Security & Compliance
Your data is protected by enterprise-grade security, NZ-based infrastructure, and strict privacy compliance.
Data encryption
All data transmitted to and from the iCareNZ platform is encrypted using TLS 1.3. Data at rest is encrypted using AES-256. This ensures your information remains confidential and secure at all times, whether in transit or stored.
NZ-based hosting
All data is stored securely within New Zealand data centres. We use enterprise-grade cloud infrastructure providers with ISO 27001 certification, ensuring physical and network security at the highest standards.
Access control
Role-based access control ensures staff only see what they need to. Multi-factor authentication is available for additional security. Full audit logs track every action taken within the platform, providing complete accountability.
Privacy compliance
iCareNZ is designed to comply with the New Zealand Privacy Act 2020 and the Health Information Privacy Code 2020. We conduct regular privacy impact assessments and maintain data processing records in accordance with regulatory requirements.
Backup & recovery
Automated daily backups with point-in-time recovery. Our disaster recovery plan ensures business continuity with a Recovery Time Objective (RTO) of less than 4 hours and a Recovery Point Objective (RPO) of 24 hours.
Penetration testing
We engage independent NZ-based security firms to conduct regular penetration testing and vulnerability assessments. Any findings are promptly assessed, prioritised, and remediated within agreed timelines.
Staff training
All iCareNZ staff undergo regular security awareness training. We maintain a strict internal security policy covering data handling, device management, and incident response. Background checks are conducted on all employees.
Report a vulnerability
If you discover a security vulnerability, please contact us at security@icarenz.nz. We take all reports seriously, will respond within 24 hours, and work with you to resolve the issue promptly.
Our certifications & standards
NZ Privacy Act
2020 Compliant
ISO 27001
Infrastructure
TLS 1.3
In Transit
AES-256
At Rest
Security is built in, not bolted on
Want to learn more about our security practices or request a security review?