MIBO TRUST CENTRE
Security you can see
Mibo is ISO 27001:2022 certified. Our platform is built on Microsoft Azure Australia with enterprise-grade encryption, access controls, and continuous compliance monitoring.
ISO 27001:2022
Certified
Azure Australia
Data Sovereignty
AES-256
Encryption
MFA Enforced
All Users
Min Group 8
Aggregation
01 – Compliance Frameworks
Trusted by design
Our compliance program is built into operational workflows – not bolted on. Evidence is generated automatically as a byproduct of daily operations.
ISO 27001:2022
Certified
SOC 2 Type II
In Progress
GDPR
Readiness
Privacy Act 1988
Complete
Detailed Status
SOC 2 Observation
Started Feb 2026
GDPR Gap Closure
78% Complete
Target Audit Date
Q4 2026
Next ISO Surveillance
August 2026
02 – Security Controls
Defence in depth
Our security controls span 10 domains aligned to ISO 27001 Annex A and SOC 2 Trust Services Criteria.
Access Security
Role-based access control (RBAC)
Multi-factor authentication (MFA)
Session management and timeout
Principle of least privilege
Access review processes
Encryption
AES-256 encryption at rest
TLS 1.2+ in transit
Key management via Azure Key Vault
Database encryption (TDE)
Network Security
Web Application Firewall (WAF)
DDoS protection (Cloudflare)
Network segmentation
Intrusion detection
Vulnerability Management
Annual penetration testing
Dependency scanning
Patch management process
Vulnerability remediation SLAs
Incident Response
Documented incident response plan
24-hour client notification SLA
72-hour GDPR supervisory authority notification
Post-incident review process
Change Management
Formal change approval process
Impact assessment requirements
Rollback procedures
Release documentation
Business Continuity
Disaster recovery plan
Quarterly DR testing
RTO/RPO defined
Geographic redundancy
Monitoring & Logging
Centralised log management
Security event monitoring
Audit trail retention
Alerting and escalation
Organisational Security
Security awareness training
Background checks
Acceptable use policies
Annual policy review
Vendor Management
Vendor security assessments
DPA requirements
Sub-processor monitoring
Annual vendor reviews
03 – Data Transparency
What we collect
Transparency about the data our platform processes, organised by user type. Mibo acts as a data processor โ our clients are the data controllers.
Portal Users
PERSONAL
Data fields:
First name ยท Last name ยท Email address
Purpose:
Platform authentication and administration
Lawful basis:
Contractual necessity (GDPR Art. 6(1)(b))
Survey Confidential Users
PERSONAL + SENSITIVE
Data fields:
Name ยท Email ยท Job role ยท Department ยท Tenure ยท Manager ยท Location ยท Survey responses (may include psychological and wellbeing data)
Purpose:
Psychosocial risk assessment and wellbeing monitoring
Lawful basis:
Consent + Explicit consent for Art. 9 data
Survey Anonymous Users
NON-PERSONAL
Data fields:
No identifying information collected ยท Aggregated responses only ยท Minimum group size of 8
Purpose:
Anonymous wellbeing assessment
Lawful basis:
Outside GDPR scope – no personal data
04 – Sub-processors
Our trusted partners
We maintain a minimal sub-processor footprint. All data processing occurs on Australian infrastructure by default.
Microsoft Azure
Cloud hosting, compute, storage, database services
DPA Active๐ Australia East (Sydney)
Cloudflare
CDN, DDoS protection, DNS, WAF
DPA Active๐ Global (nearest PoP)
Subprocessor Change Notifications
Receive 30-day advance notice when subprocessors are added, removed, or changed.
Data Sovereignty
The Mibo platform is hosted on Microsoft Azure Australia East (Sydney). All customer data – including survey responses, user records, and analytics – is stored and processed within Australian borders. No customer data is transferred internationally unless explicitly documented in the relevant DPA.
05 – Resources
Security documentation
Access our compliance documentation. Some resources are publicly available; others require NDA acceptance.
ISO 27001:2022 Certificate
Independently audited by Citation ISO Certification.
Data Security Overview
Summary of our security architecture, controls, and compliance posture.
Privacy Policy
How we collect, use, and protect personal information.
Data Processing Agreement
Standard DPA covering GDPR and Privacy Act requirements.
Information Security Policy
Our overarching information security management policy.
Acceptable Use Policy
Defines acceptable user conduct, prohibited activities, and account security responsibilities.
Detailed security documentation available on request. Our full ISMS policy suite, audit evidence, and architecture documentation.Gated documents
06 – FAQ
Common questions
Answers to the questions we hear most from security and procurement teams.
Hosting & Data Sovereignty
Where is our data hosted?
All data is hosted on Microsoft Azure Australia East (Sydney, NSW). Disaster recovery runs on Azure Australia Southeast (Melbourne, VIC). Data never leaves Australia โ no processing, storage, or transit outside the agreed region.
Is Mibo available as an on-premise deployment?
No. Mibo is exclusively a cloud-native SaaS platform on Microsoft Azure. This is a deliberate design decision โ centralised hosting enables consistent security controls, continuous patching, and real-time monitoring that are not possible in a distributed on-premise model.
Who are Mibo’s sub-processors?
Two: Microsoft Azure (cloud hosting, compute, database, storage โ Australia East) and Cloudflare (edge security, DDoS protection, CDN โ nearest global point of presence). Both operate under current Data Processing Agreements with Mibowork.
Compliance & Certifications
Is Mibo ISO 27001 certified?
Yes. Mibowork holds ISO 27001:2022 certification independently audited by Citation Certification (UKAS-accredited). Certificate No. 500-24206-IS. Valid 19 August 2025 to 18 August 2028. The certificate is available for download from the Resources tab.
What other compliance frameworks apply?
Privacy Act 1988 (including all 13 Australian Privacy Principles). GDPR readiness โ a Data Processing Agreement is available. SOC 2 Type II is in progress, with target audit completion Q4 2026.
Does Mibo serve Australian government or regulated-sector clients?
Yes. Mibowork serves clients across government-adjacent, healthcare, energy, and professional services sectors in Australia.
Data Security
How is data encrypted?
At rest: AES-256 via Azure SQL Transparent Data Encryption. In transit: TLS 1.2 minimum (TLS 1.3 preferred). Encryption keys are managed in Azure Key Vault with annual rotation.
Does Mibowork use client data for any other purpose?
No. Client data is never used for product improvement, AI/LLM training, marketing, research, or any purpose beyond delivering the contracted service. This is an absolute commitment.
Can Mibowork staff access our data?
Only in exceptional circumstances, with explicit documented permission and a recorded justification. All access is audit-logged. Routine platform operations do not require access to client data.
Identity & Access
What authentication and SSO options are available?
OIDC (primary), OAuth 2.0, and SAML 2.0 on request. SSO integrates with Azure Active Directory, Microsoft Entra ID, and compatible third-party identity providers. When SSO is configured, MFA is enforced by the client’s own identity provider.
How is access controlled within the platform?
Role-based access control (RBAC) via Azure AD groups. Platform roles follow least-privilege principles per POL-ISMS-003. Privileged operations require individually named accounts with Just-In-Time elevation and session monitoring.
Survey Anonymity
How does survey anonymity actually work?
Anonymous surveys collect no personal identifiers. Responses are aggregated at the organisational level with a minimum group size of 8 โ this mathematically prevents individual responses from being inferred. Administrators can only ever view aggregated results. No individual anonymous response is accessible to any user, including Mibowork.
Incidents & Continuity
What happens if there is a security incident?
We follow POL-ISMS-011 (Incident Response Plan). Clients are notified within 24 hours of a confirmed incident affecting their data. Where GDPR applies, supervisory authorities are notified within 72 hours. All incidents undergo post-incident review with findings shared with affected clients.
What are the platform recovery targets?
RTO โค4 hours. RPO โค15 minutes, supported by Azure SQL transaction log backups at 10โ15 minute intervals. DR is tested annually with quarterly restore drills.
Documents & AI
Is a Data Processing Agreement available?
Yes. Request it via the Resources tab or email security@mibowork.com.au. Our DPA covers GDPR requirements and Australian Privacy Act obligations including data subject rights, breach notification, and sub-processor management.
Does the Mibo platform use AI?
The platform includes a Factor Influence Prioritisation (FIP) model โ a statistical model that performs aggregate organisational analysis only. It never profiles or scores individual employees, and all outputs are reviewed by a qualified analyst before being included in client reports. Client data is never used to train any AI model.