Security controls, vendor responsibilities and incident response procedures for the Alanna platform.
ALANNA — DATA SECURITY & INCIDENT RESPONSE POLICY
Internal policy — Aumré Financial Group & CoreConverge Technology Services Pty Ltd
Effective date: 4 July 2026 · Version 1.0
| PURPOSE. This policy sets the minimum security controls for the Alanna platform and the joint response plan for security incidents and eligible data breaches under the Notifiable Data Breaches (NDB) scheme, Part IIIC of the Privacy Act 1988 (Cth). It is referenced by clause 16 of the Collaboration & Revenue Share Agreement and is published for transparency. |
1. Roles
| Role | Responsibility |
|---|---|
| CoreConverge (Technical Security Owner) | Implements and operates all technical controls in section 2; leads incident detection, containment and remediation; maintains logs and evidence; provides breach assessment input. |
| Aumré (Privacy & Notification Owner) | Owns the relationship with end users and the OAIC; decides on and issues NDB notifications; handles end-user communications and complaints; maintains the privacy policy. |
| Both (Incident Response Team) | One nominated contact per party, reachable within 4 business hours; joint decisions on breach assessment and notification. |
2. Minimum security controls (CoreConverge implements)
2.1 Access control
- Administrative access limited to named individuals on a least-privilege basis; multi-factor authentication mandatory for all admin, hosting, database and payment consoles.
- End-user authentication via Google OAuth; no passwords stored by the platform.
- Access reviewed quarterly; access revoked within 1 business day when a person leaves either organisation.
2.2 Data protection
- Encryption in transit (TLS 1.2+) for all connections and at rest for databases and backups.
- Data hosted in Australian regions where the provider offers them; any overseas processing limited to the sub-processors disclosed in the Privacy Policy.
- Card data handled exclusively by Stripe (PCI-DSS); the platform never stores card numbers.
- TFN filter: input screening discourages and redacts apparent TFNs and account numbers from stored conversation history.
- Backups: automated daily backups, retained 30 days, restore-tested at least quarterly.
- Retention: conversation history deleted or de-identified within 90 days of account closure; logs retained 12 months.
2.3 Platform security
- Critical security patches applied within 72 hours of vendor release; routine patching monthly.
- Rate limiting, abuse detection and prompt-injection guardrails on the AI interface.
- Secrets managed in a secrets manager (never in source code); dependency scanning enabled in CI.
- Centralised logging and alerting for authentication anomalies, error spikes and unusual data access.
- Annual security review of the platform configuration; findings tracked to closure.
2.4 Vendors (sub-processors)
Approved sub-processors: Vercel (hosting), Supabase (database/auth), Anthropic (AI model — no-training configuration), Stripe (payments), Resend (email). Adding or replacing a sub-processor that handles personal information requires the approval of both parties and a check of its security terms and data location.
3. Incident response plan
| Phase | Actions | Timing / owner |
|---|---|---|
| 1. Detect & report | Anyone who suspects an incident (breach, outage with data exposure, lost credential, vendor breach notice) reports it to both nominated contacts. | Immediately; within 48 hours between parties at the latest (per clause 16.4 of the Agreement) |
| 2. Contain | Revoke credentials, isolate affected systems, preserve logs and evidence. Do not destroy evidence. | CoreConverge, immediately |
| 3. Assess | Joint assessment: what data, whose, how many, is serious harm likely? Documented even if concluded to be non-notifiable. | Both parties; completed within 30 days as required by the NDB scheme, targeting 10 days |
| 4. Notify | If an eligible data breach (serious harm likely and not remediated): notify the OAIC (online form) and affected users as soon as practicable, with the content required by s 26WK. Consider ATO/TPB notification where professional data is involved, and Stripe/banks for payment incidents. | Aumré decides and issues, with CoreConverge technical input |
| 5. Remediate & review | Fix root cause, update controls, post-incident review within 10 business days, update this policy and the register. | Both parties |
Incident register. Aumré maintains a register of all incidents and assessments (including near-misses), retained for 7 years.
4. Review
This policy is reviewed at least annually by the Management Committee, and after any notifiable breach, material platform change or new sub-processor.
