Security
Security at FinEase
Financial hardship data is among the most sensitive information a lender handles. We build security into every layer of the platform — not as an afterthought, but as a foundation.
Encryption Everywhere
All data is encrypted in transit using TLS 1.2+ and at rest using industry-standard encryption. Backups are encrypted with AES-256.
Access Controls
Role-based access control (RBAC) ensures users only access what they need. Multi-factor authentication (MFA) is available for all accounts.
Comprehensive Audit Trail
Every action is logged with user identity, timestamp, and source. Audit logs are timestamped and retained for 7 years in line with NCC record-keeping obligations.
Session Security
Short-lived access tokens, automatic session expiry, idle timeouts, and device binding protect against session hijacking and unauthorised access.
Australian Data Residency
All customer data is stored on infrastructure located in Sydney, Australia.
24/7 Monitoring
Automated monitoring and alerting covers infrastructure health, application performance, and security events around the clock.
Regular Security Assessments
We conduct regular vulnerability assessments and maintain a security-first development process with dependency auditing and code review.
Backup & Recovery
Automated daily backups with tested restore procedures. Multiple retention tiers ensure data recoverability.
Regulatory alignment
FinEase is designed around the frameworks Australian hardship teams work within. These describe how the platform supports your obligations — they are not a guarantee of compliance, which remains your organisation’s responsibility.
Privacy Act 1988 (Cth)
Designed to align with the Australian Privacy Principles (APPs), covering data collection, use, disclosure and cross-border transfer.
National Consumer Credit Protection Act 2009
Designed to support NCC obligations, including response-deadline visibility, s88 default-notice templates, AFCA escalation tracking and 7-year record retention.
Notifiable Data Breaches Scheme
Incident response procedures designed to support obligations under the Notifiable Data Breaches scheme (Part IIIC).
OWASP Security Principles
Application security is built with OWASP principles in mind, including input validation, secure file upload, CSRF protection and security headers.
Infrastructure
Hosting
Dedicated infrastructure in Sydney, Australia. No shared hosting at the server level for Enterprise customers.
Network
Enterprise-grade DDoS protection and web application firewall (WAF). All traffic routes through secure tunnels.
Database
Isolated database per tenant. Automated daily backups with encryption.
Incident Response
Documented incident response procedures with defined severity levels, escalation paths, and communication timelines.
Responsible Disclosure
If you discover a security vulnerability, please report it responsibly to security@financialease.com.au. We respond within 48 hours and do not pursue legal action against researchers acting in good faith.
Important
This page describes FinEase’s security measures. No system is completely secure, and FinEase does not guarantee compliance with any law or standard. Customers remain responsible for managing their credentials and access, assessing FinEase against their own requirements, and meeting their obligations under applicable law. See our Privacy Policy and Data Processing Agreement for more.
Need more detail?
We’re happy to provide additional security documentation, answer vendor risk questionnaires, or arrange a security-focused call with your team.
Contact Security Team