LiveEvidence and security

An assurance platform should answer its own questions.

We ask institutions to state the condition of their controls. It would be poor form not to state ours. This page sets out how Testamark handles evidence, access and residency.

ISO/IEC 27001
Information security
ISO/IEC 42001
AI management system
How we handle evidence

Practices, stated plainly.

Signals, not raw data

Integrations read the state of a control and return a signal. Raw records stay in your environment, which keeps the sharing protocol narrow and reviewable.

No agents required

Testamark connects by direct API. Where you already run a secure agent and prefer to use it, we can ingest through that instead.

Data residency respected

Deployment sits within your residency and privacy constraints. Where data must remain in country, it remains in country.

Immutable record

Every state change is appended with an actor and a timestamp. The record can be read back at any past date without reconstruction.

Access, scoped

Single sign on, role based access control, and scoping down to the individual control and relationship.

Independently certified

Testamark holds ISO/IEC 27001 for information security and ISO/IEC 42001 for its AI management system.

Reporting a concern

If you find something, tell us.

Security reports are read by an engineer, not a queue. Write to security@testamark.com.au with what you found and how to reproduce it. We acknowledge within one business day and will tell you plainly what we intend to do about it.

Speak with us

Review our controls before you trust ours with yours.

We will walk your security team through the architecture, the integration model and the evidence we hold on ourselves.

Request a briefing