Get a free instant audit of your site, real findings in 15 seconds. Try it →
Industries Healthcare Industrial B2B Consumer Property & Development Professional & Trade Services Retail & Hardware Automotive (4x4) Fashion & Beauty Instant Audit Services Work Platform Why 121 Pricing Free Audit Founder Call Resources News About 1300 121 979 Book a Discovery
Book a Discovery
📞 1300 121 979 Book a Discovery
Security & Data · Vendor Due-Diligence

Security & data handling, the answers procurement and IT actually ask for.

Vendor due-diligence summary for enterprise procurement teams, healthcare data-protection officers, PE-portfolio CISO reviews, and tier-1 procurement panels. Our infrastructure stack, our access-control model, our data-residency posture, and our incident-response approach.

The infrastructure summary

Where data lives, how it moves, who touches it.

01 · IDENTITY

Google Workspace + Cloudflare Access SSO

Identity is centralised through Google Workspace. Internal tools (BigQuery dashboards, deployment platforms, agency-internal sites) are gated by Cloudflare Access requiring SSO from @121group.io. Role-based access enforced at the SSO layer.

02 · DATA RESIDENCY

Australian regions where the platform supports it

Production AI processing occurs in australia-southeast1 (Vertex AI, Gemini regional endpoints, BigQuery datasets). Customer-facing client websites are hosted on Cloudflare's Australian edge or on Australian-resident WordPress hosts (Kinsta, Cloudways). GCS buckets created in australia-southeast1.

03 · ACCESS CONTROL

Per-engagement client-data isolation

Client data is isolated per engagement. We do not pool client data across accounts for AI training or inference. Access to a client's data is restricted to the engagement team, not the agency-at-large. Audit logging on all access events.

04 · CLIENT CREDENTIALS

We use yours, never share ours

For platforms (Google Ads, Meta Business Manager, Shopify, Klaviyo, GA4, etc.), we operate as authorised users on your accounts using your authentication. We don't share credentials with third parties. We don't keep credentials longer than the engagement requires.

05 · AI BOUNDARY

Patient + sensitive data excluded

For healthcare clients, patient personal information is excluded from AI processing at the boundary level. Where engagement involves pathology data, patient-record data, or clinical encounter data, we operate under a separate written data handling protocol with the client compliance officer.

06 · INCIDENT RESPONSE

Documented response & disclosure model

Documented incident response procedure with escalation paths to client compliance officers. Notifiable Data Breach scheme awareness for healthcare clients. Privacy Act 1988 (Cth) alignment throughout. We've been operating since 2005 without a notifiable breach event.

Tools we use that procurement asks about

The full stack, named.

IDENTITY

Google Workspace

SSO, email, document storage, calendaring. Australia-region tenant where applicable.

EDGE

Cloudflare

DNS, CDN, WAF, Cloudflare Access for internal-tool gating, Cloudflare Pages for client sites, Cloudflare Workers for serverless integrations.

CLOUD

Google Cloud (Vertex AI, BigQuery, GCS)

Production AI stack. Australian-region resources where applicable. IAM-managed access, audit-logged.

CRM / ACCOUNTING

Xero + ActiveCampaign

Xero for accounting + invoicing (Australian tenant). ActiveCampaign for CRM + sales pipeline.

PROJECT MGMT

Notion

Editorial calendars, brand voice docs, engagement playbooks, internal wikis.

CODE / DEPLOY

GitHub + Cloudflare

Code repositories on GitHub. Continuous deployment to Cloudflare Pages / Cloudflare Workers for client sites.

Need the full vendor due-diligence pack?

PDF security policy + data flow diagrams + sub-processor list + incident response procedure + Privacy Act compliance attestation. Available within 4 hours of request.

security@121group.io