Security & data handling, the answers procurement and IT actually ask for.
Vendor due-diligence summary for enterprise procurement teams, healthcare data-protection officers, PE-portfolio CISO reviews, and tier-1 procurement panels. Our infrastructure stack, our access-control model, our data-residency posture, and our incident-response approach.
Where data lives, how it moves, who touches it.
Google Workspace + Cloudflare Access SSO
Identity is centralised through Google Workspace. Internal tools (BigQuery dashboards, deployment platforms, agency-internal sites) are gated by Cloudflare Access requiring SSO from @121group.io. Role-based access enforced at the SSO layer.
Australian regions where the platform supports it
Production AI processing occurs in australia-southeast1 (Vertex AI, Gemini regional endpoints, BigQuery datasets). Customer-facing client websites are hosted on Cloudflare's Australian edge or on Australian-resident WordPress hosts (Kinsta, Cloudways). GCS buckets created in australia-southeast1.
Per-engagement client-data isolation
Client data is isolated per engagement. We do not pool client data across accounts for AI training or inference. Access to a client's data is restricted to the engagement team, not the agency-at-large. Audit logging on all access events.
We use yours, never share ours
For platforms (Google Ads, Meta Business Manager, Shopify, Klaviyo, GA4, etc.), we operate as authorised users on your accounts using your authentication. We don't share credentials with third parties. We don't keep credentials longer than the engagement requires.
Patient + sensitive data excluded
For healthcare clients, patient personal information is excluded from AI processing at the boundary level. Where engagement involves pathology data, patient-record data, or clinical encounter data, we operate under a separate written data handling protocol with the client compliance officer.
Documented response & disclosure model
Documented incident response procedure with escalation paths to client compliance officers. Notifiable Data Breach scheme awareness for healthcare clients. Privacy Act 1988 (Cth) alignment throughout. We've been operating since 2005 without a notifiable breach event.
The full stack, named.
Google Workspace
SSO, email, document storage, calendaring. Australia-region tenant where applicable.
Cloudflare
DNS, CDN, WAF, Cloudflare Access for internal-tool gating, Cloudflare Pages for client sites, Cloudflare Workers for serverless integrations.
Google Cloud (Vertex AI, BigQuery, GCS)
Production AI stack. Australian-region resources where applicable. IAM-managed access, audit-logged.
Xero + ActiveCampaign
Xero for accounting + invoicing (Australian tenant). ActiveCampaign for CRM + sales pipeline.
Notion
Editorial calendars, brand voice docs, engagement playbooks, internal wikis.
GitHub + Cloudflare
Code repositories on GitHub. Continuous deployment to Cloudflare Pages / Cloudflare Workers for client sites.
Need the full vendor due-diligence pack?
PDF security policy + data flow diagrams + sub-processor list + incident response procedure + Privacy Act compliance attestation. Available within 4 hours of request.
security@121group.io