Security, privacy and data handling
You should know how we think about security and privacy before you ask.
Most of our clients send us a security questionnaire early, often during procurement or onboarding. The questionnaire is the right move and we welcome it. This post is the version of those answers we'd rather you read first, because it explains the principles behind them. If you'd prefer to skip straight to the questionnaire, the contact section at the bottom of this page will get you to us.
The film at the top of this post is the shortest version of these answers we could make. It runs about a minute and covers the four questions our clients ask most often. The post below goes deeper on each.
[YouTube embed will appear here once the film is published to HutSix's YouTube channel. Click-to-play, not autoplay.]
We do not claim certifications, controls or levels of assurance we have not achieved. No provider can honestly promise zero incidents, and we will not.
Where a control cannot be implemented immediately, we would rather be transparent about a limitation than create a false impression of assurance. Where a control sits with a third party, we will say so.
Unless otherwise agreed, the application, databases, storage and our managed backups are hosted in Australia, in AWS Sydney (ap-southeast-2). The architecture for your solution is confirmed during onboarding.
Where a dedicated environment is part of the agreed solution, it sits in its own AWS account. That gives account-level separation between client environments and keeps your data out of any shared account.
Specific infrastructure identifiers and detailed architecture information are available to your authorised representatives through our security assurance process. They are not published publicly.
What we cannot guarantee
Third-party providers run their own infrastructure and networks. We do not control where they process API requests, authentication traffic or related communications, so we cannot guarantee every interaction stays exclusively within Australia.
Each provider's residency, privacy and security practices remain subject to their own infrastructure, terms and policies.
Access is granted on a least-privilege basis. During onboarding, we determine who can approve access, and how provisioning, access reviews and offboarding will be managed. Account and administrative activity is logged.
Independent penetration testing is not a standard component of the service. Where your governance or assurance program requires it, we arrange it as a separately scoped and quoted engagement. We do not bundle pen testing into our standard fee, because the scope and methodology should match your environment rather than ours.
We handle personal information under the Privacy Act 1988 and the Australian Privacy Principles.
Unless otherwise agreed with you, we do not disclose or process client-provided personal information using AI tools.
Information about approved AI tools is available to authorised clients as part of security and privacy due diligence, as an AI Tool Register, a project-specific extract, or another suitable assurance document.
We would rather be transparent about a limitation than create a false impression of assurance. If you have a security questionnaire, an assurance requirement or a governance checklist underway, send it to us. We would rather work through it early than after implementation.
Contact
To send us a security questionnaire or talk through an assurance requirement, visit hutsix.com.au and use the contact page there. We will come back to you with specific answers.


