Security Policy

Last updated: August 2026
NextWeb Pty Ltd (ABN 94 613 674 445)

Our Commitment

At NextWeb, security is foundational to how we build and operate NextWeb OS. As a platform handling sensitive business data including CRM records, financial and invoicing information, and payroll data, we design our infrastructure, processes, and culture around protecting that data at every layer.

This policy outlines the technical and organisational measures we have in place.

1. Data Storage & Residency

All customer data is stored exclusively in Australian data centres, located in Sydney and Melbourne. No customer data is stored offshore, giving Australian businesses confidence that their data remains subject to Australian jurisdiction and law.

Our data centre providers maintain independently audited physical security controls, including restricted facility access, 24/7 monitoring, and environmental safeguards.

2. Encryption

Data at rest is encrypted using AES-256 encryption. Data in transit is encrypted using industry-standard TLS protocols across all connections to and within the Platform.

Encryption keys are managed and rotated in line with industry best practice, with access strictly limited to authorised systems and personnel.

3. Access Controls

Access to production systems and customer data is restricted on a least-privilege basis, employees only have access to what is necessary for their role. All internal access is authenticated, logged, and regularly reviewed.

Multi-factor authentication (MFA) is enforced for administrative and privileged access to our infrastructure. Customer accounts support secure authentication practices, and we recommend all users enable strong, unique passwords and MFA where available.

4. Network & Infrastructure Security

Our infrastructure is segmented and protected by firewalls, intrusion detection, and continuous monitoring. We apply security patches and updates to systems and dependencies on a regular, risk-prioritised basis.

Production environments are logically separated from development and testing environments.

5. Application Security

Our development practices incorporate secure coding standards and peer code review. We conduct regular vulnerability assessments and periodic penetration testing of the Platform, and remediate identified issues according to severity.

Third-party libraries and dependencies are monitored for known vulnerabilities.

6. Backups & Business Continuity

Customer data is backed up on a regular schedule, with backups encrypted and stored securely within Australian data centres. We maintain disaster recovery procedures designed to restore service and data integrity in the event of a significant outage or incident.

7. Monitoring & Logging

We maintain continuous monitoring and logging of system activity to detect anomalies, unauthorised access attempts, and potential security incidents. Logs are retained for a period sufficient to support investigation and compliance requirements, and access to logs is restricted.

8. Incident Response

We maintain an incident response process designed to identify, contain, investigate, and remediate security incidents promptly. In the event of a data breach that is likely to result in serious harm, we will:

  1. Contain and assess the incident
  2. Notify affected customers without undue delay
  3. Notify the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988 (Cth)
  4. Take remedial action to prevent recurrence

9. Employee Security Practices

All NextWeb staff undergo background checks appropriate to their role and confidentiality obligations as a condition of employment. Staff receive security and privacy awareness training, including handling of sensitive customer data.

Access to customer data is granted only where necessary for an employee's role and is revoked promptly upon role change or termination.

10. Third-Party & Sub-processor Security

Where we engage third-party service providers (such as payment processors or infrastructure providers), we conduct due diligence on their security practices and require contractual commitments to protect data to a standard consistent with this policy and the Australian Privacy Principles.

11. Compliance

Our security and privacy practices are designed to comply fully with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. We continually review our practices against evolving regulatory expectations and industry standards.

12. Your Role in Security

Security is a shared responsibility. We encourage customers to:

  • Use strong, unique passwords and enable multi-factor authentication
  • Limit user access within your account to what each team member needs
  • Promptly remove access for former employees or contractors
  • Report any suspected security issues to us immediately

13. Reporting a Security Concern

If you discover a security vulnerability or have concerns about the security of our Platform, please contact us immediately. We take all reports seriously and will investigate promptly.

Security Contact

Email: info@nextweb.com.au

Phone: 1800 365 247

14. Changes to This Policy

We continually review and improve our security practices. This policy may be updated from time to time to reflect changes in our infrastructure, processes, or regulatory requirements, and will be posted here with a revised “Last updated” date.

15. Contact Us

NextWeb Pty Ltd

ABN 94 613 674 445

Level 2, Suite 38, Oasis Shopping Centre, 75 Surf Parade, Broadbeach QLD 4218

Email: info@nextweb.com.au

Phone: 1800 365 247