Trust at Conpago
Conpago is ISO 27001 certified and Australian owned. We protect sensitive information with role-based access, encryption, audit logs and secure backups, so your team can assess risk with confidence.
Action of binding together, fastening
Structure, framework

Independently verified, not self-declared

ISO/IEC 27001:2022
ISO/IEC 27001 is the international standard for managing information security. It sets external requirements for how sensitive information is protected, risk assessed and kept under continual review. Conpago has held certification since July 2024, with controls externally audited and reviewed annually.

ISO/IEC 42001 (planned)
ISO/IEC 42001 is the international standard for managing artificial intelligence responsibly. It sets external requirements for how AI is governed, risk assessed and kept under human oversight. Certification is planned for 2026, holding our AI governance to the same standard as our security.
Your data stays in Australia
Conpago is Australian owned and Australian based. Production data is hosted onshore, with multiple backups in data centres across NSW and Victoria, and covered by the Privacy Act 1988. Your community's information is stored and processed here.
Hosted onshore · backups across NSW and VIC
How Conpago earns trust
Product
Security is built into how we design and ship the platform, not added later.
Data
Encryption, controlled access and secure backups help protect data at rest and in transit.
Monitoring
Monitoring and alerting help us identify issues early and keep systems reliable.
Corporate
Clear ownership, staff training and supplier checks support consistent security practices.
Policy
Documented policies guide how we assess risk, respond to incidents and recover services.
Legal
Transparent policies and trusted third-party partnerships to ensure full compliance.
At Conpago, security is an ongoing practice, not a one-off project
Our posture is proactive, rather than reactionary, with our onshore team conducting regular security reviews and planned enhancements to strengthen controls.
Executive-level oversight ensures clarity around our governance, supported by continual staff training, so we remain compliant and keep your information safe.
Security and compliance controls
Practical safeguards that protect your data, support audit requirements and help teams operate with confidence.
Product Security
Protecting every user interaction.
Our identity and access systems keep every account secure with verified logins, detailed activity tracking and strong session protection.
SSO Support
Supports single sign-on so identity is managed by your existing identity provider, and access follows your organisation's own controls.
Audit Logging
Security events, such as sign-ins and permission changes, are logged to support investigation, oversight, and compliance reporting.
Data Security
Application data is stored in managed environments with restricted access and regular backups, separating production and internal systems.
MFA Capabilities
Leverages native multi-factor authentication offered by compatible identity providers, enforcing existing protections when accessing the platform.
Data Security
Keeping your data protected.
Conpago's infrastructure is designed with layers of protection to help ensure your data is secure while transmitted, stored or processed.
Tokenised Sensitive Info
Uses tokenised information for sensitive information, meaning raw payment details never pass through or are stored in the platform.
Multi-Region Sovereign Backups
Data is backed up across regions, onshore in Australia, supporting recovery from corruption or hardware failure.
Encryption at Rest
Primary data stores and backups are encrypted at rest using industry-standard encryption, protecting against unauthorised access to storage media.
Encryption in Transit
Data in transit between customers, services and internal components is protected to prevent interception or tampering.
Continuous Monitoring
Monitoring your system.
Conpago's infrastructure is protected by layered access control, centralised monitoring and auditable change to safeguard the system.
Access Monitoring
Layers of access controls restrict unnecessary handling of data.
Logging and Monitoring
Centralised logging and infrastructure monitoring provide visibility into system health and potential security incidents.
Change Monitoring Policy
Production changes follow a documented change process with tracking and review, so modifications are visible and auditable.
Corporate Security
Operating securely.
We treat security as a responsibility of everyone in their day-to-day, with controlled staff access, vetted suppliers and ongoing training.
Asset and Supplier Registers
Key information assets and suppliers are recorded and reviewed, so we understand dependencies and risks.
Role-Based Access Controls
Staff access to systems and data is based on role, following least-privilege principles with periodic access review.
Penetration Testing
Regular penetration testing helps identify weaknesses so they can be assessed and rectified.
Software Development Lifecycle
Security reviews, code reviews and automated testing are built into the development lifecycle before changes reach production.
Security Policy Stack
Governing risk clearly.
Documented policies for assessment, response, recovery and change guide how we manage risk and review remediations.
Vulnerability Management
Identified vulnerabilities are tracked, assessed for impact and remediated swiftly.
Risk Assessment Policy
Material changes and new initiatives are subject to risk assessment to identify controls and mitigations.
Incident Response Plan
A documented incident response plan sets out roles and communication paths for handling security events.
Disaster Recovery Plan
Disaster procedures define how our core services and data are restored following a major outage or loss event.
Legal Protections
Contractual assurance.
Our privacy policy, data terms, and subprocessors give legal and compliance teams a transparent view of how and who is involved in handling data.
Privacy Policy
Our Privacy Policy outlines how we collect, use, store, and share important data, and the rights available to individuals.
Standard Terms (Upon Request)
Standard contractual terms are available upon request and include provisions on security, data protection, and customer responsibilities.
Subprocessors
Conpago employs Google, Twilio, and SendGrid services for our business processes, providing core infrastructure, communications, and security controls.
Conpago has been certified to ISO/IEC 27001:2022 for its information security management system since July 2024.
Conpago is Australian founded, owned, and operated. Our leadership team has hands-on experience and research in the retirement and care sector.
Conpago champions a proactive approach to security. We design and operate the platform with a focus on anticipating and reducing security risks wherever possible, rather than simply reacting to incidents after they occur.
We recognise the vulnerability of some of our users. We use native security features from our subprocessors, such as multi-factor authentication and tokenised data for payments, meaning we never touch or store that sensitive data.
Due diligence questions? Talk to us.
We'll answer them directly and put you in front of the people who hold the answers.
Book a Demo
