Skip to main content

Security & Compliance

AES-256 encryption at rest, TLS 1.3 in transit, and access controls built for Australian accounting practices.

How We Protect Your Data

We use AES-256 encryption at rest and TLS 1.3 in transit, Australian data centres for storage, and role-based access controls with multi-factor authentication.

Where we use third-party AI providers to process your data, that processing may occur outside Australia. See AI Processing of Your Data in our Privacy Policy.

Security Features

Multi-Factor Authentication (MFA)

TOTP-based two-factor authentication (2FA) with time-based one-time passwords. Users can enable MFA using authenticator apps, with recovery codes provided for account recovery. Enhanced security for all user accounts protects against unauthorized access even if passwords are compromised.

Single Sign-On (SSO)

Microsoft Azure AD integration for seamless and secure authentication. Enterprise-grade SSO support allows practices to manage user access through their existing Microsoft identity provider. Supports conditional access policies and centralized user management.

ISO 27001-Aligned (not certified)

Our security practices are aligned with the ISO 27001 information security management standard, including risk assessment, access control, cryptography, and incident management. Fedix is not ISO 27001 certified.

Encryption at Rest & In Transit

AES-256 encryption at rest and TLS 1.3 in transit. Your data is protected throughout its lifecycle with industry-standard encryption protocols, and all network communications are secured in transit.

Data Isolation

Practice-level data isolation separates each practice's data, with access controls enforced at both the application and database layer. Practices can only access their own client data.

Multi-Layer Server Architecture

Layered security architecture with multiple tiers provides defense in depth against threats. Different system layers are separated with strict network controls and access restrictions. Firewalls, intrusion detection, and continuous monitoring systems protect each layer of the infrastructure.

Australian Data Centres

Your data is stored at rest in Australian data centres. Where we use third-party AI providers to process your data, that processing may occur outside Australia - see 'AI Processing of Your Data' in our Privacy Policy. Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it in accordance with the Australian Privacy Principles, including through contractual data-protection obligations.

Role-Based Access Control

Granular permissions and role-based access controls ensure that only authorized users in your practice can access client data. You control who sees what. Custom roles can be defined with specific permissions for different functions, ensuring least-privilege access principles.

Comprehensive Audit Logs

Comprehensive audit logging tracks all access and changes to client data. Full audit trail for compliance and security monitoring. All user actions, data access, and system changes are logged with timestamps, user identification, and IP addresses for complete traceability.

Compliance & Standards

  • Personal information handled in accordance with the Privacy Act 1988 and the Australian Privacy Principles
  • Built to support registered tax agents and their practice workflows
  • ISO 27001-aligned security practices (aligned - not certified)
  • Data backup and disaster recovery procedures
  • Multi-factor authentication (MFA) support
  • Single Sign-On (SSO) with Microsoft Azure AD
  • AES-256 encryption at rest, TLS 1.3 in transit
  • Practice-level data isolation
  • Multi-layer server architecture
  • Australian data centre storage at rest

Data Protection

Backup & Recovery

Automated backups run on a regular schedule, with documented disaster-recovery procedures to support business continuity in the event of a system failure.

Access Control

Only authorized users in your practice can access client data. Fedix staff never access your client data without explicit permission for support purposes, and all access is logged.

Privacy

We handle personal information in accordance with the Privacy Act 1988 and the Australian Privacy Principles. Your client data belongs to you. We use third-party providers, including AI providers, to deliver parts of the service - what we disclose, to whom, and where it is processed is set out in our Privacy Policy.

Questions about security?

Our team is happy to discuss our security practices and answer any questions you may have.