Capabilities

Multi-layered security for regulated industries.

Security decisions start long before penetration testing.

Architecture, access controls, data handling, code review and incident response all shape how much risk a system carries into production. Our ISO 27001 processes give those decisions a documented framework throughout delivery.


Why security matters

In 2025, the OAIC recorded 1,205 data breach notifications - the highest total since mandatory reporting began in 2018.

Certification gives us a structured way to answer three important questions: what data you hold, who can reach it, and what happens when something goes wrong.

Read our Digital Risk Report to find out more

1,205

Data breaches recorded across Australia in 2025

28%

Of users would permanently stop using an app after a data breach

41%

Say storing data in Australia is a make-or-break decision


Independent ISO certification audit materials

ISO certifications in practice

ISO 27001 and 9001 are the operating system for how Airteam runs, from how we write code to how we hire. We call it the Airteam Management System, and it's the same framework whether you're a new client or a new starter.

That means a documented incident response plan, mandatory security training and police checks for every team member, secure code repositories with mandatory peer review before any commit, and a defined process for provisioning and deprovisioning system access the moment someone joins or leaves a project.


Government and industry partnership documentation

Government & industry partnerships

Airteam is an approved supplier on the NSW Government ICT Services Scheme and the Australian Government's Digital Marketplace and BuyICT panels, and the principal digital partner of the Members Health Fund Alliance, representing 25 not-for-profit health funds. We're also an approved supplier for organisations including Westpac and Transport for NSW.

Most of these panels require ongoing evidence of our certifications and controls, with reassessment on a defined schedule.


Security in the real world

Software built for organisations where reliability matters.

  • DHF - mobile

    Doctors’ Health Fund

    Migrating Doctors' Health Fund off a monolithic legacy codebase to a serverless architecture on AWS reduced their attack surface and gave their team direct oversight of a platform that now underpins DMS for health funds across Australia.

    View case study
  • Screens from the Latrobe health care app

    Digital Member Services (DMS)

    Our own white-label platform for private health insurers is built to the same standard we hold ourselves to: APRA CPS 234 alignment, enforced MFA, WCAG 2.1 AA accessibility, and OWASP-aligned application testing - because a security page means nothing if our own product doesn't meet it.

Have a few more questions?

Check out some of our frequently asked questions below or get in touch with us to find out more.

Get in touch
What does ISO 27001 certification mean for my project?

ISO 27001 gives us a documented framework for managing information security throughout your project. It covers how we control access, manage risk, respond to incidents, train our team and review our own security practices. Our certification is independently audited, and embedded into how Airteam operates.

Who can access our systems and where is our data stored?

Access is limited to the people who need it for their role on the project, with documented processes for approving, reviewing and removing access. Our team is 100% Australian-based, so your project isn’t handed to an offshore development team. Where application data is stored depends on the requirements and architecture of your system. If Australian data residency is required, we can design the hosting and infrastructure around that constraint.

What happens if there is a security incident?

Our ISO 27001 management system includes a documented incident response process covering identification, escalation, containment and review. If an incident affects your system, the priority is to understand the impact, contain the issue and communicate clearly with the people responsible for managing the response. We then review what happened and feed those findings back into our security controls.

How is security built into your development process?

Security starts before code is written. We consider architecture, data handling, access controls and potential failure points during design and development, with mandatory peer review before code is merged. Testing and vulnerability management continue through delivery, so security isn’t left to a penetration test immediately before launch.

How do you test software for security vulnerabilities?

We test applications against OWASP-aligned security standards throughout delivery and track identified issues through the same process as other development work. The level of testing depends on the system’s risk profile and regulatory requirements, and can include independent penetration testing where appropriate.

Can you meet our organisation’s security and compliance requirements?

We’ll review your security, privacy and regulatory requirements before deciding how the system should be designed and delivered. We’ve worked in regulated environments including healthcare, private health insurance, finance and government, but requirements differ between organisations. Where a control, certification or architecture requirement falls outside our standard approach, we’ll identify that early rather than assume compliance.