Security at Kicking Pixels, Gatheroo & MWA

The Kicking Pixels builds and operates digital products for organisations that can’t afford to get security wrong, including clients in healthcare and government. This page sets out how we protect information: the controls we operate, who our sub-processors are, where data is stored, and how we handle incidents and privacy requests.

Our information security management system is certified to ISO/IEC 27001:2022. One certified management system covers all our brands, so the same governance, access control, incident response and supplier management applies whether you’re using Gatheroo, on a MyWebAdvantage care plan, or running an enterprise build with Kicking Pixels.

This Trust Centre covers Kicking Pixels, MyWebAdvantage and Gatheroo.

Subprocessors

Amazon Web Services

Infrastructure provider for Gatheroo. Primary infrastructure for the Gatheroo application. All data uploaded to Gatheroo is stored and processed with Amazon Web Services. Platform hosting, storage and backup.
Australia

Bitbucket

Version Control. Bitbucket is used to manage and store the Gatheroo source code. It enables secure version control and collaborative development across our team.
USA

WPEngine

Website Hosting. Managed WordPress hosting, SSL, backups.
Australia

Access is granted on a least-privilege basis, reviewed annually and on every role change, and revoked within 24 hours of a person leaving.

We deploy updates regularly for improvements, fixes and security patches. Emergency security patches are expedited.

ISO 27001 is the international standard for information security management systems. Certification means an accredited third party has audited our security practices against the standard and continues to audit us annually.

Yes. Two-factor authentication is available to all Gatheroo users via email or SMS, and MFA is enforced across our internal systems and all production access.

Governance & Certification

Control
Status
ISO/IEC 27001:2022 certified

One independently certified management system covering all brands and services.

Certificate number 1357-I-1, issued by Global Compliance Certification Pty Ltd under JAS-ANZ accreditation. Held by Kicking Pixels Pty Ltd, ABN 13 136 066 496, trading as MyWebAdvantage and Gatheroo. Scope: information security management system for the provision of SaaS products, website planning, design and development. Issued 26 March 2025, valid to 25 March 2028, maintained through annual surveillance audits. Next surveillance audit Q1 2027.

A copy of the certificate, extracts from our Statement of Applicability, and completed security questionnaires are available on request.

Documented policy framework

Fifteen information security policies cover governance, access, assets, physical security, third parties, people, data protection, cryptography, development and incident response. Each is reviewed at least annually.

Independent surveillance

The ISMS is audited annually by our accredited certification body.

Internal audit programme

A three-year audit schedule covers every applicable clause and control, with findings reported to management.

Management review

Security performance is reviewed quarterly against documented annual information security objectives.

Risk management

A documented risk assessment and treatment process is maintained, with a risk register reviewed annually and on significant change.

Regulatory monitoring

Australian privacy law and ACSC guidance are reviewed quarterly, with a full legal and regulatory compliance assessment annually.

Access & Identity

Control
Status
Least privilege

Access is granted on a least-privilege basis, with management approval required for elevated access.

Centralised identity

Microsoft 365 is our primary identity provider, with account lifecycle managed by the Administrative Lead.

Multi-factor authentication

Enforced across internal business systems and all production access.

Access reviews

Access is reviewed annually and on every role change, and revoked within 24 hours of a person leaving.

Privileged access

Administrative access is restricted to named personnel with MFA enforced and credentials held in a managed secrets vault.

VPN-only remote access

All remote access to production systems requires a dedicated VPN with multi-factor authentication.

Data Protection & Privacy

Control
Status
Information classification

All information is treated as confidential by default. External sharing requires management approval.

Approved storage only

Client and business data is stored only in approved platforms. Personal cloud storage and removable media are prohibited.

Data location and access

Gatheroo customer data is stored exclusively in Australia. Client websites are hosted in Australia, with encrypted offsite backups held in the United States. A small number of our personnel located outside Australia access production systems remotely via dedicated VPN with multi-factor authentication and full activity logging.

Encryption in transit

TLS 1.2 or higher for all data transmitted externally.

Encryption at rest

Production databases, file storage and backups are encrypted, and full-disk encryption is mandatory on all devices.

Data masking

Payment card details display the last four digits only. Passwords are never displayed.

Australian Privacy Principles

Personal information is handled in accordance with the Privacy Act 1988 and the Notifiable Data Breaches scheme, with GDPR obligations met where EU data subjects are involved.

No payment card data held

All payment processing is outsourced to Stripe, a PCI DSS Level 1 provider.

Privacy rights

Access requests answered within 30 days, corrections within 14 days, deletions assessed within 14 days and actioned within 30.

Product & Application Security

Control
Status
Secure development lifecycle

Changes flow through separated environments with security checks at each stage. No code reaches production without staging validation.

Peer-reviewed code

Changes to protected branches require pull request review and approval. Direct pushes are blocked and full history is retained as an audit trail.

Secure coding standards

Input validation, server-side authorisation, no secrets in code, generic error messages, and OWASP Top 10 applied throughout.

Synthetic test data only

Real client data is never used in development, staging or pre-flight environments.

Vulnerability remediation

Critical and high severity findings are remediated within 30 days, medium within 90, low within 180. Emergency security patches are expedited within 7 days.

Security testing

OWASP-methodology testing and staging validation before every release, plus an annual infrastructure security assessment. Independent penetration testing is available where a client’s procurement process requires it.

AI tooling controls

No client data, personal data or source code is entered into AI tools. AI-assisted development is restricted, operates with privacy mode enforced, and all output is reviewed before reaching production.

Infrastructure & Operations

Control
Status
Managed cloud infrastructure

We operate on AWS, Microsoft 365 and managed WordPress hosting under shared responsibility models. All hold ISO 27001 or equivalent certification.

Environment separation

Development, staging and production environments are maintained separately across all platforms.

Endpoint security

Company devices use full-disk encryption, endpoint protection, automatic screen lock and current security patches.

Network segregation

A dedicated business network operates separately from building infrastructure, with guest traffic isolated.

Logging

Cloud audit logs and system access logs are retained for a minimum of 12 months.

Monitoring

Automated alerting from cloud and hosting providers, reviewed monthly, with immediate escalation of alerts.

Removable media prohibited

USB and external media are prohibited on all company devices.

Approved software only

Software installation is restricted to a maintained approved software list.

Resilience & Incident Response

Control
Status
Backups

Every production system is backed up on a documented schedule with defined retention, verified monthly and quarterly, with a full restoration test performed annually.

Recovery objectives

Target recovery times of one hour for Gatheroo, one hour for email, and two hours for client websites.

Documented incident response

A documented plan with severity classification and defined phases covering detection, investigation, containment, recovery and review.

Response timeframes

Incident reports are acknowledged within 4 business hours and technical containment is targeted within 8 business hours.

Breach notification

Suspected breaches are contained immediately and assessed against the Notifiable Data Breaches scheme. Where a breach is confirmed as eligible, we notify the OAIC and affected individuals as soon as practicable. Clients are notified within 24 to 72 hours in line with contractual terms. Where EU data subjects are involved, the relevant supervisory authority is notified within 72 hours.

Post-incident review

Root cause analysis is completed after every incident, with lessons applied to policy and procedure.

People & Personnel Security

Control
Status
Screening

Personnel with privileged access undergo reference checks and employment history verification before access is granted.

Confidentiality agreements

Signed before any system access is granted.

Security awareness training

Completed annually by all personnel, with additional annual secure coding training for developers.

Onboarding and offboarding

A security briefing is required before access is granted. All access is revoked within 24 hours of a person leaving.

Remote working

Documented home office security requirements apply, with VPN mandatory for production access and on public Wi-Fi.

Physical security

Our office is located in a professionally secured building with controlled access, monitoring, a visitor log and key register, operated under clear desk and clear screen practices.

Supplier & Sub-processor Management

Control
Status
Assessment before engagement

A security assessment is completed before engaging any vendor that will handle business or client data.

Annual review

All active vendors are reviewed annually with certifications reconciled, plus a quarterly check for unrecorded changes.

Data processing terms

Data processing agreements or equivalent contractual terms are in place for vendors processing personal data.

30-day change notification

We publish our sub-processors and provide at least 30 days’ notice before adding or replacing any sub-processor that processes client data.

Gatheroo

Control
Status
Australian data residency

All customer data is stored in AWS Australian regions, Sydney primary with Melbourne for backup.

Two-factor authentication

Available to all users via email or SMS.

No client accounts required

Your clients complete requests through a secure link, so there are no extra credentials to manage.

Field-level encryption

Sensitive text fields such as tax file numbers carry additional AES-128-GCM encryption.

Immediate deletion

Deleting a file removes it from active storage immediately, clears encrypted backups within seven days, and is recorded permanently in the activity log.

Retention and account closure

Data is retained for the life of the subscription and deleted 60 days after cancellation. Inactive trial accounts are deleted automatically after 60 days.

Backups

Hourly database and instance snapshots with seven-day retention, plus continuous file versioning, held in a second Australian region.

Complete audit trail

Every request, submission, view, download and deletion is timestamped and logged.

Four-stage pipeline

Changes flow through local, staging, pre-flight and production environments.

Websites — Kicking Pixels & MyWebAdvantage

Control
Status
Australian managed hosting

Client websites are hosted on managed WordPress infrastructure in Australia with server-level security monitoring and automatic threat protection.

Website Backups

Full site backups daily with 60-day retention at the host, plus a daily offsite copy retained 90 days.

Plugin vulnerability monitoring

Plugin and theme vulnerabilities are monitored with daily alerts, and updates are tested in staging before being applied to production.

Malware scanning

Daily malware scanning and detection across managed sites, with WordFence deployed on security-sensitive websites.

SSL and certificate management

Certificates are tracked in an expiry register and renewed before expiration.

Pre-launch security verification

Security headers, HTTPS configuration, permissions and access controls are verified before every site goes live.

Security hardening assessment

Client projects include a security hardening assessment as part of delivery.

Recovery objective

Target recovery time of two hours for client websites.

Website security assessments

Standalone security evaluation services are available for existing client websites.

Amazon Web Services

Infrastructure provider for Gatheroo. Primary infrastructure for the Gatheroo application. All data uploaded to Gatheroo is stored and processed with Amazon Web Services. Platform hosting, storage and backup.
Australia

Bitbucket

Version Control. Bitbucket is used to manage and store the Gatheroo source code. It enables secure version control and collaborative development across our team.
USA

WPEngine

Website Hosting. Managed WordPress hosting, SSL, backups.
Australia

Office365

Document Management. Office365 is used to store, manage, and collaborate on documents and files securely across all Kicking Pixels Group brands.
Australia

Stripe

Payment processor for billing. Billing data and email addresses are processed by Stripe to facilitate secure payments for all subscriptions.
USA

ManageWP

Website Management. Offsite backups, vulnerability, uptime and malware monitoring.
USA

Growth360 (GoHighLevel)

Marketing. CRM and client communications.
USA

Client Control and Support

Email security@kickingpixels.com.au. Reports are acknowledged within 4 business hours.

Yes. We support procurement and compliance teams with documentation, questionnaire responses and calls.

Yes. Submit requests through support or your account contact.

Yes. We provide onboarding sessions, documentation and ongoing support tailored to your team.

In Gatheroo you control every field, template and permission, so you request only what you need.

You do. Unless you are on a rental subscription, you retain full ownership of your content, design assets and domain.

Data Protection and Privacy

Gatheroo customer data is stored only in Australia, in AWS Australian regions. Client websites are hosted in Australia, with encrypted offsite backups held in the United States. Payment processing and CRM are provided by US-based providers. Our full sub-processor list, including data locations, is published above.

Yes. All data is encrypted in transit using TLS 1.2 or higher and encrypted at rest. In Gatheroo, sensitive text fields such as tax file numbers carry additional AES-128-GCM field-level encryption.

Yes. A small number of our own personnel located outside Australia access production systems remotely through a dedicated VPN with multi-factor authentication and full activity logging. They are screened before access is granted and subject to the same policies as our Australian team. No Gatheroo customer data is stored outside Australia.

We access client documents only when necessary for support, and only with your written permission. You retain ownership of your data at all times.

Gatheroo data is retained for the life of your subscription and deleted 60 days after cancellation. Inactive trial accounts are deleted automatically after 60 days. Website backups are retained 60 to 90 days depending on the provider. Security logs are retained for a minimum of 12 months. Financial records are retained for 7 years as required by law.

Yes. You can export your Gatheroo request data at any time, and deletion requests are supported and processed securely.

Gatheroo data is securely deleted 60 days after cancellation. You can request immediate deletion if you prefer.

Deleting a file removes it from active storage immediately. It clears our encrypted backups within seven days, and the deletion is recorded permanently in the activity log.

No. Client data, personal data and source code are never entered into AI tools, and none of your data is used for model training.

No. Development, staging and pre-flight environments use synthetic or anonymised data only.

Email privacy@kickingpixels.com.au. Access requests are answered within 30 days, corrections within 14 days, and deletion requests are assessed within 14 days and actioned within 30.

Platform Operations

We deploy updates regularly for improvements, fixes and security patches. Emergency security patches are expedited.

Critical and high severity findings are remediated within 30 days, medium within 90 days and low within 180 days. Emergency security patches are applied within 7 days.

We conduct annual infrastructure security assessments and OWASP-methodology security testing. Independent third-party penetration testing is available where a client's procurement process requires it.

Yes. All changes to protected branches require pull request review and approval, secure coding standards are applied including the OWASP Top 10, and no change reaches production without staging validation.

Gatheroo uses hourly database and instance snapshots with seven-day retention in a second Australian region. Client websites are backed up daily with 60-day retention at the host plus a daily offsite copy retained 90 days. Backup completion is verified monthly, schedules confirmed quarterly, and a full restoration test is performed annually.

We follow a documented incident response and business continuity plan, supported by automated alerting from our cloud and hosting providers. Target recovery times are one hour for Gatheroo, one hour for email and two hours for client websites.

Yes. Automated alerting from our cloud and hosting providers is reviewed monthly with immediate escalation of alerts. Managed websites receive daily vulnerability and malware alerts.

Yes, on care plans. Plugin and theme vulnerabilities are monitored with daily alerts, malware scanning runs daily, and updates are tested in staging before being applied to your live site.

We follow our documented incident response process: contain, investigate, restore from backup, and complete a root cause analysis. You are notified in line with our breach notification commitments.

We follow our documented business continuity plan, monitor provider status, and notify affected clients promptly.

Yes. Gatheroo supports Zapier and other workflow tools, and custom integrations are available on request.

Security and Access

ISO 27001 is the international standard for information security management systems. Certification means an accredited third party has audited our security practices against the standard and continues to audit us annually.

Yes. Two-factor authentication is available to all Gatheroo users via email or SMS, and MFA is enforced across our internal systems and all production access.

SSO is not currently available.

Access is granted on a least-privilege basis, reviewed annually and on every role change, and revoked within 24 hours of a person leaving.

All remote access to production systems requires a dedicated VPN with multi-factor authentication, on devices with full-disk encryption and endpoint protection.

Only named personnel who need it for your work. Access is granted on a least-privilege basis, reviewed regularly, and removed within 24 hours when no longer required.

Yes. Personnel with privileged access undergo reference checks and employment history verification before access is granted, sign confidentiality agreements, and complete annual security awareness training.

All policies are reviewed at least annually, and whenever there is a significant change to our systems or regulatory obligations.

Reports are acknowledged within 4 business hours and technical containment is targeted within 8 business hours. We follow a documented plan covering detection, investigation, containment, recovery and post-incident review.

Yes. Suspected breaches are assessed against the Notifiable Data Breaches scheme. Where a breach is confirmed as eligible we notify the OAIC and affected individuals as soon as practicable, and clients within 24 to 72 hours in line with contractual terms.

Yes. We provide at least 30 days' notice before adding or replacing any sub-processor that processes client data.