Annature does not complete custom security questionnaires, spreadsheets, or vendor risk portals.
This page is the assessment. It is written so a customer’s security, privacy, risk, or procurement team can complete their own due diligence using information we already make public, plus the controls that sit behind our ISO 27001-certified Information Security Management System (ISMS).
If you need independent evidence, download our current certificates and reports from Certifications & Reports. Our sub processors, privacy policy, and the rest of the Trust centre should be read with this page.
We will not fill in your form, join your vendor portal, or restate these answers in a spreadsheet. If a control is not described here, it is either not applicable to a multi-tenant SaaS platform or not something we disclose beyond our independent audits.
Annature is ISO 27001 certified. That certification is independently audited. The controls described here are the same controls that certification requires us to operate, maintain, and evidence.
Company overview
Annature is not a bank, reporting entity, or payment acquirer. Customers remain responsible for their own regulatory obligations (including AML/CTF, where they are the reporting entity). We provide tools and records that support those obligations.
Certifications and independant assurance
What we are not
- Not PCI DSS certified. Card payments are handled by Stripe. We do not store cardholder data.
- Not IRAP certified as an organisation. Our infrastructure provider, AWS, maintains its own IRAP and other government assessments for in-scope services.
Data we hold
Annature processes the information required to deliver digital signing and identity verification, including:
- names, email addresses, phone numbers, and IP addresses
- documents uploaded for signing, plus envelope metadata and audit trails
- identity verification information, which may include government ID details, tax file numbers, biometric images captured during an ID check, and screening results
- usage and operational metadata needed to run the service
We do not use customer personal information for unrelated marketing analytics at an identifiable level. We may use redacted or aggregated data to operate and improve the platform.
Customers own their documents and customer-uploaded content. Annature owns the platform, software, and related intellectual property.
Data residency and hosting
All customer data is stored in Amazon Web Services (AWS), region ap-southeast-2 (Sydney) by default.
- Data is not stored or replicated outside Australia unless a customer has explicitly opted in to another AWS region.
- There is no replication between the Australian region and any other region without instruction.
- Enterprise customers may opt in to a different AWS region. In that case, data stays in the nominated region only.
Physical data centre security, environmental controls, and the underlying host infrastructure are provided by AWS. AWS maintains ISO 27001, SOC, and other certifications for its services. Annature does not operate its own data centres.
The platform is:
- containerised with Docker
- orchestrated with AWS Elastic Container Service (ECS)
- deployed in auto-scaling groups with CloudWatch alarms
- spread across multiple Availability Zones in Sydney for high availability
Instances are replaced after 30 days of uptime so images stay patched. Operating system patches are applied automatically on scale-in. Secrets are stored in AWS Secrets Manager and AWS Systems Manager Parameter Store.
Production is a multi-tenant SaaS environment. Customer data is segregated logically in the application and at the storage layer (including per-account object storage). Customers cannot access another customer’s data through the product. Annature staff cannot browse customer documents as a normal part of support.
Encryption and key management
Access control and identity
Internal (Annature)
- Access is role-based (RBAC) and granted on least privilege / need-to-know.
- MFA is mandatory on all internal systems, regardless of classification.
- Internal identity is federated through Google Workspace.
- Production administrative access is limited to senior information security officers.
- Production is reached over encrypted channels (including VPN for administrative access). Support and onboarding staff do not have standing production access.
- Joiner, mover, and leaver access is revoked or adjusted when someone changes role or leaves. Privileged access is reviewed periodically.
- Individual accounts are used. Shared or generic logins are not used for staff access to production.
- Staff with access to systems handling customer data are subject to screening appropriate to the role, confidentiality obligations, and our Acceptable Use Policy.
Customer (your organisation)
The Annature dashboard supports:
- username and password
- multi-factor authentication (MFA)
- single sign-on (SSO), including Microsoft Entra ID (Azure AD) and SAML-based SSO, plus Xero SSO where applicable
- API authentication with scoped API keys
Your administrators control who in your organisation can access your account. You can enforce MFA. You can provision and de-provision users from the dashboard. User lists can be provided from the product or on request.
Session timeouts apply. Failed login attempts are rate-limited.
We do not require customers to use a specific password complexity standard if SSO is enforced. Where local passwords are used, complexity and length controls apply. Password managers are recommended.
We do not currently offer customer-configurable IP allowlisting as a default product feature for all plans. Privileged Annature administrative access is tightly restricted and is not exposed as a public customer login.
Application and infrastructure security
Defence in depth, on AWS:
- AWS WAF — IP controls, rate limiting, and attack detection
- AWS Shield — DDoS protection
- Network segmentation — internet-facing components (API and web application) are separated from data stores. Databases and object storage are not exposed to the public internet.
- Stateful firewalling between network segments
- Hardened, short-lived containers rather than long-lived patched servers
- Malware and vulnerability controls on infrastructure and endpoints, including file-type validation on uploads (PDF and images for signing)
- Email authentication — SPF, DKIM, and DMARC on domains we send from
- Endpoint protection on staff devices, with encryption, MDM-style remote management, and VPN for remote work
The service is browser-based. There is no native mobile app. There is no in-product web browsing, chat, or arbitrary outbound messaging. The platform sends transactional email and SMS (signing invitations, notifications, OTPs) through listed subprocessors.
Uploaded files are limited to supported document and image types and are checked so that the content matches the declared type.
Secure development
Annature develops and maintains the software we operate.
- Source control is GitHub. CI/CD is Jenkins. Every change is peer-reviewed through a pull request.
- Production, staging, and development are separate. Production data is not used in test or development, except where a customer has consented to a specific bug investigation, in which case data is minimised or anonymised where possible.
- Dependencies are monitored for known vulnerabilities. Critical and high issues are patched on a risk-based timeline.
- Infrastructure and containers are scanned regularly.
- Independent penetration tests are performed annually, and after significant change. Tests are performed by an independent third party.
- We deploy to production multiple times per day, with automated tests in the pipeline.
Customers may not scan, fuzz, or penetration-test the production platform without a written agreement. Unauthorised testing is treated as abuse. We will share our latest independent pentest report instead.
Secure coding practices are part of the ISMS (secure development policy, change management, and vulnerability management). We do not publish internal coding standards or architecture packs for questionnaire use.
Privacy and data protection
We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. We meet applicable GDPR obligations for EEA users. We follow the Notifiable Data Breaches (NDB) scheme.
- Privacy Officer: Corey Cacic, CEO — hello@annature.com.au
- Public privacy policy: annature.com.au/privacy-policy
- Privacy and security training is mandatory for staff and is refreshed on a recurring basis. It covers phishing, social engineering, data handling, and secure development where relevant.
- We run phishing simulations.
- Information is classified and handled according to ISMS policies.
- We do not sell personal information.
- Competitors of a customer do not receive that customer’s data.
Retention
By default, data is not automatically deleted. Customers can enable a retention policy to purge selected data types after a defined period.
On account termination, customers can export their data through the product and API. After the working relationship ends, we will delete or de-identify personal information on request, except where we must retain records (for example backups that age out, or information we are required to keep by law). Remaining backup copies expire through the backup lifecycle.
Data subject access and correction requests: via the dashboard where the data is editable, otherwise hello@annature.com.au or 1300 031 065.
Destruction
Cloud media is not “shredded” by Annature as a physical process. When data is deleted, it is removed from production systems and then expires from encrypted backups. AWS handles physical media destruction for decommissioned hardware under its controls. Staff devices are encrypted and wiped or destroyed before they leave our control.
Subprocessors and third parties
Annature uses subprocessors to operate the service. Each is reviewed for security and privacy. The live list is at annature.com.au/trust/sub-processors.
Customer documents and signed content stay in Annature’s AWS environment in Australia. They are not sent to CRM, billing, or marketing tools.
Limited data is processed by subprocessors only as needed to deliver the service, for example:
- AWS — hosting and storage of all customer data
- Email / SMS — Mandrill, Resend, Twilio, Tallbob (contact details and delivery metadata)
- Identity verification / AML — ComplyCube, RealAML, Mindee (ID documents, biometrics, and screening data where those features are used)
- Document rendering — Microsoft (PDF processing)
- Observability — Datadog (logs and operational metadata)
- Payments — Stripe (billing; not document content)
- OpenAI — automated risk scoring for new Annature account signups (customer identification metadata). This is not used to read or score your signed documents.
Some subprocessors operate globally. That can mean temporary processing of limited metadata or content outside Australia (for example email delivery or an identity check). It does not change where we store documents. We do not permanently store customer document data offshore.
We assess suppliers under our ISMS supplier security process. Contracts include confidentiality and security obligations. We do not allow arbitrary third parties onto the production network.
Annature does not outsource the operation of the core platform to an unmanaged third party. We do not run a separate managed SOC vendor as the owner of our environment; monitoring is in-house using AWS and Datadog.
Logging, monitoring, and incident response
- Access to personal data and production systems is logged and monitored.
- Application, infrastructure, and security events are sent to a centralised platform (Datadog), with AWS CloudWatch for infrastructure telemetry.
- Logs include authentication events, privileged access, and security-relevant application activity.
- Logs are protected from unauthorised change and can support investigation and, where required, forensic reconstruction of events.
- Envelope-level audit trails are hash-chained (each event includes the checksum of the previous event) so the signing history is tamper-evident. See Blockchain technology.
- Time sources are synchronised via AWS.
We do not operate a marketing-style 24×7 human SOC floor. We do operate continuous monitoring, alerting, and on-call response for security and availability events.
Incidents
We maintain a documented incident response plan as part of the ISMS. It covers identification, containment, eradication, recovery, evidence handling, and notification.
If a breach is likely to cause serious harm, we will notify affected customers and, where required, the OAIC, in line with the NDB scheme and our Data Breach Notification Policy.
Notify us of a suspected incident at hello@annature.com.au or 1300 031 065.
We do not publish a separate “cyber hotline” number. The contacts above are the incident contacts.
Root-cause information that is relevant to a customer will be shared with affected customers after an incident, without exposing details that would help an attacker.
Backups, continuity, and disaster recovery
- Database snapshots are taken every 15 minutes.
- Object storage is lifecycle-managed into encrypted cold storage (Glacier).
- Backups are encrypted, retained in cold storage, and replicated to a separate AWS account for isolation. That replication remains in Australia.
- Storage is distributed across multiple Availability Zones.
- Backup processes are automated, versioned, and monitored.
Recovery point objective (RPO): 15 minutes for database-backed data, matching snapshot frequency.
Recovery time objective (RTO): core platform services are designed to be restored within 4 hours in a disaster-recovery scenario. Day-to-day failures are absorbed by multi-AZ high availability without invoking DR.
We maintain a Business Continuity Plan and Disaster Recovery procedures aligned to ISO 27001. The BCP is tested annually. Lessons learned feed back into the ISMS. The CTO reviews continuity metrics.
If our office is unavailable, staff work remotely on encrypted, managed devices over VPN. The product does not depend on a physical office.
We do not publish raw BCP test reports. The existence, annual testing, and ISO alignment of the plan are the public statement.
Contractual availability, if any, is in the Subscriber Agreement. Architecturally the platform is built for high availability; we do not quote a marketing uptime percentage on this page.
People, offices, and culture
- Security awareness training is mandatory and recurring.
- Phishing simulations are run.
- Confidentiality obligations apply to staff and relevant contractors.
- There is a disciplinary process for security policy breaches (ISMS requirement).
- Remote work is covered by Acceptable Use, clear desk/clear screen, and endpoint standards (disk encryption, VPN, hardening).
- Offices are access-controlled. Production systems do not run from the office LAN; they run in AWS.
- Annature does not use customer environments from unmanaged personal devices. Staff devices used for work are company-managed and encrypted.
Support is provided during Australian business hours. We are not a follow-the-sun, 24-hour helpdesk. Infrastructure monitoring continues outside business hours.
Identity verification and AML tooling
This section is for customers assessing Annature as an identity or AML/CTF tooling provider. Annature is not itself an AUSTRAC reporting entity for your customer relationships. You remain the decision-maker on onboarding.
Depending on the product configuration, verification can include:
- government document checks (passport, driver licence, and similar)
- electronic data verification against independent sources
- biometric / liveness capture
- checks against government sources (including DVS where our verification partners provide it)
- enhanced screening for PEPs, sanctions, watchlists, and adverse media (typically via ComplyCube as part of enhanced verification)
- ongoing monitoring, where the customer has enrolled that feature
Results are returned to the customer (pass/fail and supporting report data). We do not decide whether you should accept a person as a client.
Fraud controls on the identity path include document authenticity checks, liveness / spoofing resistance provided by the verification partner, and audit logging of the verification event. Deepfake and biometric fraud controls are those of the specialised vendor performing the check.
Records retained (subject to your retention settings) can include ID artefacts, verification results, audit logs, and AML screening results. They are timestamped. Envelope and verification history can be exported for your own compliance files.
The service is available in the dashboard and via API. Requests can be started by email or SMS. Workflows can be configured to the checks you need (standard vs enhanced).
Insurance, contracts, and exit
- We maintain cyber insurance and professional indemnity insurance. Certificates of currency are available on request. We do not publish policy limits on this page.
- The Subscriber Agreement (and, for identity, the ID verification terms) governs the commercial relationship, liability, data ownership, and termination.
- Governing law is Australia (identity terms specify Queensland).
- Customers retain ownership of their data. On termination, export your data, then request deletion. We do not hold your documents hostage.
- We do not accept each customer’s ISMS, Essential Eight profile, or audit-rights schedule as a contract overlay. Our independently audited ISMS is the control framework.
- We do not permit customers to audit AWS data centres, or to audit our other customers’ tenancies.
- Pricing, licence metrics, and order forms are commercial documents, not security documents.
Related public documents
FAQ
Do you complete vendor security questionnaires?
No. This page, the Trust Centre, and our independent certificates are the response. We will not complete portals, Excel workbooks, or Word questionnaires.
Are you ISO 27001 certified?
Yes. The current certificate is on Certifications & Reports.
Are you SOC 2 certified?
Yes — SOC 2 Type I. SOC 2 Type II is in progress and will be published when issued.
Do you have ISO 27017, 27018, or 27701?
Not yet. Audits are underway. Do not record these as current certifications.
Where is data stored?
AWS Sydney (ap-southeast-2), by default. Not outside Australia unless you opt in to another region.
Are backups stored in Australia?
Yes. Backups are encrypted and replicated to a separate AWS account, remaining in Australia.
Is this a multi-tenant service? Can another customer see our data?
Yes, it is multi-tenant. No, another customer cannot access your data. Segregation is enforced in the application and in storage.
Who in Annature can see our documents?
Standing access to production is limited to senior information security officers on a least-privilege basis. Support staff do not have standing access to customer documents. Access is logged.
Is data encrypted at rest and in transit?
Yes. AES-256 at rest (AWS KMS). TLS 1.2+ in transit.
Can we bring our own encryption keys?
No.
Do you enforce MFA?
Yes, for all Annature internal systems. Customers can enable and enforce MFA (and SSO) on their own accounts.
Do you support SSO / SAML / Entra ID?
Yes. The dashboard supports SSO including SAML and Microsoft Entra ID, and Xero SSO where applicable. APIs use API keys over HTTPS.
Do you meet the ASD Essential Eight?
We are a cloud SaaS provider, not a government agency, so we do not publish an Essential Eight maturity score. The controls behind ISO 27001 address the same outcomes that Essential Eight is aiming at in a cloud environment: MFA, patching, backups, least privilege, and application control in a containerised AWS environment.
Do you have a CISO?
Information security is owned by senior leadership under the ISO 27001 ISMS. Corey Cacic, CEO, is the Privacy Officer. Production administration is limited to senior information security officers.
Do you have a Data Protection Officer?
The Privacy Officer is the CEO. That is the privacy accountability role. We are an Australian company; a European-style DPO title is not required for our default operations.
Do you have an Information Security Policy, and is it reviewed?
Yes. Policies are approved, communicated to staff, and reviewed at least annually or when material change requires it. That is an ISO 27001 requirement. We do not attach the full policy set to questionnaires.
Do you conduct background checks?
Yes, screening appropriate to the role is part of hiring for staff who will access our systems. Confidentiality obligations apply.
Do you train staff on security and privacy?
Yes. Recurring awareness training, including phishing and social engineering, plus role-appropriate content for engineers. Phishing simulations are used.
How often do you penetration test?
Annually, by an independent third party, and after significant change. Reports are available from the Trust Centre / on request as part of the public evidence pack — not as a custom questionnaire attachment process.
Do you vulnerability-scan?
Yes. Infrastructure, containers, and dependencies are scanned on an ongoing basis.
Can we penetration-test your platform?
Not without a written agreement. Send a request if you have a genuine coordinated-testing need. Unauthorised scanning is not permitted.
Do you have a WAF, firewall, and DDoS protection?
Yes. AWS WAF, AWS network firewalling, and AWS Shield.
Do you use a SIEM?
Yes. Centralised logging and alerting via Datadog, with AWS CloudWatch. Logs are reviewed through alerting and investigation, not by mailing a daily log dump to customers.
Do you have EDR / antivirus?
Staff endpoints are protected. Production runs on short-lived AWS-managed containers rather than a traditional antivirus estate. Malware controls exist at upload, email, and endpoint layers.
Do you have DLP?
We do not market a standalone DLP product. We rely on encryption, least privilege, logging, endpoint controls, and prohibition on uncontrolled export of customer data. That is the practical control set.
Do you have an incident response plan? Will you notify us of a breach?
Yes. We will notify affected customers in line with the NDB scheme and our incident procedures. Contact hello@annature.com.au or 1300 031 065 to report an incident to us.
Have you had a notifiable breach in the last 12–24 months?
No notifiable privacy or data incident resulting in regulatory investigation or censure. If that changes, affected customers are notified through the process above — we will not keep a running incident blog.
What is your RPO and RTO?
RPO 15 minutes. RTO 4 hours for core services in a DR scenario. Multi-AZ design is intended so most failures never reach DR.
How often are backups tested?
Backup processes are automated and monitored continuously. The broader BCP/DR plan is tested annually.
How long do you keep our data?
Indefinitely by default, or for the period you configure in a retention policy. You can request deletion. Backup remnants expire through the backup cycle.
What happens to our data if we leave?
Export via the product and API, then deletion on request. You own your content.
Are audit logs available? How long are they kept?
Envelope audit trails are available in the product and are retained with the envelope (default: until you delete or a retention policy applies). Security and operational logs are retained to support investigation and legal requirements — significant audit events are kept for years, not days. Logs can be provided to a customer on request where they relate to that customer’s tenancy and an investigation reasonably requires them.
Do you use production data in test?
No, except a specific production bug investigation with customer consent, minimised or anonymised where possible.
Is support offshore? Does support have access to our data?
Customer support is provided in Australian business hours. Support staff do not have standing production access. Production access is limited to senior information security officers.
Do you subcontract hosting?
Hosting is AWS. Other subprocessors are listed publicly. We do not subcontract operation of the core platform to an unnamed host.
Do you have cyber insurance?
Yes. Professional indemnity as well. Certificates of currency on request. We will not quote limits here or confirm that our policy is your policy.
Do you have a BCP and DR plan?
Yes. ISO 27001-aligned, tested annually, covering people, cloud infrastructure, suppliers, and data.
What is your uptime SLA?
High availability across multiple AZs. Any contractual SLA is in the Subscriber Agreement, not on this page.
Do you comply with the Australian Privacy Act and the APPs?
Yes.
Do you comply with GDPR?
We meet applicable GDPR obligations for EEA individuals who use the service. Our primary regime is Australian privacy law. Data is stored in Australia.
Do you share data with third parties?
Only subprocessors and only to provide the service, or as required by law. The list is public.
Do you use AI on our documents?
The platform is not an AI document-reader for your envelopes. OpenAI is used for automated risk scoring of new Annature signups, not to process the contents of your signing workflows. Identity verification uses specialised KYC vendors, not a generative model to “decide” a person’s identity.
Do you implement post-quantum encryption?
Not yet. AES-256 and TLS 1.2+ today. We will follow AWS/NIST as PQC becomes practical in our stack.
Are you a reporting entity under AML/CTF?
Annature provides identity and screening tools. Your organisation is responsible for its own AML/CTF obligations. We do not make your onboarding decisions.
Do you verify against DVS? PEPs? Sanctions? Adverse media?
Document, data, and biometric verification are supported. Government sources including DVS are used where our verification partners provide them. Enhanced verification screens PEPs, sanctions, watchlists, and adverse media. Ongoing monitoring is available where you enable it.
Can we export verification reports?
Yes. Results and supporting records are available to the customer that requested the check.
What browsers do you support?
Latest stable Chrome, Firefox, and Safari. Internet Explorer is not supported. Edge is not a certified test target.
Do you have a native mobile app?
No. The product is used in a mobile browser.
What is the technology stack?
AWS, with application components in common modern stacks (including Ruby, .NET/C#, Angular, and MySQL). APIs are HTTPS. This is sufficient for vendor assessment; we do not issue a full architecture pack.
Do you sync with Active Directory for every login?
Customers can use SAML/Entra SSO. We are not an on-prem LDAP connector.
Do you allow customer audit of your ISMS or AWS?
We provide independent ISO and SOC reports and pentest reports. We do not host customer auditors in AWS data centres or open the ISMS to every procurement team. That is what the certification is for.
Do you have a sustainability report?
No. This is not a security control.
How do we get certificates?
Certifications & Reports and the Trust overview. If a file is missing, email hello@annature.com.au — ask for the certificate, not a completed questionnaire.
Who do we contact?
hello@annature.com.au · 1300 031 065
For privacy: the same address, directed to the Privacy Officer.
For a suspected security incident: the same channels, marked urgent.