Information security, built in.
Compliance isn't a checkbox for us, it's the foundation. TaleFin holds whole-of-business certifications and accreditations, backed by independent audits, and engineers protection into everything we build. We collect only what's needed, with the customer's consent, and protect it at every step.
Certified and accredited, with no carve-outs.
We hold the certifications enterprise risk and procurement teams expect, and we meet the requirements of each standard across the whole business, not just part of it.
ISO/IEC 27001
Our information security management system is independently certified to ISO 27001 across the whole business. One audited standard governs how we manage risk across our people, processes and technology, and how we keep improving.
Consumer Data Right (ACCC ADR)
TaleFin is an ACCC-accredited Data Recipient under the Consumer Data Right. We meet the CDR's privacy safeguards and information security controls for collecting, using and protecting consumer-consented data.
ASAE 3150 assurance
An independent assurance engagement under ASAE 3150 provides third-party assurance over the design and operating effectiveness of our controls and governance, giving your team evidence, not just claims.
Privacy Act & CR Code
As a credit reporting participant under Part IIIA of the Privacy Act and the Credit Reporting Code, our handling of credit information is governed by strict rules and independently audited.
How we protect your data.
Our ISO 27001-certified management system turns into concrete, day-to-day controls across the platform.
Encryption everywhere
Data is encrypted in transit and at rest using modern, industry-standard cryptography.
Least-privilege access
Role-based access with multi-factor authentication and SSO, granted on need and reviewed regularly.
Continuous monitoring
Activity is logged and monitored, with alerting on anomalous behaviour so issues are caught early.
Secure by design
Security is built into our development lifecycle, with code review, testing and change control before anything ships.
Vulnerability management
We run regular vulnerability assessments and independent testing, and patch on a risk-prioritised basis.
Resilience & recovery
Backups, redundancy and tested recovery procedures keep the platform available and your data safe.
Fair, by design.
Meeting the standards is the baseline. We also build fairness and transparency into the products themselves: no penalties for shopping around, nuanced variables rather than blunt proxies like postcodes, and scoring built on real financial behaviour.