Trust and Security

Trust & Security at DigiU

Last Updated: 9 June 2026  |  DigiU Pty Ltd  |  ABN 43 671 018 107

Security, privacy, and responsible AI governance are embedded into our technology, operations, and culture — not treated as afterthoughts.

Our Commitment

At DigiU, trust is foundational to everything we build. Our clients rely on us to manage critical business processes, sensitive data, automation workflows, and regulatory obligations. We take that responsibility seriously.

  • Protecting customer data with enterprise-grade security controls
  • Maintaining strict privacy and confidentiality standards
  • Designing automation systems with transparency and accountability
  • Aligning with regulatory and industry best practices
  • Continuously improving our security and AI governance posture

Security and trust are core design principles across all DigiU platforms not features we add later.

Data Security

Secure Architecture

  • Segregated environments — development, staging, and production are fully isolated
  • Role-based access control (RBAC) throughout all systems
  • Least-privilege access — personnel access only what is needed for their role
  • Multi-factor authentication (MFA) required for all administrative access
  • Secure API integrations with rate limiting and authentication
  • Encrypted data transmission using TLS 1.2 or higher on all connections

Data Encryption

  • In Transit — All data transmitted between clients, servers, and integrations is encrypted using HTTPS with TLS 1.2+.
  • At Rest — Data stored on our platforms is encrypted at rest using industry-standard methods with secure key management.
  • Key Management — Encryption keys are managed using secure, access-controlled systems with regular rotation policies.
  • Data Segregation — Client data is logically segregated to prevent cross-contamination between organisations.

Infrastructure Security

Our hosting and infrastructure providers meet high industry security standards and provide:

  • Continuous monitoring
  • Network segmentation
  • Firewall protection
  • Intrusion detection and prevention mechanisms
  • Physical data centre security controls
Infrastructure Security
  • Continuous 24/7 infrastructure monitoring
  • Network segmentation to limit attack surface
  • Web application firewalls (WAF) and DDoS protection
  • Intrusion detection and prevention systems (IDS/IPS)
  • Physical data centre security controls including biometric access and CCTV
  • Redundant network connectivity and power
  • Regular penetration testing and vulnerability assessments

DigiU’s infrastructure partners are selected based on their security certifications, compliance posture, and track record. We review our infrastructure security posture on an ongoing basis.

Privacy and Confidentiality
  • Collecting only data necessary to deliver contracted services (data minimisation)
  • Processing data in accordance with the Privacy Act 1988 (Cth) and Australian Privacy Principles
  • Maintaining strict internal access controls and need-to-know principles
  • Requiring confidentiality obligations for all employees, contractors, and subprocessors
  • Never selling or sharing customer data outside the scope of agreed services

Customer data is never sold or shared with third parties for marketing, advertising, or any purpose outside the contracted services.

AI Governance and Responsible AI

DigiU’s AI-powered platforms are designed with strong governance, transparency, and human oversight at their core. We recognise that AI systems must be secure, explainable, compliant, and ethically deployed.

Human-in-the-Loop Oversight

  • Human review checkpoints for high-risk or regulated decisions
  • Configurable approval workflows for sensitive automated actions
  • Escalation pathways to live agents or supervisors at any point
  • Full audit trails of all automated decisions and actions
  • Override and intervention capabilities available at all times

Data Usage and AI Model Integrity

  • Customer data is never used to train public or external AI models
  • AI models operate within controlled, customer-specific environments
  • Data access is restricted to authorised systems and personnel only
  • Inputs and outputs are logged for audit and compliance purposes
  • Strict data segregation between customers is enforced at all times

Explainability and Transparency

  • Automated interactions are clearly identified where appropriate
  • Configurable response frameworks allow organisations to set boundaries
  • Full traceability of AI-driven outputs is maintained
  • Reporting and audit requirements are supported

Bias Mitigation and Responsible Deployment

  • Controlled configuration of AI behaviours and response parameters
  • Pre-deployment testing and validation of all AI components
  • Ongoing monitoring of AI performance and output quality
  • Structured feedback loops for continuous improvement
  • Governance review required before major automation changes

AI solutions are deployed in alignment with business, regulatory, and ethical considerations. Customers remain in control of all business-critical decisions.

Secure Development Lifecycle
  • Secure coding standards and guidelines enforced across all development teams
  • Mandatory peer code reviews for all changes to production systems
  • Version control and change tracking for all code and configuration
  • Controlled deployment processes with staged rollouts
  • Testing across fully segregated environments (dev, staging, production)
  • Ongoing vulnerability assessment and dependency scanning
Access Controls
  • Role-based permissions aligned to job function and operational necessity
  • Multi-factor authentication (MFA) enforced for all system access
  • Periodic access reviews to ensure permissions remain appropriate
  • Immediate revocation of access upon role change, resignation, or termination
  • All access events are logged and available for audit purposes
  • Privileged access is separately controlled and subject to enhanced monitoring
Incident Response and Monitoring

Detection and Response

  • Continuous system monitoring to detect unusual activity, anomalies, and potential threats
  • Defined incident classification and escalation procedures
  • Rapid containment and isolation protocols for confirmed incidents
  • Root cause analysis and remediation for every significant event
  • Post-incident review and improvement processes

Client Notification

In the event of a data breach affecting client data, DigiU will notify affected clients promptly and in accordance with the Privacy Act 1988 (Cth) Notifiable Data Breaches scheme, including notification to the OAIC where required.

DigiU’s target notification timeframe for confirmed data breaches affecting client data is 72 hours from confirmation, in line with international best practice.

Compliance and Governance Framework
  • Documented information security policies and procedures
  • Formal change management controls and approval workflows
  • Periodic access management and privilege reviews
  • Risk assessments for new platforms, integrations, and significant changes
  • Incident response planning and regular drills
  • Secure software development lifecycle documentation
  • Automation and AI governance protocols

Our platforms are designed to support organisations’ compliance obligations under the National Energy Retail Law, Australian Privacy Act, Anti-Money Laundering regulations, and other applicable frameworks.

Business Continuity and Resilience
  • Redundant infrastructure components where operationally critical
  • Secure, tested backup and recovery processes
  • Disaster recovery planning with defined recovery time objectives (RTO)
  • Regular system monitoring, health checks, and performance testing
  • Capacity planning to support growth and peak demand
Third-Party Risk Management
  • Security posture and compliance status assessed prior to engagement
  • Contractual confidentiality and data protection obligations required
  • Access limited strictly to operational necessity
  • Critical integrations subject to ongoing oversight and review
  • Subprocessors required to meet security standards consistent with our own

A list of key subprocessors and technology partners used in the delivery of DigiU services is available upon request.

Continuous Improvement
  • Ongoing security reviews and internal audits
  • Proactive threat intelligence monitoring
  • Regular updates to policies, procedures, and technical controls
  • Staff security awareness training and phishing simulations
  • Strengthening of AI governance frameworks as technology advances

Trust is earned through consistent action. We continuously strengthen our safeguards and we are transparent about how we do it.

Questions About Security

If you have questions about our security framework, AI governance model, vulnerability disclosure, or compliance approach, please contact us:

DigiU Security Team

Let’s solve your toughest energy challenges.