Security & Sovereignty
Our approach to protecting your data and keeping it under Australian sovereignty.
Last updated: July 2026
Our Security Commitment
Security is engineered into everything we do. We apply layered, defense-grade controls across our people, processes, and technology to protect the confidentiality, integrity, and availability of the data entrusted to us.
Australian Data Sovereignty
We prioritise keeping data within Australian jurisdiction, aligned to local compliance and sovereignty requirements. Where trusted providers are involved, we take reasonable steps to preserve equivalent protection and transparency.
Essential Eight Alignment
Our practices are mapped to the ACSC Essential Eight mitigation strategies, with ongoing maturity uplift across application control, patching, configuration hardening, and backups.
Encryption
Data is protected in transit using modern TLS, and sensitive data at rest is encrypted. We manage keys carefully and rotate credentials on a regular basis.
Access Control & Monitoring
Access follows least-privilege principles with strong authentication. We continuously monitor for anomalies and respond rapidly to potential threats.
Vulnerability Management
We perform ongoing vulnerability scanning, prioritisation, and remediation, complemented by periodic security testing.
Incident Response
We maintain an incident response capability designed to detect, contain, and recover from security events quickly, with clear communication where required.
Reporting a Vulnerability
If you believe you have found a security issue affecting Bayswater, please contact us at info@bayswater.tech so we can investigate promptly. We appreciate responsible disclosure.
