YourCSM Security

YourCSM is an independent pre-credit document-intelligence product for Australian mortgage brokers. This page describes our security posture honestly: what we have today, what we're working toward, and how to talk to us if you find a problem.

Last updated: 19 August 2026 · Next review: 19 November 2026

Phishing-resistant MFA in rollout EDR active (managed) Client-side encryption at rest — state blob only; document files not covered DMARC enforcement Wk3 SOC 2 Type I planned (not yet commenced) ISO 27001 planned (not yet commenced)

How to report a security issue

Email security@yoursoftware.com.au. Use the same address even if the issue is in a third-party tool we use.

We commit to:

Our machine-readable security.txt follows RFC 9116.

Coordinated vulnerability disclosure policy

In scope

Out of scope

Safe harbour

Good-faith research consistent with this policy is authorised. We will not pursue civil or criminal action against researchers who follow it. Activity outside this policy is subject to applicable law.

Disclosure window

Please give us a 90-day disclosure window before publishing details. We may request an extension for complex vulnerabilities — and we'll keep you in the loop on progress.

Controls we operate today

DomainControlStatus
IdentityPhishing-resistant MFA (passkey / YubiKey) for all staff accessing RESTRICTED dataIn rollout Wk1-4
IdentityTwo-person rule for super-admin accounts on Workspace, MyCRM, Azure, Anthropic Console, 1PasswordWk1 secondary admin onboarded
EndpointFull-disk encryption (BitLocker) on every device touching client dataVerified per device in Wk5 audit
EndpointEDR with managed response on every deviceActive (N-able via MSP)
EmailDMARC p=reject + DKIM + SPFWk3
EmailBEC-proof settlement process (callback verification + two-person rule + change-of-details auto-suspend)Wk3
ApplicationSAST + dependency scan + secret scan + IaC scan on every PRWk4
ApplicationClient-side encryption at rest, YourCSM — optional passphrase encrypts the browser localStorage state blob (AES-256-GCM; DEK wrapped under passphrase + recovery key, PBKDF2-SHA-256 150k). Scope limit: the original document files in IndexedDB are NOT encrypted by this control.Live, scope-limited as stated
ApplicationEncryption at rest for document files in IndexedDBNot implemented — under decision; see privacy notice §8
ApplicationField-level encryption for RESTRICTED data at rest (envelope encryption with per-tenant DEKs once multi-tenant)v2 builds Wk5-Mo12
AITiered AI use policy (T1-T4) covering DPA + zero-retention + region + HITLLive
AIAI agent identity store covering every autonomous AI agent we operateLive
AIPer-call cost cap + per-day cost cap enforced at code boundaryLive (Anthropic SDK wrapper)
AIPrompt-injection defence (input sanitisation + XML tag boundary + injection score + system-prompt protocol)Helper live; full deploy Wk2
BackupWorkspace third-party backup with 12-month retention + tested restoreWk7
LoggingSIEM with detection rules for impossible-travel + auto-forward + bulk export + new OAuth grantMo 3 (Wazuh)
VendorDPA on every vendor processing RESTRICTED data; sub-processor list publicWk6 audit

This list is honest. "Pending" means the control is planned + scheduled, not "we don't have it and we hope to". When a control flips to "Live", we update this page.

Certifications + frameworks

Today

Planned (not yet commenced)

Frameworks we map to today

NIST CSF 2.0 (with Govern as umbrella) · OWASP ASVS L2 · OWASP LLM Top 10 (2025) · MITRE ATT&CK + ATLAS · CIS Benchmarks · NIST AI RMF 1.0 · ISO/IEC 42001 · APRA CPS 230 alignment (we are not APRA-regulated but our aggregator partner is in scope) · Australian Privacy Principles · OAIC Notifiable Data Breaches · NCCP · ASIC RG 234

Sub-processors

Vendors that may process customer data on behalf of Yoursoftware Pty Ltd or our products. Current list:

VendorRoleRegionDPA
Anthropic (Claude API)AI inference for YourCSM extraction and AI features across our productsUS (contracted-region)Pending Wk6 audit
Voyage AI (now Anthropic)Embedding model for YourCSM document similarityUSPending Wk6 audit
Google WorkspaceEmail + Drive + Calendar + ChatAU + globalStandard Workspace DPA
Microsoft AzureStatic hosting + Azure Functions + Front Door for YourCSM and productised appsAU (Australia East)Microsoft Products & Services DPA
1PasswordCredential vault for staffCAStandard 1Password Business DPA
CRM provider (MyCRM)Broker client and lead dataAUAggregator agreement Wk1 review
illionBank statement retrieval + categorisationAUPending
DocuSignDocument signing for client onboardingAUPending
QuickliServiceability calculationAUPending
SupabaseDatabase + auth + storage for productised apps v2AU (region selection)Pending — pre-v2 launch

When this list changes, customers are notified before the change goes live (unless emergency; we'll explain after the fact). Subscribe to sub-processor updates.

Acknowledgements

We thank the following researchers for responsible disclosure:

Additional resources