Security at FinEase

Financial hardship data is among the most sensitive information a lender handles. We build security into every layer of the platform — not as an afterthought, but as a foundation.

Encryption Everywhere

All data is encrypted in transit using TLS 1.2+ and at rest using industry-standard encryption. Backups are encrypted with AES-256.

Access Controls

Role-based access control (RBAC) ensures users only access what they need. Multi-factor authentication (MFA) is available for all accounts.

Comprehensive Audit Trail

Every action is logged with user identity, timestamp, and source. Audit logs are timestamped and retained for 7 years in line with NCC record-keeping obligations.

Session Security

Short-lived access tokens, automatic session expiry, idle timeouts, and device binding protect against session hijacking and unauthorised access.

Australian Data Residency

All customer data is stored on infrastructure located in Sydney, Australia.

24/7 Monitoring

Automated monitoring and alerting covers infrastructure health, application performance, and security events around the clock.

Regular Security Assessments

We conduct regular vulnerability assessments and maintain a security-first development process with dependency auditing and code review.

Backup & Recovery

Automated daily backups with tested restore procedures. Multiple retention tiers ensure data recoverability.

Regulatory alignment

FinEase is designed around the frameworks Australian hardship teams work within. These describe how the platform supports your obligations — they are not a guarantee of compliance, which remains your organisation’s responsibility.

Privacy Act 1988 (Cth)

Designed to align with the Australian Privacy Principles (APPs), covering data collection, use, disclosure and cross-border transfer.

National Consumer Credit Protection Act 2009

Designed to support NCC obligations, including response-deadline visibility, s88 default-notice templates, AFCA escalation tracking and 7-year record retention.

Notifiable Data Breaches Scheme

Incident response procedures designed to support obligations under the Notifiable Data Breaches scheme (Part IIIC).

OWASP Security Principles

Application security is built with OWASP principles in mind, including input validation, secure file upload, CSRF protection and security headers.

Infrastructure

Hosting

Dedicated infrastructure in Sydney, Australia. No shared hosting at the server level for Enterprise customers.

Network

Enterprise-grade DDoS protection and web application firewall (WAF). All traffic routes through secure tunnels.

Database

Isolated database per tenant. Automated daily backups with encryption.

Incident Response

Documented incident response procedures with defined severity levels, escalation paths, and communication timelines.

Responsible Disclosure

If you discover a security vulnerability, please report it responsibly to security@financialease.com.au. We respond within 48 hours and do not pursue legal action against researchers acting in good faith.

Important

This page describes FinEase’s security measures. No system is completely secure, and FinEase does not guarantee compliance with any law or standard. Customers remain responsible for managing their credentials and access, assessing FinEase against their own requirements, and meeting their obligations under applicable law. See our Privacy Policy and Data Processing Agreement for more.

Need more detail?

We’re happy to provide additional security documentation, answer vendor risk questionnaires, or arrange a security-focused call with your team.

Contact Security Team