Dedicated regional environments
Each organisation is hosted in the region it chooses.
- Provider
- Amazon Web Services
- Data residency
- Data stays within that region
How CommandPost® is hosted, secured, assessed and made accessible, in one place. Start your security review here, before the demo.
Security controls are designed against the Australian Government's PSPF, ISM and Essential Eight, and built into how the platform is written, tested and run.
Data is encrypted in transit with TLS 1.2 or higher (TLS 1.3 preferred), and sensitive fields are encrypted with AES-256.
Multi-factor authentication and role-based permissions for every operation. Changing a password, role or MFA setting ends every existing session.
Each organisation's data is kept apart from every other organisation's, with automated tests for isolation and access control.
Every change a user makes is recorded, cannot be altered and is kept for seven years.
Critical vulnerabilities are patched within 48 hours and high ones within two weeks, in line with the Essential Eight.
Every change is peer reviewed and tested, and each production release needs an independent approval.
Each deployment is hosted on Amazon Web Services in its own region, and its data does not leave that region.
Each organisation is hosted in the region it chooses.
Our current position against the frameworks buyers ask about most. Ask us for the latest evidence for any of them.
| Framework | Status | Detail |
|---|---|---|
| NSW Government ICT Services Scheme | Approved supplier | Listed on the Advanced Register. |
| PSPF, ISM and the Essential Eight | Aligned | Controls designed against the Australian Government's security frameworks. |
| Privacy Act 1988 and the Australian Privacy Principles | Aligned | Personal information handled in line with the APPs. |
| WCAG 2.1 AA | Target standard | See the accessibility statement for known issues. |
| ISO/IEC 27001 | In progress | Not yet certified. |
| SOC 2 Type II | In progress | Not yet attested. |
Status as at September 2026.
We aim to meet the Web Content Accessibility Guidelines (WCAG) 2.1 at level AA across the CommandPost® web app, the mobile and desktop apps, and this website.
The web app is designed for keyboard-only use, screen readers and high-contrast settings, and supports right-to-left languages such as Arabic.
If something is hard to use, email support@commandpost.app and tell us the page and what happened.
This statement was last reviewed in September 2026.
Two pages on what CommandPost® does, who it serves, how it is hosted and secured, and our company details.
Architecture, controls and hosting in detail, with our answers to common security questionnaires.
Our WCAG 2.1 AA position and the known issues we are fixing.
How we collect, use and protect personal information.
The terms that apply to every CommandPost® account.