Last updated: 22 July 2026
We are a security firm, so we hold ourselves to the standard we test others against. Data is handled on Australian infrastructure, access is granted on a least-privilege basis, and personnel are bound by confidentiality.
Personal and engagement data is encrypted in transit. Stored data is held under access control on Australian infrastructure and encrypted at rest.
Testing is run in isolated, fully logged environments. We collect only the evidence needed to demonstrate a finding, retain it for the period recorded in the engagement agreement, and destroy it onshore when that period ends. Evidence never leaves Australia.
Access to client data is limited to the people working on your engagement. Everyone involved is bound by written confidentiality obligations, and access is removed when it is no longer needed.
If a data breach affecting your information occurs, we will act promptly to contain it, notify affected clients, and meet our obligations under the Notifiable Data Breaches scheme in the Privacy Act 1988 (Cth).
Our practices are aligned to the Australian Privacy Principles, the principles of APRA CPS 234, and ISO 27001 controls. Where we use the word aligned, it means aligned to, not independently certified against, unless a specific certificate is provided to you in writing.
Security enquiries: redteam@provok.com.au, FIMALU Pty Ltd T/As Evolaition, Level 7, 570 St Kilda Road, Melbourne VIC 3004.
← Back to home