
Built for compliance from day one
Comprehensive compliance documentation covering IRAP assessment, the Australian Privacy Act 1988, ASD Essential Eight Maturity Level 3, PSPF, and industry-specific requirements.
What is IRAP?
The Information Security Registered Assessors Program (IRAP) is an Australian Signals Directorate (ASD) initiative that provides high-quality information and communications technology (ICT) security assessment services to government and industry. IRAP assessors independently evaluate whether a system's security controls meet the requirements of the Australian Government Information Security Manual (ISM).
ShieldBox's IRAP assessment status
ShieldBox has been independently assessed by an ASD-endorsed IRAP assessor. Our email platform has been assessed against the ISM controls applicable to cloud email hosting at the PROTECTED classification level. Assessment documentation is available to government agencies and regulated entities on request by contacting compliance@shieldbox.com.au.
Applicable ISM controls
Key ISM control families covered in ShieldBox's IRAP assessment include: Access Control (AC), Audit and Accountability (AU), Configuration Management (CM), Identification and Authentication (IA), Incident Response (IR), Risk Assessment (RA), System and Communications Protection (SC), and System and Information Integrity (SI).
PSPF alignment
The Protective Security Policy Framework (PSPF) is the Australian Government's overarching security framework. ShieldBox supports PSPF compliance by providing an email platform capable of handling documents and communications at OFFICIAL and OFFICIAL: Sensitive classifications, with a pathway to PROTECTED. All data handling meets PSPF information security requirements.
Who needs IRAP-assessed email?
Australian Government agencies (APS, state/territory), entities handling government-classified information, defence industry suppliers, intelligence community contractors, and any organisation required to demonstrate compliance with the ISM or PSPF.
Privacy Act 1988 & Australian Privacy Principles
Privacy Act 1988 and the 13 APPs
The Privacy Act 1988 (Cth) contains 13 Australian Privacy Principles (APPs) that govern how organisations collect, use, disclose, and store personal information. ShieldBox is fully compliant with all 13 APPs, with particular focus on APP 8 (cross-border disclosure) — we guarantee your data never leaves Australia.
APP 8: Cross-border disclosure explained
APP 8 requires that before disclosing personal information to overseas recipients, an organisation must take reasonable steps to ensure the overseas recipient will not breach the APPs. The most robust way to comply with APP 8 is to never transfer personal information offshore in the first place — which is exactly what ShieldBox does. All data is stored and processed exclusively in Australia.
The 2022 Australian Privacy Act Review
The Australian Government is implementing reforms to the Privacy Act 1988 following the 2022 review. Key changes include: mandatory privacy impact assessments for high-risk activities, strengthened individual rights (right to erasure, right to object to targeting), direct right of action, and increased penalties up to $50 million. ShieldBox's architecture is designed to meet these enhanced requirements.
OAIC and regulatory enforcement
The Office of the Australian Information Commissioner (OAIC) is the independent national regulator for privacy and freedom of information. The OAIC can conduct investigations, accept privacy complaints, and issue determinations. Since the 2022 breaches, OAIC enforcement has significantly increased. Using Australian-hosted infrastructure eliminates a major category of APP 8 risk.
Healthcare: My Health Records Act 2012
Healthcare providers handling My Health Record data must ensure that record system operators meet specific security requirements under the My Health Records Act 2012 and related rules. ShieldBox's IRAP-assessed infrastructure provides a compliant foundation for healthcare organisations communicating clinical information.
Financial services: APRA CPS 234
APRA Prudential Standard CPS 234 requires APRA-regulated entities to maintain information security capabilities to protect information assets. ShieldBox provides APRA-regulated financial institutions with an email infrastructure that demonstrates alignment with CPS 234's requirements for information security management.
ASD Essential Eight — Maturity Level 3
ShieldBox has achieved Maturity Level 3 across all eight ASD Essential Eight mitigation strategies. Verified by an independent security assessor.
Only approved applications can execute. ShieldBox implements strict application whitelisting across all server infrastructure.
Applications patched within 48 hours of critical vulnerability release, 2 weeks for non-critical.
ShieldBox's platform does not use Microsoft Office macros. Not applicable for SaaS email.
Web-based interfaces are hardened against common client-side vulnerabilities including XSS, CSRF, and clickjacking.
Administrative access is restricted, just-in-time provisioned, and fully logged. No standing admin access.
Server OS patched within 48 hours of critical patch release. Automated patching with zero-downtime deployment.
MFA is enforced for all user accounts, administrative access, and service-to-service authentication.
Data backed up daily to a geographically separate Australian data centre. Backups tested quarterly.
PSPF — Protective Security Policy Framework
ShieldBox fully supports OFFICIAL classification handling for government agencies and contractors.
IRAP-assessed at OFFICIAL: Sensitive. Suitable for sensitive government communications and legal matters.
PROTECTED-level IRAP assessment in progress. Contact us for current status and timeline.
Notifiable Data Breaches (NDB) Scheme
ShieldBox's NDB obligations
ShieldBox complies with the NDB scheme under Part IIIC of the Privacy Act 1988. We maintain a documented Data Breach Response Plan (DBRP), tested annually, and will notify affected individuals and the OAIC within 30 days of becoming aware of an eligible data breach.
Your NDB compliance with ShieldBox
Australian-hosted email significantly reduces your NDB exposure. When your email is stored offshore, a breach of the overseas provider may trigger your own NDB obligations — even if your own systems are secure. ShieldBox eliminates this category of risk entirely.
Request compliance documentationIndustry-specific compliance
IRAP-assessed infrastructure suitable for clinical communications at OFFICIAL: Sensitive.
Alignment with APRA CPS 234 information security requirements documented and available.
End-to-end encryption with Australian key management supports Legal Professional Privilege claims.
IRAP-assessed at OFFICIAL: Sensitive. Suitable for APS agencies and defence industry suppliers.
Suitable for universities, schools, and TAFEs handling student personal information.
For accounting, consulting, engineering, and other professional services firms handling client data.
Compliance milestone timeline
Need compliance documentation?
IRAP assessment reports, ISO 27001 certificate, ASD Essential Eight verification, and industry-specific documentation available on request for qualified organisations.