MIBO TRUST CENTER

Security you can see

๐Ÿ›ก๏ธ

ISO 27001:2022

Certified

โ˜๏ธ

Azure Australia

Data Sovereignty

๐Ÿ”

AES-256

Encryption

๐Ÿ‘ฅ

MFA Enforced

All Users

๐Ÿ“Š

Min Group 8

Aggregation


01 – Compliance Frameworks

Trusted by design

๐Ÿ…

ISO 27001:2022

Certified

๐Ÿ“‹

SOC 2 Type II

In Progress

๐Ÿ‡ช๐Ÿ‡บ

GDPR

Readiness

๐Ÿ‡ฆ๐Ÿ‡บ

Privacy Act 1988

Complete

02 – Security Controls

Defence in depth

Access Security
Encryption
Network Security
Vulnerability Management
Incident Response
Change Management
Business Continuity
Monitoring & Logging
Organisational Security
Vendor Management

03 – Data Transparency

What we collect

04 – Sub-processors

Our trusted partners

05 – Resources

Security documentation

ISO 27001:2022 Certificate

Independently audited by Citation ISO Certification.

Data Security Overview

Summary of our security architecture, controls, and compliance posture.

Privacy Policy

How we collect, use, and protect personal information.

Data Processing Agreement

Standard DPA covering GDPR and Privacy Act requirements.

Information Security Policy

Our overarching information security management policy.

Acceptable Use Policy

Defines acceptable user conduct, prohibited activities, and account security responsibilities.

Detailed security documentation available on request. Our full ISMS policy suite, audit evidence, and architecture documentation.

12 ISMS policies 3 audit reports Architecture diagram

06 – FAQ

Common questions

Hosting & Data Sovereignty

Where is our data hosted?

All data is hosted on Microsoft Azure Australia East (Sydney, NSW). Disaster recovery runs on Azure Australia Southeast (Melbourne, VIC). Data never leaves Australia โ€” no processing, storage, or transit outside the agreed region.

Is Mibo available as an on-premise deployment?

No. Mibo is exclusively a cloud-native SaaS platform on Microsoft Azure. This is a deliberate design decision โ€” centralised hosting enables consistent security controls, continuous patching, and real-time monitoring that are not possible in a distributed on-premise model.

Who are Mibo’s sub-processors?

Two: Microsoft Azure (cloud hosting, compute, database, storage โ€” Australia East) and Cloudflare (edge security, DDoS protection, CDN โ€” nearest global point of presence). Both operate under current Data Processing Agreements with Mibowork.

Compliance & Certifications

Is Mibo ISO 27001 certified?

Yes. Mibowork holds ISO 27001:2022 certification independently audited by Citation Certification (UKAS-accredited). Certificate No. 500-24206-IS. Valid 19 August 2025 to 18 August 2028. The certificate is available for download from the Resources tab.

What other compliance frameworks apply?

Privacy Act 1988 (including all 13 Australian Privacy Principles). GDPR readiness โ€” a Data Processing Agreement is available. SOC 2 Type II is in progress, with target audit completion Q4 2026.

Does Mibo serve Australian government or regulated-sector clients?

Yes. Mibowork serves clients across government-adjacent, healthcare, energy, and professional services sectors in Australia.

Data Security

How is data encrypted?

At rest: AES-256 via Azure SQL Transparent Data Encryption. In transit: TLS 1.2 minimum (TLS 1.3 preferred). Encryption keys are managed in Azure Key Vault with annual rotation.

Does Mibowork use client data for any other purpose?

No. Client data is never used for product improvement, AI/LLM training, marketing, research, or any purpose beyond delivering the contracted service. This is an absolute commitment.

Can Mibowork staff access our data?

Only in exceptional circumstances, with explicit documented permission and a recorded justification. All access is audit-logged. Routine platform operations do not require access to client data.

Identity & Access

What authentication and SSO options are available?

OIDC (primary), OAuth 2.0, and SAML 2.0 on request. SSO integrates with Azure Active Directory, Microsoft Entra ID, and compatible third-party identity providers. When SSO is configured, MFA is enforced by the client’s own identity provider.

How is access controlled within the platform?

Role-based access control (RBAC) via Azure AD groups. Platform roles follow least-privilege principles per POL-ISMS-003. Privileged operations require individually named accounts with Just-In-Time elevation and session monitoring.

Survey Anonymity

How does survey anonymity actually work?

Anonymous surveys collect no personal identifiers. Responses are aggregated at the organisational level with a minimum group size of 8 โ€” this mathematically prevents individual responses from being inferred. Administrators can only ever view aggregated results. No individual anonymous response is accessible to any user, including Mibowork.

Incidents & Continuity

What happens if there is a security incident?

We follow POL-ISMS-011 (Incident Response Plan). Clients are notified within 24 hours of a confirmed incident affecting their data. Where GDPR applies, supervisory authorities are notified within 72 hours. All incidents undergo post-incident review with findings shared with affected clients.

What are the platform recovery targets?

RTO โ‰ค4 hours. RPO โ‰ค15 minutes, supported by Azure SQL transaction log backups at 10โ€“15 minute intervals. DR is tested annually with quarterly restore drills.

Documents & AI

Is a Data Processing Agreement available?

Yes. Request it via the Resources tab or email security@mibowork.com.au. Our DPA covers GDPR requirements and Australian Privacy Act obligations including data subject rights, breach notification, and sub-processor management.

Does the Mibo platform use AI?

The platform includes a Factor Influence Prioritisation (FIP) model โ€” a statistical model that performs aggregate organisational analysis only. It never profiles or scores individual employees, and all outputs are reviewed by a qualified analyst before being included in client reports. Client data is never used to train any AI model.

Scroll to Top