Legal Center
Information Security Policy
Last Updated: November 5, 2025
Information Security Policy
Enboarder protects information, systems, data, and supporting technology through risk-based controls, secure operations, and continual improvement.
Information security is the protection of information and supporting systems from a wide range of threats in order to ensure business continuity, minimise operational risk, and maximise return on investments and operational opportunities.
Data, information, and the underlying technology systems are essential assets to Enboarder. They provide vital resources to our staff and customers and must therefore be suitably protected.
The security of information in all its forms is of the utmost importance to Senior Management. Information security is achieved by implementing a suitable set of controls based on our risk profile, including policies, processes, procedures, organisational structures, software, and hardware functions. This gives interested parties confidence that risks from potential incidents are adequately managed.
This policy applies to all employees and other relevant third parties.
Controls are selected and implemented based on Enboarder’s risk profile and operational needs.
Employees receive cyber security awareness training and are granted access based on need.
Enboarder maintains and improves its Information Security Management System over time.
Information Security Principles
Enboarder works to enact best-practice principles of information security, including:
- Systems and applications are configured to reduce their attack surface.
- A defence-in-depth security methodology is employed.
- Systems and applications are administered in a secure and accountable manner.
- Security vulnerabilities in systems and applications are identified and mitigated in a timely manner.
- Data, applications, and configuration settings are backed up on a regular basis.
- Personnel are granted the minimum access to systems, applications, and data repositories required for their duties.
- Personnel are provided with ongoing cyber security awareness training.
Information Security Objectives
To support these principles, the following information security objectives have been established:
- Establish and continually improve an Information Security Management System.
- Ensure strategic and operational information security risks are understood and treated to an acceptable level for Enboarder.
- Ensure public web services and internal networks meet specified availability standards.
- Conduct application vulnerability scans to help protect the application from emerging threats.
- Produce, maintain, and test business continuity plans, including information security continuity, as far as practicable.
- Provide information security training to all employees.
Our Commitments
To achieve these objectives, we will:
- Communicate this policy to all existing employees and to new employees upon commencement.
- Comply with all legislative, regulatory, and other requirements relevant to Enboarder.
- Make our commitment to information security visible to all interested parties.
- Maintain and continually improve an Information Security Management System that meets the requirements of ISO 27001:2022 and SOC 2 Type II.