LEGAL · HARDROCK CYBER

Data Handling

How your assessment data is captured, secured, moved and retired — our chain of custody.

Last updated: June 2026

ON THIS PAGE

The bottom line

Our approach

On-site capture

Data at rest

Data in motion

Device hygiene

Backups & resilience

Access & retention

Staff confidentiality

Contact us

The bottom line

Protecting your information is one of our highest priorities. We handle all client data with care, using strong security measures throughout the entire process — from collection and storage to transfer and deletion. Our systems and procedures are designed to keep your information safe, confidential, and accessible only to authorised personnel.

Our approach

The independence and integrity of your business data is critical to how we work. We document only what an assessment or consult requires, we keep a clear chain of custody from the moment evidence is captured, and protect it with layered controls at every stage. This page explains that lifecycle in plain English.

On-site capture (air-gapped)

We record assessment evidence on site using a dedicated, secured Windows 11 device running our proprietary audit assessment and compliance application. During capture, the device is air-gapped — kept off your network entirely — so the assessment cannot affect or reconfigure your live environment. Opening the tool requires hardware-key authentication using a physical security key that is carried separately from the device, so data cannot be accessed if the device alone is lost. This is industry-leading hardware security, trusted by governments and enterprises to protect critical business systems. Recording evidence directly into our own tool, isolated from your network, is fundamental to preserving the credibility and integrity of the assessment.

Data at rest (encryption)

Assessment data is stored in an encrypted local database on the device, protected with strong database-level encryption and a securely derived key tied to a protected master credential. The database cannot be opened without the correct key, and an incorrect key is rejected outright. The local audit application has a data kill-switch that clears and resets the database on lost or failed authentication attempts. When data reaches our master systems, it is held in an encrypted, access-controlled cloud environment, while the local application copy is cleaned and inspected free of your data before the device is used elsewhere.

Data in motion (secure sync)

The device stays air-gapped until the on-site work is complete. When it is next connected online in our controlled environment, the assessment is checked in to our master database over an encrypted connection. Access to that database is governed by individual sign-in and role-based permissions, and activity is recorded in tamper-evident logs — so the chain of custody is auditable from end to end.

Device hygiene

Once an assessment has been securely synchronised to our master systems, all audit records, evidence, notes, findings and supporting data are removed from the on-site device database. The application tool itself remains installed, along with basic client reference information required to identify the engagement, but no assessment evidence or audit records are retained on the travelling device. This ensures client assessment data is not carried between engagements or exposed if a device is subsequently lost, stolen or compromised.

Backups & resilience

Assessment data stored within our master systems is protected by encrypted backups and platform resilience controls. Backups are managed within our cloud environment and are designed to support recovery from accidental deletion, corruption or service disruption. Backup access is restricted to authorised personnel and protected by the same access control and confidentiality requirements that apply to production data.

Access, retention & third parties

Access to assessment records on our master systems is restricted on a strict need-to-know basis under role-based controls. We retain data only as long as needed for your engagement or as required by law, and any third-party provider involved in storage or processing is bound by strict confidentiality obligations.

Staff confidentiality & authorised sharing

Access to client information is restricted to authorised Hardrock Cyber personnel who require access to perform their role. All personnel are subject to confidentiality obligations and are expected to handle client information in accordance with our security and privacy requirements. We do not share assessment information outside Hardrock Cyber unless required to deliver the engagement, required by law, or specifically authorised by you. For example, you may instruct us to communicate findings directly with your managed service provider (MSP), IT support provider or other nominated representative. Where requested, we are happy to enter into a Non-Disclosure Agreement (NDA) to provide additional assurance regarding the handling of your information.

Contact us

For questions about how we handle your assessment data, contact us at tech@hardrockcyber.com.au.