a self assessed posture, not an independently audited one, which is standard practice at this scale. Where a specific contract or funder requires a higher maturity level or a formal audit, that can be scoped as additional work.

What this means day to day

  • Centralised sign on with multi factor authentication for all administrative and staff accounts
  • Role based access, so each person only has the access their role actually needs
  • Infrastructure defined as version controlled configuration, so updates are applied deliberately and can be rolled back
  • Regular, automated backups as standard
  • Production data and backups held in Australia, on infrastructure controlled through your own account — any external service that may process content, such as an AI provider you've opted into, is identified upfront

What we do not claim

Not every Essential Eight strategy applies to every kind of system. For example, Microsoft Office macro controls are not relevant to a server based platform, so that particular strategy simply does not apply here. This page describes the strategies that do apply, self assessed against Maturity Level 1, and scoped to the platform we deploy. Your organisation's overall Essential Eight maturity also depends on endpoints, identity management, patching and the rest of your ICT environment, which sit outside what any single deployed platform can establish. Formal certifications such as ISO 27001 are not claimed, and we will say so plainly if a request goes beyond what this baseline covers.

Continuity

Because infrastructure is defined as version controlled configuration and comes with written runbooks and full handover documentation, the platform can be understood, operated and supported independently. Capacity building is part of every engagement for exactly this reason: your system should never depend on any one individual, including us, for its day to day running.

Have a specific requirement?

Tell us what your funder or contract actually requires.

If a particular grant agreement, government contract or insurer has specific security requirements, share the details and we will tell you plainly whether they are met by this baseline or would need additional work.

Email hello@databytesai.com.au