Information Security Policy

Effective Date: June 2026

Zero Carbon Australia Pty Ltd ("Zero Carbon Australia", "we", "our", or "us") is committed to protecting the confidentiality, integrity and availability of information entrusted to us by our customers, partners and employees.

This Information Security Policy outlines the security principles and controls that govern the operation of the Zero Carbon Australia Platform ("Platform").

1. Purpose

The purpose of this Policy is to:

  • protect customer and business information;
  • reduce cybersecurity risks;
  • support business continuity;
  • comply with applicable legal and regulatory requirements;
  • promote secure handling of information;
  • maintain customer trust.

2. Scope

This Policy applies to:

  • the Zero Carbon Australia Platform;
  • all employees, contractors and consultants;
  • authorised users of the Platform;
  • cloud infrastructure;
  • software applications;
  • databases;
  • APIs;
  • development environments;
  • third-party service providers that process information on our behalf.

3. Security Principles

Our security program is based on the following principles:

  • Confidentiality
  • Integrity
  • Availability
  • Accountability
  • Privacy by Design
  • Least Privilege
  • Defence in Depth
  • Secure by Default
  • Continuous Improvement

4. Information Classification

Information is classified according to its sensitivity.

Categories include:

  • Public
  • Internal
  • Confidential
  • Restricted

Appropriate safeguards are applied based on the classification of the information.

5. Access Control

Access to systems is provided only where required for legitimate business purposes.

Security controls include:

  • unique user accounts;
  • strong password requirements;
  • role-based access control (RBAC);
  • least privilege access;
  • account approval workflows;
  • periodic access reviews;
  • prompt removal of access when no longer required.

Administrative access is restricted to authorised personnel.

6. Multi-Factor Authentication

Where supported, Multi-Factor Authentication (MFA) is required for:

  • administrator accounts;
  • privileged users;
  • production environments;
  • cloud management consoles;
  • development repositories;
  • remote administrative access.

Customers are encouraged to enable MFA for their own accounts.

7. Password Security

Passwords should:

  • be unique;
  • be of sufficient length and complexity;
  • not be shared;
  • not be reused across services.

Passwords are stored using industry-standard cryptographic hashing and are never stored in plain text.

8. Encryption

Sensitive information is protected using encryption.

Security controls include:

  • encryption of data in transit using Transport Layer Security (TLS);
  • encryption of sensitive data at rest where appropriate;
  • secure management of encryption keys;
  • encrypted backups where practical.

9. Cloud Security

The Platform is hosted using reputable cloud infrastructure providers.

Cloud security practices include:

  • network isolation;
  • infrastructure monitoring;
  • secure storage;
  • regular updates;
  • vulnerability management;
  • identity and access controls;
  • logging and audit capabilities.

10. Application Security

Security is integrated throughout the software development lifecycle.

Practices include:

  • secure coding standards;
  • code review;
  • dependency management;
  • vulnerability scanning;
  • testing before production release;
  • controlled deployment processes.

11. API Security

Where APIs are available:

  • authentication is required;
  • encrypted connections are enforced;
  • rate limiting may be applied;
  • monitoring may be performed to detect misuse;
  • API access may be revoked where necessary.

12. Data Protection

Customer information is protected using administrative, technical and physical safeguards.

These measures include:

  • access controls;
  • encryption;
  • logging;
  • monitoring;
  • backups;
  • secure deletion procedures;
  • disaster recovery planning.

Customers remain responsible for ensuring the accuracy of information they upload.

13. Logging and Monitoring

The Platform maintains security logs to assist with:

  • monitoring system activity;
  • detecting unauthorised access;
  • investigating incidents;
  • auditing security events;
  • supporting compliance obligations.

Logs are protected from unauthorised modification.

14. Vulnerability Management

We maintain processes to identify and address security vulnerabilities.

This includes:

  • routine patching;
  • software updates;
  • dependency monitoring;
  • vulnerability assessments;
  • remediation based on risk.

15. Security Testing

Security testing may include:

  • vulnerability scanning;
  • penetration testing;
  • configuration reviews;
  • access control reviews;
  • code analysis;
  • security assessments.

Testing frequency is determined according to business risk.

16. Incident Response

Zero Carbon Australia maintains an Incident Response process designed to:

  • identify security incidents;
  • contain threats;
  • investigate root causes;
  • restore services;
  • communicate with affected customers where appropriate;
  • implement corrective actions.

17. Data Breach Management

Where a data breach is likely to result in serious harm, we will comply with applicable legal obligations, including the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth).

Where required, affected individuals and the Office of the Australian Information Commissioner (OAIC) will be notified.

18. Backup and Disaster Recovery

Regular backups are performed to support business continuity.

Backups are:

  • protected from unauthorised access;
  • tested periodically where appropriate;
  • retained in accordance with operational requirements.

Disaster recovery procedures are maintained to support restoration of critical services.

19. Business Continuity

Zero Carbon Australia maintains business continuity procedures intended to minimise service disruption caused by:

  • cyber incidents;
  • hardware failure;
  • software failure;
  • natural disasters;
  • cloud service interruptions;
  • other operational events.

20. Third-Party Service Providers

We engage trusted third-party service providers to support Platform operations.

These providers may include services for:

  • cloud hosting;
  • authentication;
  • payment processing;
  • communications;
  • analytics;
  • monitoring;
  • customer support.

We conduct reasonable due diligence and expect service providers to maintain appropriate security standards.

21. Employee Responsibilities

Employees and contractors are expected to:

  • protect confidential information;
  • follow security procedures;
  • report suspected incidents promptly;
  • use approved systems;
  • safeguard credentials;
  • participate in security awareness training where required.

22. Customer Responsibilities

Customers are responsible for:

  • maintaining secure passwords;
  • protecting account credentials;
  • enabling MFA where available;
  • ensuring authorised use of their accounts;
  • promptly reporting suspected unauthorised access;
  • maintaining appropriate security on their own devices and networks.

23. Acceptable Use

Users must not:

  • attempt unauthorised access to systems;
  • interfere with Platform security;
  • upload malicious software;
  • conduct denial-of-service attacks;
  • exploit vulnerabilities;
  • misuse APIs;
  • engage in unlawful activity using the Platform.

Accounts may be suspended or terminated where these requirements are breached.

24. Compliance

Zero Carbon Australia seeks to operate in accordance with applicable legal and regulatory requirements, including:

  • Privacy Act 1988 (Cth);
  • Australian Privacy Principles (APPs);
  • Australian Cyber Security Centre (ACSC) guidance;
  • contractual security obligations;
  • industry best practices.

Where appropriate, we may align our security management practices with recognised international standards, including ISO/IEC 27001.

25. Policy Review

This Information Security Policy is reviewed periodically and updated as necessary to reflect:

  • emerging cybersecurity threats;
  • changes in technology;
  • legal and regulatory developments;
  • business requirements;
  • lessons learned from security incidents.

26. Contact Us

Questions regarding this Information Security Policy or the security of the Platform should be directed to:

Security Officer

Zero Carbon Australia Pty Ltd

Email: support@zerocarbonaustralia.org

Website: https://zerocarbonaustralia.org

We encourage responsible disclosure of potential security vulnerabilities. Security concerns should be reported promptly using the contact details above.