SharpLyncGet IT Support

Security and trust

Security Policy

The principles and practical controls SharpLync uses to protect systems, services and customer information.

1. Purpose and scope

This policy explains the security principles, controls and procedures SharpLync uses to protect internal systems, customer information, cloud services, software development and remote-support operations.

It describes our security approach without publishing sensitive configuration details that could increase risk.

2. Security principles

  • Verify explicitly: access is authenticated and not trusted solely because of location or device.
  • Least privilege: people and systems receive only the access required for their role.
  • Protect data: encryption and appropriate controls are used for information in transit and at rest.
  • Monitor and record: significant security and administrative activity is logged and reviewed where appropriate.
  • Build securely: security is considered when services and systems are selected, configured and developed.
  • Prepare to respond: suspected incidents are assessed, contained, remediated and documented.

3. TrendAI partnership and endpoint security

SharpLync is a TrendAI partner. We use Trend Micro security technology as part of our own security approach and in managed customer endpoint services where agreed.

Depending on the selected service and licence, capabilities may include endpoint protection, behavioural detection, threat telemetry, investigation and response workflows. Customer coverage and monitoring commitments are defined in the applicable Quote or SOW.

Learn more on our TrendAI endpoint security page.

4. Cloud and application security

SharpLync uses reputable cloud platforms and service providers, including Microsoft and Cloudflare services, according to the needs of each website, application, customer system or internal function.

  • Encrypted HTTPS connections for public websites and supported applications.
  • Access controls and multi-factor authentication for administrative services.
  • Secrets and service credentials kept out of public source code.
  • Platform security controls, patching and logging appropriate to the service.
  • Network restrictions and firewall controls where supported and appropriate.

5. Data, backups and payment information

Access to customer and operational information is restricted to authorised people and systems with a legitimate business or service need. Separate administrative and application access is used where appropriate.

Backups and recovery arrangements are selected according to the service and information involved. Managed backup obligations for customers apply only where included in an accepted Quote or SOW.

SharpLync does not store full customer payment-card numbers, CVV codes or internet-banking credentials. Payment and accounting information is handled through established providers such as Xero and Stripe under their own security and compliance programs.

6. Identity, credentials and devices

  • Multi-factor authentication is used for important administrative and business accounts where available.
  • Passwords and service credentials are stored in approved encrypted credential-management systems.
  • Shared administrative accounts are avoided and access is removed when no longer required.
  • SharpLync work devices use endpoint protection, encryption and secure configuration appropriate to their role.
  • Privileged access and account permissions are periodically reviewed.

7. Software and change security

SharpLync applies practical secure-development controls to software and websites it operates. These may include source control, dependency review, secret scanning, code review, environment separation, restricted deployment access and security testing appropriate to the application’s risk.

Changes are tested and deployed through controlled workflows. Sensitive credentials must not be committed to public repositories.

8. Customer support security

Identity and authority are checked before sensitive account discussions or changes. Remote support follows our Remote Support Policy, including expected-session checks, customer control and strict financial-safety rules.

No permanent remote access is installed during an ordinary QuickSupport session. Unattended access requires a documented need and explicit authorisation.

9. Incident response and notification

Suspected incidents are triaged according to their nature and impact. Response may include preserving evidence, containing affected access or devices, resetting credentials, removing malicious activity, restoring services and documenting corrective actions.

Customers and relevant authorities will be notified where required by law or where notification is appropriate to help reduce harm. Security events relating to managed customer services are handled according to the agreed service scope.

10. Customer responsibilities

  • Keep passwords and authentication codes private.
  • Maintain appropriate backups unless SharpLync has an agreed managed-backup responsibility.
  • Keep systems and supported software updated.
  • Notify SharpLync promptly about suspected incidents and staff access changes.
  • Follow agreed security guidance and do not weaken controls without understanding the risk.

11. Report a security concern

SharpLync Security Team
Email: security@sharplync.com.au
Phone: 0492 014 463
PO Box 1081, Stanthorpe QLD 4380