VTARATECH
SECURITY & ASSURANCE
Trust requires more than an answer. It requires evidence that the system producing it can be trusted.
VCLARIFI is designed as decision infrastructure. Security, integrity, attribution and auditability therefore form part of the architecture of the platform rather than being treated solely as operational controls.
Security by design
VCLARIFI applies a risk-based approach to information security across the design, development and operation of the platform.
Our security approach is built around four objectives:
Confidentiality — information is accessible only to authorised users and systems.
Integrity — decision information and governance events are protected against unauthorised alteration.
Availability — systems and information are designed to remain available and recoverable.
Accountability — material activity can be attributable and auditable.
Data protection
VCLARIFI uses technical and organisational safeguards appropriate to the nature of the information being processed.
These may include:
encryption in transit and at rest;
controlled user authentication;
role and permission-based access;
tenant and data segregation;
secure credential and secrets management;
logging and monitoring;
backup and recovery controls;
vulnerability and patch management;
secure software development practices; and
incident detection and response procedures.
Specific security architecture is not publicly disclosed where doing so could increase security risk.
Access and authority
VCLARIFI is designed to distinguish between information, analysis, recommendation, authority and commitment.
Access to customer information is restricted according to role, system requirements and legitimate operational need.
Where VCLARIFI records an attributable governance event, the platform is designed to preserve relevant information concerning the event, including its relationship to the applicable evidence, conditions and authority.
Tenant isolation
Customer environments and information are logically separated using controls designed to prevent unauthorised access between tenants.
Access to production information by VCLARIFI personnel is restricted and should occur only where required for authorised operational, support, security or legal purposes.
Decision integrity
Security in VCLARIFI extends beyond protecting stored information.
VCLARIFI is designed to preserve the integrity of the decision governance process by maintaining relationships between relevant:
assumptions;
evidence;
dependencies;
conditions;
authority;
commitment; and
subsequent change.
This creates a traceable record of what was committed, based on what information and under what conditions.
AI and third-party providers
Where third-party infrastructure, AI or technology providers support VCLARIFI services, we assess providers according to relevant security, privacy, contractual and operational requirements.
Customer information provided to third-party services is limited to what is reasonably necessary for the applicable service.
Private customer Decision Case content is not used by VCLARIFI to train publicly available or general-purpose AI models unless expressly agreed with the customer.
Security framework
VCLARIFI's security program is informed by recognised cybersecurity practices and applicable Australian regulatory requirements.
Where appropriate to the environment and risk profile, controls may be informed by guidance including the Australian Signals Directorate's cybersecurity guidance.
VCLARIFI will only claim compliance with, alignment to or certification against a particular security standard where that claim can be substantiated.
Incident management
VCLARIFI maintains processes for identifying, assessing, containing, investigating and responding to security incidents.
Where an incident involves personal information and meets applicable notification thresholds, VCLARIFI will make notifications in accordance with the Notifiable Data Breaches scheme and other applicable legal requirements.
Data lifecycle
Information security controls apply throughout the information lifecycle, including collection, transmission, processing, storage, access, retention and deletion.
Customer information is retained only for legitimate service, governance, contractual or legal purposes and is deleted, destroyed or de-identified when no longer required, subject to applicable retention obligations and backup processes.
Business continuity
VCLARIFI applies resilience, backup and recovery practices designed to reduce the impact of operational disruption and support restoration of critical services.
Responsible disclosure
If you believe you have identified a security vulnerability affecting VCLARIFI, please report it responsibly to:
security@vclarifi.com
Please do not publicly disclose a suspected vulnerability before VCLARIFI has had a reasonable opportunity to investigate and address it.
We will assess legitimate security reports and respond according to their severity and potential impact.
Enterprise assurance
Enterprise customers may request additional information regarding VCLARIFI's security, privacy and assurance controls, subject to appropriate confidentiality arrangements.
Contact security@vclarifi.com for further information.