Provok Book a scoping call
Legal · documentation

Security & Data.

Last updated: 22 July 2026

Our approach

We are a security firm, so we hold ourselves to the standard we test others against. Data is handled on Australian infrastructure, access is granted on a least-privilege basis, and personnel are bound by confidentiality.

Data in transit and at rest

Personal and engagement data is encrypted in transit. Stored data is held under access control on Australian infrastructure and encrypted at rest.

Engagement evidence

Testing is run in isolated, fully logged environments. We collect only the evidence needed to demonstrate a finding, retain it for the period recorded in the engagement agreement, and destroy it onshore when that period ends. Evidence never leaves Australia.

Access and personnel

Access to client data is limited to the people working on your engagement. Everyone involved is bound by written confidentiality obligations, and access is removed when it is no longer needed.

Incident handling

If a data breach affecting your information occurs, we will act promptly to contain it, notify affected clients, and meet our obligations under the Notifiable Data Breaches scheme in the Privacy Act 1988 (Cth).

Alignment

Our practices are aligned to the Australian Privacy Principles, the principles of APRA CPS 234, and ISO 27001 controls. Where we use the word aligned, it means aligned to, not independently certified against, unless a specific certificate is provided to you in writing.

Contact

Security enquiries: redteam@provok.com.au, FIMALU Pty Ltd T/As Evolaition, Level 7, 570 St Kilda Road, Melbourne VIC 3004.

← Back to home