Version 2026-10-v1 · Australian Standard
ZimQi is built from the ground up with defensive engineering to protect the workforce and financial data of Australian businesses.
PostgreSQL Row-Level Security (RLS) and scoped data queries enforce isolation per company. Every tenant query is pre-filtered by tenant context.
Platform administration routes require RFC 6238 TOTP multi-factor authentication, dedicated short-lived sessions, and PII masking by default.
Every sensitive action, export, and administrative modification is written to database-enforced append-only audit ledgers that cannot be updated or deleted.
HSTS with strict transport security, double-submit CSRF protection, and AES-256 encrypted automated backups with rolling 35-day retention.
We welcome reports from security researchers and practitioners to help keep our users and infrastructure safe. If you believe you have discovered a security vulnerability in ZimQi, please report it to us responsibly.
Please email details to: security@zimqi.com.au
If you conduct your research in good faith and comply with these guidelines, we consider your research authorized and will not initiate legal action against you:
Our digital security policy declaration is available at /.well-known/security.txt.