Loading…
Upskroll is built for organisations operating in regulated environments. Governance, risk management, and data protection are embedded into the platform's structure and operating model. This is not a software product that later added policies. The control framework supports how the system is designed, maintained, and supported.
Aligned with the Privacy Act 1988 (Cth) and Australian Privacy Principles. GDPR accommodated where applicable. Structured incident lifecycle: detection → containment → investigation → remediation → notification. Eligible breaches assessed under the Notifiable Data Breaches (NDB) scheme.
Security framework aligned with recognised international standards.
99.9% monthly uptime target. Severity-based response and restoration targets documented with defined escalation pathways. Planned maintenance windows and emergency maintenance protocols clearly outlined. Service credit mechanisms established.
Formal risk management and business continuity framework. Critical services have defined RTO and RPO. Encrypted daily backups with restore testing. Business Impact Analyses reviewed annually. Disaster recovery procedures documented and tested. Post-incident reviews conducted following major disruptions.
Built to support the Standards for RTOs 2015 and NCVER reporting obligations. Structured data capture and validation ensure compliance with government reporting requirements and audit-ready documentation.
Vendors classified by data sensitivity, access level, and service criticality. Higher-risk vendors undergo formal due diligence and are contractually bound to confidentiality, breach notification, security controls, audit cooperation, and data handling requirements. Subprocessors subject to consistent obligations.
Segregation of duties, defined approval matrices, transparent invoicing, formal dispute handling timelines. Service credits for availability shortfalls governed under documented commitments. Operational integrity extends beyond technical systems.
Formal code of conduct and whistleblower framework. Reporting channels for misconduct, privacy concerns, financial irregularities, or compliance risks. Confidentiality protections and structured investigation procedures maintained. WHS obligations apply across all environments.
Upskroll maintains a consolidated governance framework that maps operational controls to regulatory and industry standards, including the Standards for RTOs 2015, NCVER reporting obligations, privacy legislation, cybersecurity frameworks, business continuity standards, and consumer protection laws. Policies are reviewed at least annually or upon material change. Oversight is maintained at Director level.
Compliance is not marketing language. It is a structured framework that underpins how the platform operates.