YourCSM Security
YourCSM is an independent pre-credit document-intelligence product for Australian mortgage brokers. This page describes our security posture honestly: what we have today, what we're working toward, and how to talk to us if you find a problem.
How to report a security issue
Email security@yoursoftware.com.au. Use the same address even if the issue is in a third-party tool we use.
We commit to:
- Acknowledge your report within 5 business days
- Triage within 10 business days
- Coordinate disclosure with you
- Credit you publicly (or keep your name out of it — your choice)
Our machine-readable security.txt follows RFC 9116.
Coordinated vulnerability disclosure policy
In scope
yoursoftware.com.auand all sub-domainsyourcsm.yoursoftware.com.auand any production YourCSM domain- Any Yoursoftware portal domain
- Any Yoursoftware-owned mobile or desktop application
Out of scope
- Email security best-practice advice without a working exploit
- Outdated TLS cipher reports without a working downgrade
- Findings from automated scanners without a working proof-of-concept
- Social engineering of staff, brokers, family members, or third parties
- Physical attacks on offices
- Denial-of-service / brute-force / spam testing
Safe harbour
Good-faith research consistent with this policy is authorised. We will not pursue civil or criminal action against researchers who follow it. Activity outside this policy is subject to applicable law.
Disclosure window
Please give us a 90-day disclosure window before publishing details. We may request an extension for complex vulnerabilities — and we'll keep you in the loop on progress.
Controls we operate today
| Domain | Control | Status |
|---|---|---|
| Identity | Phishing-resistant MFA (passkey / YubiKey) for all staff accessing RESTRICTED data | In rollout Wk1-4 |
| Identity | Two-person rule for super-admin accounts on Workspace, MyCRM, Azure, Anthropic Console, 1Password | Wk1 secondary admin onboarded |
| Endpoint | Full-disk encryption (BitLocker) on every device touching client data | Verified per device in Wk5 audit |
| Endpoint | EDR with managed response on every device | Active (N-able via MSP) |
DMARC p=reject + DKIM + SPF | Wk3 | |
| BEC-proof settlement process (callback verification + two-person rule + change-of-details auto-suspend) | Wk3 | |
| Application | SAST + dependency scan + secret scan + IaC scan on every PR | Wk4 |
| Application | Client-side encryption at rest, YourCSM — optional passphrase encrypts the browser localStorage state blob (AES-256-GCM; DEK wrapped under passphrase + recovery key, PBKDF2-SHA-256 150k). Scope limit: the original document files in IndexedDB are NOT encrypted by this control. | Live, scope-limited as stated |
| Application | Encryption at rest for document files in IndexedDB | Not implemented — under decision; see privacy notice §8 |
| Application | Field-level encryption for RESTRICTED data at rest (envelope encryption with per-tenant DEKs once multi-tenant) | v2 builds Wk5-Mo12 |
| AI | Tiered AI use policy (T1-T4) covering DPA + zero-retention + region + HITL | Live |
| AI | AI agent identity store covering every autonomous AI agent we operate | Live |
| AI | Per-call cost cap + per-day cost cap enforced at code boundary | Live (Anthropic SDK wrapper) |
| AI | Prompt-injection defence (input sanitisation + XML tag boundary + injection score + system-prompt protocol) | Helper live; full deploy Wk2 |
| Backup | Workspace third-party backup with 12-month retention + tested restore | Wk7 |
| Logging | SIEM with detection rules for impossible-travel + auto-forward + bulk export + new OAuth grant | Mo 3 (Wazuh) |
| Vendor | DPA on every vendor processing RESTRICTED data; sub-processor list public | Wk6 audit |
Certifications + frameworks
Today
- None issued yet. We are 22 staff. This is honest. Below is what's in flight.
Planned (not yet commenced)
- CSA STAR Level 1 (CAIQ) — self-attestation (does not depend on an external audit); pre-completed CAIQ available on request
- SOC 2 Type I — planned; not yet commenced, target under review
- SOC 2 Type II — planned; follows Type I
- ISO 27001:2022 — planned; not yet commenced, target under review
- ISO 27017 / 27018 / 27701 — planned add-ons
Frameworks we map to today
NIST CSF 2.0 (with Govern as umbrella) · OWASP ASVS L2 · OWASP LLM Top 10 (2025) · MITRE ATT&CK + ATLAS · CIS Benchmarks · NIST AI RMF 1.0 · ISO/IEC 42001 · APRA CPS 230 alignment (we are not APRA-regulated but our aggregator partner is in scope) · Australian Privacy Principles · OAIC Notifiable Data Breaches · NCCP · ASIC RG 234
Sub-processors
Vendors that may process customer data on behalf of Yoursoftware Pty Ltd or our products. Current list:
| Vendor | Role | Region | DPA |
|---|---|---|---|
| Anthropic (Claude API) | AI inference for YourCSM extraction and AI features across our products | US (contracted-region) | Pending Wk6 audit |
| Voyage AI (now Anthropic) | Embedding model for YourCSM document similarity | US | Pending Wk6 audit |
| Google Workspace | Email + Drive + Calendar + Chat | AU + global | Standard Workspace DPA |
| Microsoft Azure | Static hosting + Azure Functions + Front Door for YourCSM and productised apps | AU (Australia East) | Microsoft Products & Services DPA |
| 1Password | Credential vault for staff | CA | Standard 1Password Business DPA |
| CRM provider (MyCRM) | Broker client and lead data | AU | Aggregator agreement Wk1 review |
| illion | Bank statement retrieval + categorisation | AU | Pending |
| DocuSign | Document signing for client onboarding | AU | Pending |
| Quickli | Serviceability calculation | AU | Pending |
| Supabase | Database + auth + storage for productised apps v2 | AU (region selection) | Pending — pre-v2 launch |
Acknowledgements
We thank the following researchers for responsible disclosure:
- (None yet — be the first.)
Additional resources
- Request our customer DPA template
- Request our pre-completed SIG Lite + CAIQ v4 (NDA may apply)
- Request access to our Trust Portal (NDA required; opens Mo 3)
- OAIC Notifiable Data Breaches — where to read about your rights as an affected individual
This page describes the security posture of Yoursoftware Pty Ltd and our products. It is not a contract. Specific commitments to customers are in the customer DPA and master service agreement.