An assurance platform should answer its own questions.
We ask institutions to state the condition of their controls. It would be poor form not to state ours. This page sets out how Testamark handles evidence, access and residency.
Practices, stated plainly.
Signals, not raw data
Integrations read the state of a control and return a signal. Raw records stay in your environment, which keeps the sharing protocol narrow and reviewable.
No agents required
Testamark connects by direct API. Where you already run a secure agent and prefer to use it, we can ingest through that instead.
Data residency respected
Deployment sits within your residency and privacy constraints. Where data must remain in country, it remains in country.
Immutable record
Every state change is appended with an actor and a timestamp. The record can be read back at any past date without reconstruction.
Access, scoped
Single sign on, role based access control, and scoping down to the individual control and relationship.
Independently certified
Testamark holds ISO/IEC 27001 for information security and ISO/IEC 42001 for its AI management system.
If you find something, tell us.
Security reports are read by an engineer, not a queue. Write to security@testamark.com.au with what you found and how to reproduce it. We acknowledge within one business day and will tell you plainly what we intend to do about it.
Review our controls before you trust ours with yours.
We will walk your security team through the architecture, the integration model and the evidence we hold on ourselves.