Security & Vulnerability Disclosure

Version 2026-10-v1 · Australian Standard

ZimQi is built from the ground up with defensive engineering to protect the workforce and financial data of Australian businesses.

Security architecture & controls

🔒 Tenant isolation

PostgreSQL Row-Level Security (RLS) and scoped data queries enforce isolation per company. Every tenant query is pre-filtered by tenant context.

🛡️ Least privilege & MFA

Platform administration routes require RFC 6238 TOTP multi-factor authentication, dedicated short-lived sessions, and PII masking by default.

📜 Append-only audit logs

Every sensitive action, export, and administrative modification is written to database-enforced append-only audit ledgers that cannot be updated or deleted.

🔐 Encryption & backups

HSTS with strict transport security, double-submit CSRF protection, and AES-256 encrypted automated backups with rolling 35-day retention.

Coordinated vulnerability disclosure

We welcome reports from security researchers and practitioners to help keep our users and infrastructure safe. If you believe you have discovered a security vulnerability in ZimQi, please report it to us responsibly.

Reporting a vulnerability

Please email details to: security@zimqi.com.au

Safe harbour & rules of engagement

If you conduct your research in good faith and comply with these guidelines, we consider your research authorized and will not initiate legal action against you:

Security standard (RFC 9116)

Our digital security policy declaration is available at /.well-known/security.txt.