Independently verified

Certified and accredited, with no carve-outs.

We hold the certifications enterprise risk and procurement teams expect, and we meet the requirements of each standard across the whole business, not just part of it.

ISO 27001: Independently Audited

ISO/IEC 27001

Our information security management system is independently certified to ISO 27001 across the whole business. One audited standard governs how we manage risk across our people, processes and technology, and how we keep improving.

Consumer Data Right: Accredited Data Recipient

Consumer Data Right (ACCC ADR)

TaleFin is an ACCC-accredited Data Recipient under the Consumer Data Right. We meet the CDR's privacy safeguards and information security controls for collecting, using and protecting consumer-consented data.

ASAE 3150: Independently Audited

ASAE 3150 assurance

An independent assurance engagement under ASAE 3150 provides third-party assurance over the design and operating effectiveness of our controls and governance, giving your team evidence, not just claims.

Privacy Act: Independently Audited

Privacy Act & CR Code

As a credit reporting participant under Part IIIA of the Privacy Act and the Credit Reporting Code, our handling of credit information is governed by strict rules and independently audited.

In our environment

How we protect your data.

Our ISO 27001-certified management system turns into concrete, day-to-day controls across the platform.

Encryption everywhere

Data is encrypted in transit and at rest using modern, industry-standard cryptography.

Least-privilege access

Role-based access with multi-factor authentication and SSO, granted on need and reviewed regularly.

Continuous monitoring

Activity is logged and monitored, with alerting on anomalous behaviour so issues are caught early.

Secure by design

Security is built into our development lifecycle, with code review, testing and change control before anything ships.

Vulnerability management

We run regular vulnerability assessments and independent testing, and patch on a risk-prioritised basis.

Resilience & recovery

Backups, redundancy and tested recovery procedures keep the platform available and your data safe.

Beyond compliance

Fair, by design.

Meeting the standards is the baseline. We also build fairness and transparency into the products themselves: no penalties for shopping around, nuanced variables rather than blunt proxies like postcodes, and scoring built on real financial behaviour.