Calxa is committed to protecting your data and ensuring the privacy of everyone who uses our platform. Security is built into every part of our product, infrastructure, and operations, and we continually invest in processes and technology that keep your information safe.
This article provides a high‑level overview of how we safeguard your data. For detailed information, including technical controls, policies, FAQs, and certifications please visit the Calxa Trust Centre.
ISO 27001:2022 Certification
Calxa is ISO 27001:2022 certified, demonstrating our commitment to maintaining a robust Information Security Management System (ISMS). This internationally recognised standard ensures we follow best‑practice processes for managing risks, protecting data, and maintaining secure operations.
You can find certification details and supporting documentation in our Trust Centre.
How We Protect Your Data
Infrastructure Security
Calxa’s infrastructure is hosted in Microsoft Azure and governed by strict ISO‑aligned controls that ensure secure data transfer, strong cryptography, and tightly managed access. We enforce MFA, manage identities throughout their lifecycle, and apply privileged‑access restrictions to minimise risk. Our cloud environments follow defined governance processes, ensuring secure configuration, monitoring, and resilience.
Organisational Security
We maintain clear security governance across the organisation, supported by documented ISMS scope, asset ownership, and protection requirements. Devices and storage media follow strict handling, transport, and disposal procedures, and all staff receive ongoing security training to maintain competence. Malware protection, endpoint controls, and secure off‑premises use ensure organisational assets remain protected wherever they are used.
Product Security
Security is embedded throughout our development lifecycle, with controlled access to source code, secure coding standards, and structured testing at every stage. Development, test, and production environments are strictly separated. All testing uses synthetic or non‑production data, and our secure development processes ensure new features and updates are designed, built, and deployed with security as a core requirement.
Internal Security Procedures
Our operational processes ensure continuity, resilience, and secure system management. We maintain tested backup and recovery procedures, monitor capacity and configuration, and apply controlled change‑management practices to all infrastructure updates. Software installation is tightly governed, and regular internal audits verify that our ISMS remains effective, compliant, and continuously improving.
Data & Privacy
Calxa protects customer information through responsible data‑handling practices that comply with relevant privacy legislation, including the Australian Privacy Principles. We collect only the information needed to deliver our services, store it securely, and delete it when no longer required. Personal data is accessed only by authorised staff for legitimate operational purposes, and we maintain clear procedures for managing and safeguarding customer records. For full details on how we collect, use, store, and disclose personal information, please refer to our Privacy Policy.
