This page summarises the controls set out in the RedSeed IT Security Policy, which is approved by our board and reviewed at least once a year.
Our approach
Managers use RedSeed to work through real situations with real people on their team. That means we hold notes and conversation records that would never go in an email, so protecting them is a condition of doing business rather than a feature we add on.
Our security programme is governed by an IT Security Policy approved by the RedSeed board. It covers every system, application, data store and network we own or operate, including those run on our behalf by third parties, and any system that connects to or affects ours. We review it at least annually and update it as threats change.
The approach is deliberately pragmatic. We prioritise the controls that remove the most risk rather than chasing every measure available, and we treat security as the responsibility of every person at RedSeed and of every vendor who works with us.
We keep a detailed inventory of all hardware that can store or process data, from cloud servers to laptops and network equipment, alongside an inventory of all licensed software and SaaS applications. Software has to be authorised and actively supported before it goes near our systems.
Hosting and infrastructure
Servers and other critical equipment are hosted in secure datacentres, or in secured areas where equipment is on site. On top of that:
- Servers and workstations run host-based firewalls.
- Internet connections sit behind a firewall configured to deny inbound traffic by default.
- Systems, software and network infrastructure are administered only over encrypted channels such as SSH or HTTPS.
- Default passwords are replaced with strong, unique passwords whenever we bring new systems or equipment into service.
- Wireless networks use encryption and a strong password.
- Screens lock automatically after a period without use.
Encryption
- Data sent over the internet is encrypted using TLS 1.2 or above.
- Login is encrypted everywhere, on our own network and across the internet.
- Confidential and personal data is encrypted at rest.
- Customer environments are separated from one another through tenant isolation.
- Laptops are configured with disk encryption.
- Backups are encrypted.
- We avoid sending files containing personal information about multiple people by email.
Access control and authentication
Access to data is granted on a need-to-know basis, so people hold the least privilege that lets them do their job.
- Remote access requires multi-factor authentication, through single sign-on wherever possible, and two-factor authentication is available on platform accounts.
- Remote access is available only to authorised people, uses strong encryption, and is permitted only from approved locations.
- Everyone has an individual, identifiable account. Shared accounts are avoided, and the rare exception has to be approved by management.
- Administrators use a separate account for everyday work such as email and browsing, and an administrative account only for administrative tasks.
- Service accounts are individual, use unique strong passwords, and cannot be used remotely.
- An account lockout policy blocks password guessing and brute force attempts.
- We provide a company password manager, passwords are never reused across systems or accounts, and stored credentials are encrypted and protected against unauthorised access, deletion or deciphering.
- Accounts are disabled within two days of someone leaving RedSeed, a contractor’s engagement ending, or a vendor’s staff member no longer needing access.
- Permissions are reviewed whenever someone changes role, and at least once a year regardless.
Data handling and retention
We run a documented data management process covering sensitivity, ownership, handling, retention limits and disposal.
- Data is classified by confidentiality where it is corporate data or intellectual property, and by sensitivity where it is personal data.
- We maintain a data inventory recording which systems hold confidential and personal data.
- Data is retained according to what the business genuinely needs and what regulation requires, including the New Zealand Privacy Act 2020.
- Access to systems containing personal data is logged.
- When workstations, laptops, servers, USB drives or other media are disposed of, all data and software is rendered unreadable first.
Manager confidentiality
Inside RedSeed, access to your data follows the same need-to-know rule as everything else. Only the people who need it in order to support you can reach it, access to systems holding personal data is logged, and everyone here is trained on their obligations under our privacy policy and the Privacy Act 2020.
Inside the product, coaching conversations are held tightly:
- Meeting agendas, notes and action items are visible only to the two people in the meeting.
- A note marked private is visible only to the person who wrote it, and is excluded from the inputs used for coaching quality scoring.
- Customer environments are kept separate from one another through tenant isolation.
- RedSeed staff do not browse meeting content. A small number of staff can reach it through internal tools for support and troubleshooting, and that access is logged.
Coaching records stay visible to the other meeting participant, including after someone leaves the organisation. Your organisation sets how long those records are kept. The full picture of who can see what is in our privacy policy.
Monitoring and logging
- Security alerts, including those raised by Google Workspace and our anti-malware tooling, are reviewed at least daily.
- Access to systems containing personal data is logged.
- Use of our IT systems is monitored.
Backups and recovery
- Servers and systems, including cloud systems, are backed up at least daily.
- Backups are retained for at least 30 days.
- Backups are encrypted, and access to the backup solution is protected by multi-factor authentication.
- Backups are not directly reachable from inside production systems, which limits the risk of malicious corruption or deletion.
- Recent backups are immutable, meaning they cannot be altered or deleted by anyone, including an administrator. This is specifically to defeat the ransomware tactic of destroying backups before demanding payment.
Vulnerability management
- Critical security patches are applied to servers, PCs, firewalls and third-party applications within 30 days of release.
- Zero-day vulnerabilities that pose a critical risk are patched within 48 hours.
- Approved anti-malware software runs on all workstations, laptops, mobiles and servers.
- Any data or software brought into our network is scanned for malware by approved, up-to-date tooling.
- All company email, inbound and outbound, is scanned for malware and malicious links and put through further security checks.
- We use measures including DMARC to stop criminals sending email that appears to come from a RedSeed address.
Secure development
RedSeed is our own product, so how we build it is part of how we secure it.
- Security requirements are defined during the design and specification phase of every software project, focused on data security and system resilience.
- Risk assessments run at project inception so threats are identified and planned for early.
- We follow secure coding guidelines endorsed by recognised bodies such as OWASP, and apply coding standards enforced by both static and dynamic analysis tooling.
- Vulnerability scans and penetration testing are part of standard testing before any release.
- Critical applications are audited by third parties to validate our controls.
- Our deployment process is designed so only intended features and configuration reach production.
- A change management process assesses the security implications of every software modification.
People and training
- Everyone at RedSeed completes cyber security awareness training at least annually.
- We brief staff on new security risks and any extra steps they need to take as those risks emerge.
- All staff are made aware of our privacy policy and their obligations under the Privacy Act 2020.
Sub-processors
Outsourcing part of a system does not hand over responsibility for it. Cloud platforms generally operate a shared responsibility model, and we plan for our half of it.
- Third parties, including SaaS vendors, are classified by the risk they would pose to us if they suffered a service disruption or a data breach.
- We carry out a security assessment before selecting any vendor or cloud application that could affect the confidentiality, integrity or availability of our systems and data.
- Third parties are recorded in a register covering contact details, classification and assessment status.
- Third-party contracts include security clauses.
- Data sovereignty is assessed wherever personal data will be stored or processed.
The providers we rely on cover hosting and storage, calendar and video conferencing, transcription, AI generation, email delivery, analytics and customer support tooling. A current list of the service providers that process platform data, and where each one processes it, is available from your account team or from us on request.
Incident response
- We maintain a documented incident response plan, and the people who would run it understand it.
- Every incident produces a report setting out the cause, the impact, the immediate action taken, further action required, and recommendations for reducing the likelihood and impact of a repeat.
- The response plan is updated on the back of those recommendations.
- We run incident response exercises at least annually.
If a privacy breach happens that is likely to cause serious harm, we notify the people affected and the relevant regulator, as required by the New Zealand Privacy Act 2020 and the Australian Notifiable Data Breaches scheme. Where the affected data belongs to your organisation, we notify your organisation so that it can meet its own obligations.
Certifications and compliance
We operate under the New Zealand Privacy Act 2020, and our data retention, handling and disposal practices are built around it. Our IT Security Policy is approved by the RedSeed board and reviewed at least annually, and it is the standard the controls on this page are measured against.
SOC 2 is in progress. We are working towards SOC 2 and the programme is underway. We will publish the outcome here once it completes. Until then, the controls on this page are what we hold ourselves to, and we are happy to walk a prospective customer’s security team through them.
Reporting a security issue
If you believe you have found a vulnerability in RedSeed, or you have seen something that looks like a security problem, please tell us and we will investigate. Include enough detail for us to reproduce what you saw, and please give us a reasonable window to fix the issue before sharing it publicly.
Email support@redseed.com and mark your message as a security report. For anything about your personal information rather than a vulnerability, our Privacy Officer is reachable at privacy@redseed.com.