Security at Kicking Pixels, Gatheroo & MWA
The Kicking Pixels builds and operates digital products for organisations that can’t afford to get security wrong, including clients in healthcare and government. This page sets out how we protect information: the controls we operate, who our sub-processors are, where data is stored, and how we handle incidents and privacy requests.
Our information security management system is certified to ISO/IEC 27001:2022. One certified management system covers all our brands, so the same governance, access control, incident response and supplier management applies whether you’re using Gatheroo, on a MyWebAdvantage care plan, or running an enterprise build with Kicking Pixels.
This Trust Centre covers Kicking Pixels, MyWebAdvantage and Gatheroo.
Controls
Subprocessors
Amazon Web Services
Bitbucket
WPEngine
FAQs
Access is granted on a least-privilege basis, reviewed annually and on every role change, and revoked within 24 hours of a person leaving.
We deploy updates regularly for improvements, fixes and security patches. Emergency security patches are expedited.
ISO 27001 is the international standard for information security management systems. Certification means an accredited third party has audited our security practices against the standard and continues to audit us annually.
Yes. Two-factor authentication is available to all Gatheroo users via email or SMS, and MFA is enforced across our internal systems and all production access.
Governance & Certification
One independently certified management system covering all brands and services.
Certificate number 1357-I-1, issued by Global Compliance Certification Pty Ltd under JAS-ANZ accreditation. Held by Kicking Pixels Pty Ltd, ABN 13 136 066 496, trading as MyWebAdvantage and Gatheroo. Scope: information security management system for the provision of SaaS products, website planning, design and development. Issued 26 March 2025, valid to 25 March 2028, maintained through annual surveillance audits. Next surveillance audit Q1 2027.
A copy of the certificate, extracts from our Statement of Applicability, and completed security questionnaires are available on request.
Fifteen information security policies cover governance, access, assets, physical security, third parties, people, data protection, cryptography, development and incident response. Each is reviewed at least annually.
The ISMS is audited annually by our accredited certification body.
A three-year audit schedule covers every applicable clause and control, with findings reported to management.
Security performance is reviewed quarterly against documented annual information security objectives.
A documented risk assessment and treatment process is maintained, with a risk register reviewed annually and on significant change.
Australian privacy law and ACSC guidance are reviewed quarterly, with a full legal and regulatory compliance assessment annually.
Access & Identity
Access is granted on a least-privilege basis, with management approval required for elevated access.
Microsoft 365 is our primary identity provider, with account lifecycle managed by the Administrative Lead.
Enforced across internal business systems and all production access.
Access is reviewed annually and on every role change, and revoked within 24 hours of a person leaving.
Administrative access is restricted to named personnel with MFA enforced and credentials held in a managed secrets vault.
All remote access to production systems requires a dedicated VPN with multi-factor authentication.
Data Protection & Privacy
All information is treated as confidential by default. External sharing requires management approval.
Client and business data is stored only in approved platforms. Personal cloud storage and removable media are prohibited.
Gatheroo customer data is stored exclusively in Australia. Client websites are hosted in Australia, with encrypted offsite backups held in the United States. A small number of our personnel located outside Australia access production systems remotely via dedicated VPN with multi-factor authentication and full activity logging.
TLS 1.2 or higher for all data transmitted externally.
Production databases, file storage and backups are encrypted, and full-disk encryption is mandatory on all devices.
Payment card details display the last four digits only. Passwords are never displayed.
Personal information is handled in accordance with the Privacy Act 1988 and the Notifiable Data Breaches scheme, with GDPR obligations met where EU data subjects are involved.
All payment processing is outsourced to Stripe, a PCI DSS Level 1 provider.
Access requests answered within 30 days, corrections within 14 days, deletions assessed within 14 days and actioned within 30.
Product & Application Security
Changes flow through separated environments with security checks at each stage. No code reaches production without staging validation.
Changes to protected branches require pull request review and approval. Direct pushes are blocked and full history is retained as an audit trail.
Input validation, server-side authorisation, no secrets in code, generic error messages, and OWASP Top 10 applied throughout.
Real client data is never used in development, staging or pre-flight environments.
Critical and high severity findings are remediated within 30 days, medium within 90, low within 180. Emergency security patches are expedited within 7 days.
OWASP-methodology testing and staging validation before every release, plus an annual infrastructure security assessment. Independent penetration testing is available where a client’s procurement process requires it.
No client data, personal data or source code is entered into AI tools. AI-assisted development is restricted, operates with privacy mode enforced, and all output is reviewed before reaching production.
Infrastructure & Operations
We operate on AWS, Microsoft 365 and managed WordPress hosting under shared responsibility models. All hold ISO 27001 or equivalent certification.
Development, staging and production environments are maintained separately across all platforms.
Company devices use full-disk encryption, endpoint protection, automatic screen lock and current security patches.
A dedicated business network operates separately from building infrastructure, with guest traffic isolated.
Cloud audit logs and system access logs are retained for a minimum of 12 months.
Automated alerting from cloud and hosting providers, reviewed monthly, with immediate escalation of alerts.
USB and external media are prohibited on all company devices.
Software installation is restricted to a maintained approved software list.
Resilience & Incident Response
Every production system is backed up on a documented schedule with defined retention, verified monthly and quarterly, with a full restoration test performed annually.
Target recovery times of one hour for Gatheroo, one hour for email, and two hours for client websites.
A documented plan with severity classification and defined phases covering detection, investigation, containment, recovery and review.
Incident reports are acknowledged within 4 business hours and technical containment is targeted within 8 business hours.
Suspected breaches are contained immediately and assessed against the Notifiable Data Breaches scheme. Where a breach is confirmed as eligible, we notify the OAIC and affected individuals as soon as practicable. Clients are notified within 24 to 72 hours in line with contractual terms. Where EU data subjects are involved, the relevant supervisory authority is notified within 72 hours.
Root cause analysis is completed after every incident, with lessons applied to policy and procedure.
People & Personnel Security
Personnel with privileged access undergo reference checks and employment history verification before access is granted.
Signed before any system access is granted.
Completed annually by all personnel, with additional annual secure coding training for developers.
A security briefing is required before access is granted. All access is revoked within 24 hours of a person leaving.
Documented home office security requirements apply, with VPN mandatory for production access and on public Wi-Fi.
Our office is located in a professionally secured building with controlled access, monitoring, a visitor log and key register, operated under clear desk and clear screen practices.
Supplier & Sub-processor Management
A security assessment is completed before engaging any vendor that will handle business or client data.
All active vendors are reviewed annually with certifications reconciled, plus a quarterly check for unrecorded changes.
Data processing agreements or equivalent contractual terms are in place for vendors processing personal data.
We publish our sub-processors and provide at least 30 days’ notice before adding or replacing any sub-processor that processes client data.
Gatheroo
All customer data is stored in AWS Australian regions, Sydney primary with Melbourne for backup.
Available to all users via email or SMS.
Your clients complete requests through a secure link, so there are no extra credentials to manage.
Sensitive text fields such as tax file numbers carry additional AES-128-GCM encryption.
Deleting a file removes it from active storage immediately, clears encrypted backups within seven days, and is recorded permanently in the activity log.
Data is retained for the life of the subscription and deleted 60 days after cancellation. Inactive trial accounts are deleted automatically after 60 days.
Hourly database and instance snapshots with seven-day retention, plus continuous file versioning, held in a second Australian region.
Every request, submission, view, download and deletion is timestamped and logged.
Changes flow through local, staging, pre-flight and production environments.
Websites — Kicking Pixels & MyWebAdvantage
Client websites are hosted on managed WordPress infrastructure in Australia with server-level security monitoring and automatic threat protection.
Full site backups daily with 60-day retention at the host, plus a daily offsite copy retained 90 days.
Plugin and theme vulnerabilities are monitored with daily alerts, and updates are tested in staging before being applied to production.
Daily malware scanning and detection across managed sites, with WordFence deployed on security-sensitive websites.
Certificates are tracked in an expiry register and renewed before expiration.
Security headers, HTTPS configuration, permissions and access controls are verified before every site goes live.
Client projects include a security hardening assessment as part of delivery.
Target recovery time of two hours for client websites.
Standalone security evaluation services are available for existing client websites.
Amazon Web Services
Bitbucket
WPEngine
Office365
Stripe
ManageWP
Growth360 (GoHighLevel)
Client Control and Support
Email security@kickingpixels.com.au. Reports are acknowledged within 4 business hours.
Yes. We support procurement and compliance teams with documentation, questionnaire responses and calls.
Yes. Submit requests through support or your account contact.
Yes. We provide onboarding sessions, documentation and ongoing support tailored to your team.
In Gatheroo you control every field, template and permission, so you request only what you need.
You do. Unless you are on a rental subscription, you retain full ownership of your content, design assets and domain.
Compliance and Legal
Yes. Certificate 1357-I-1, issued by Global Compliance Certification under JAS-ANZ accreditation, valid to 25 March 2028 and maintained through annual surveillance audits.
Yes, available on request and included in procurement documentation where required.
Kicking Pixels, MyWebAdvantage and Gatheroo, all under one management system. Growth360 is a resold third-party platform and sits outside our ISMS scope.
Relevant extracts can be shared under NDA for security assessments and vendor due diligence.
Yes. We handle personal information in accordance with the Privacy Act 1988 and the Notifiable Data Breaches scheme.
Our primary market is Australia. Where EU data subjects are involved we meet GDPR obligations, including notifying the relevant supervisory authority within 72 hours of becoming aware of a breach.
Yes. We can provide a signed DPA on request or as part of vendor onboarding.
We respond only to lawful requests supported by appropriate documentation, and notify affected customers where legally permitted.
No. All payment processing is outsourced to Stripe, a PCI DSS Level 1 provider.
Data Protection and Privacy
Gatheroo customer data is stored only in Australia, in AWS Australian regions. Client websites are hosted in Australia, with encrypted offsite backups held in the United States. Payment processing and CRM are provided by US-based providers. Our full sub-processor list, including data locations, is published above.
Yes. All data is encrypted in transit using TLS 1.2 or higher and encrypted at rest. In Gatheroo, sensitive text fields such as tax file numbers carry additional AES-128-GCM field-level encryption.
Yes. A small number of our own personnel located outside Australia access production systems remotely through a dedicated VPN with multi-factor authentication and full activity logging. They are screened before access is granted and subject to the same policies as our Australian team. No Gatheroo customer data is stored outside Australia.
We access client documents only when necessary for support, and only with your written permission. You retain ownership of your data at all times.
Gatheroo data is retained for the life of your subscription and deleted 60 days after cancellation. Inactive trial accounts are deleted automatically after 60 days. Website backups are retained 60 to 90 days depending on the provider. Security logs are retained for a minimum of 12 months. Financial records are retained for 7 years as required by law.
Yes. You can export your Gatheroo request data at any time, and deletion requests are supported and processed securely.
Gatheroo data is securely deleted 60 days after cancellation. You can request immediate deletion if you prefer.
Deleting a file removes it from active storage immediately. It clears our encrypted backups within seven days, and the deletion is recorded permanently in the activity log.
No. Client data, personal data and source code are never entered into AI tools, and none of your data is used for model training.
No. Development, staging and pre-flight environments use synthetic or anonymised data only.
Email privacy@kickingpixels.com.au. Access requests are answered within 30 days, corrections within 14 days, and deletion requests are assessed within 14 days and actioned within 30.
Platform Operations
We deploy updates regularly for improvements, fixes and security patches. Emergency security patches are expedited.
Critical and high severity findings are remediated within 30 days, medium within 90 days and low within 180 days. Emergency security patches are applied within 7 days.
We conduct annual infrastructure security assessments and OWASP-methodology security testing. Independent third-party penetration testing is available where a client's procurement process requires it.
Yes. All changes to protected branches require pull request review and approval, secure coding standards are applied including the OWASP Top 10, and no change reaches production without staging validation.
Gatheroo uses hourly database and instance snapshots with seven-day retention in a second Australian region. Client websites are backed up daily with 60-day retention at the host plus a daily offsite copy retained 90 days. Backup completion is verified monthly, schedules confirmed quarterly, and a full restoration test is performed annually.
We follow a documented incident response and business continuity plan, supported by automated alerting from our cloud and hosting providers. Target recovery times are one hour for Gatheroo, one hour for email and two hours for client websites.
Yes. Automated alerting from our cloud and hosting providers is reviewed monthly with immediate escalation of alerts. Managed websites receive daily vulnerability and malware alerts.
Yes, on care plans. Plugin and theme vulnerabilities are monitored with daily alerts, malware scanning runs daily, and updates are tested in staging before being applied to your live site.
We follow our documented incident response process: contain, investigate, restore from backup, and complete a root cause analysis. You are notified in line with our breach notification commitments.
We follow our documented business continuity plan, monitor provider status, and notify affected clients promptly.
Yes. Gatheroo supports Zapier and other workflow tools, and custom integrations are available on request.
Security and Access
ISO 27001 is the international standard for information security management systems. Certification means an accredited third party has audited our security practices against the standard and continues to audit us annually.
Yes. Two-factor authentication is available to all Gatheroo users via email or SMS, and MFA is enforced across our internal systems and all production access.
SSO is not currently available.
Access is granted on a least-privilege basis, reviewed annually and on every role change, and revoked within 24 hours of a person leaving.
All remote access to production systems requires a dedicated VPN with multi-factor authentication, on devices with full-disk encryption and endpoint protection.
Only named personnel who need it for your work. Access is granted on a least-privilege basis, reviewed regularly, and removed within 24 hours when no longer required.
Yes. Personnel with privileged access undergo reference checks and employment history verification before access is granted, sign confidentiality agreements, and complete annual security awareness training.
All policies are reviewed at least annually, and whenever there is a significant change to our systems or regulatory obligations.
Reports are acknowledged within 4 business hours and technical containment is targeted within 8 business hours. We follow a documented plan covering detection, investigation, containment, recovery and post-incident review.
Yes. Suspected breaches are assessed against the Notifiable Data Breaches scheme. Where a breach is confirmed as eligible we notify the OAIC and affected individuals as soon as practicable, and clients within 24 to 72 hours in line with contractual terms.
Yes. We provide at least 30 days' notice before adding or replacing any sub-processor that processes client data.