ShieldBox
ShieldBox compliance centre
Australian Compliance Centre

Built for compliance from day one

Comprehensive compliance documentation covering ISO 27001:2022 certification, the Australian Privacy Act 1988, ASD Essential Eight Maturity Level 3, PSPF, and industry-specific requirements.

ASD Essential Eight ML3
ISO 27001 Aligned
ASD E8 ML3
Data stays in Australia
ISO 27001 Certification — In Progress

ShieldBox is built to ISO/IEC 27001:2022 standards and our ISMS is fully operational. Formal third-party certification by an accredited body is actively underway, with the certification audit scheduled for Q4 2026. Documentation of our alignment is available on request at compliance@shieldbox.com.au.

Official Documentation

Compliance Reports & Documents

All documents current as of Apr 2026
6
Active documents
100%
Compliance score
7 yrs
Audit retention
0
Critical findings
ASD Essential Eight Assessment SummaryCurrentGovernment Security
April 202642 pages2.1 MB
Privacy Act Compliance ReportCurrentPrivacy & Data
April 202638 pages1.8 MB
Email Audit Log — Q1 2026ArchivedAudit Trail
Jan – Mar 2026156 pages4.7 MB
Data Sovereignty StatementCurrentData Sovereignty
January 202612 pages0.6 MB
ISO 27001:2022 Alignment StatementCurrentInternational Standard
March 20268 pages0.5 MB
ASD Essential Eight — ML3 VerificationCurrentASD Framework
February 202628 pages1.4 MB

Need the full verified compliance package?

Government agencies, enterprise procurement teams, and regulated entities can request the complete documentation package including original signed certificates and assessor reports.

Request package
Assessment Status
ASD Essential Eight ML3
All 8 strategies at Maturity Level 3
Last Assessed
Q4 2024
ASD-endorsed assessor
Documentation
Available on request
Email compliance@shieldbox.com.au
What is the ASD Essential Eight?

The ASD Essential Eight is a set of baseline mitigation strategies developed by the Australian Signals Directorate (ASD) to help organisations protect against cyber threats. It covers application control, patching, macro settings, user application hardening, admin privilege restriction, multi-factor authentication, regular backups, and OS patching — each assessed at Maturity Levels 0–3.

ShieldBox's ASD Essential Eight status

ShieldBox has achieved ASD Essential Eight Maturity Level 3 across all eight mitigation strategies. Our email platform has been assessed against ISM controls applicable to cloud email hosting. Assessment documentation is available to government agencies and regulated entities on request by contacting compliance@shieldbox.com.au.

Applicable ISM controls

Key ISM control families covered in ShieldBox's ASD Essential Eight assessment include: Access Control (AC), Audit and Accountability (AU), Configuration Management (CM), Identification and Authentication (IA), Incident Response (IR), Risk Assessment (RA), System and Communications Protection (SC), and System and Information Integrity (SI).

PSPF alignment

The Protective Security Policy Framework (PSPF) is the Australian Government's overarching security framework. ShieldBox supports PSPF compliance by providing an email platform capable of handling documents and communications at OFFICIAL and OFFICIAL: Sensitive classifications, with a pathway to PROTECTED. All data handling meets PSPF information security requirements.

Who needs ASD Essential Eight aligned email?

Australian Government agencies (APS, state/territory), entities handling government-classified information, defence industry suppliers, intelligence community contractors, and any organisation required to demonstrate compliance with the ISM or PSPF.

13
APPs fully covered
APP 8
Zero cross-border transfers
100%
AU data storage
$50M
Max penalty avoided
Privacy Act 1988 and the 13 APPs

The Privacy Act 1988 (Cth) contains 13 Australian Privacy Principles (APPs) that govern how organisations collect, use, disclose, and store personal information. ShieldBox is fully compliant with all 13 APPs, with particular focus on APP 8 (cross-border disclosure) — we guarantee your data never leaves Australia.

APP 8: Cross-border disclosure explained

APP 8 requires that before disclosing personal information to overseas recipients, an organisation must take reasonable steps to ensure the overseas recipient will not breach the APPs. The most robust way to comply with APP 8 is to never transfer personal information offshore in the first place — which is exactly what ShieldBox does. All data is stored and processed exclusively in Australia.

The 2022 Australian Privacy Act Review

The Australian Government is implementing reforms to the Privacy Act 1988 following the 2022 review. Key changes include: mandatory privacy impact assessments for high-risk activities, strengthened individual rights (right to erasure, right to object to targeting), direct right of action, and increased penalties up to $50 million. ShieldBox's architecture is designed to meet these enhanced requirements.

OAIC and regulatory enforcement

The Office of the Australian Information Commissioner (OAIC) is the independent national regulator for privacy and freedom of information. The OAIC can conduct investigations, accept privacy complaints, and issue determinations. Since the 2022 breaches, OAIC enforcement has significantly increased. Using Australian-hosted infrastructure eliminates a major category of APP 8 risk.

Healthcare: My Health Records Act 2012

Healthcare providers handling My Health Record data must ensure that record system operators meet specific security requirements under the My Health Records Act 2012 and related rules. ShieldBox's ISO 27001-aligned, Australian-sovereign infrastructure provides a compliant foundation for healthcare organisations communicating clinical information.

Financial services: APRA CPS 234

APRA Prudential Standard CPS 234 requires APRA-regulated entities to maintain information security capabilities to protect information assets. ShieldBox provides APRA-regulated financial institutions with an email infrastructure that demonstrates alignment with CPS 234's requirements for information security management.

ASD Framework — Eight Strategies

Maturity Level 3 — All Eight Strategies

ShieldBox has achieved Maturity Level 3 across all eight ASD Essential Eight mitigation strategies — the highest achievable level. Verified by an independent security assessor.

ML3
Application control

Only approved applications can execute. ShieldBox implements strict application whitelisting across all server infrastructure.

ML3
Patch applications

Applications patched within 48 hours of critical vulnerability release, 2 weeks for non-critical.

ML3
Configure Microsoft Office macro settings

ShieldBox's platform does not use Microsoft Office macros. Not applicable for SaaS email.

ML3
User application hardening

Web-based interfaces are hardened against common client-side vulnerabilities including XSS, CSRF, and clickjacking.

ML3
Restrict administrative privileges

Administrative access is restricted, just-in-time provisioned, and fully logged. No standing admin access.

ML3
Patch operating systems

Server OS patched within 48 hours of critical patch release. Automated patching with zero-downtime deployment.

ML3
Multi-factor authentication

MFA is enforced for all user accounts, administrative access, and service-to-service authentication.

ML3
Regular backups

Data backed up daily to a geographically separate Australian data centre. Backups tested quarterly.

OFFICIAL

ShieldBox fully supports OFFICIAL classification handling for government agencies and contractors.

Maturity Level 3

ASD Essential Eight Maturity Level 3 achieved across all eight mitigation strategies. Suitable for sensitive government communications and legal matters.

ISO 27001:2022

Built to ISO 27001:2022 standards. Internationally recognised information security management framework. Formal certification in progress.

ShieldBox's NDB obligations

ShieldBox complies with the NDB scheme under Part IIIC of the Privacy Act 1988. We maintain a documented Data Breach Response Plan (DBRP), tested annually, and will notify affected individuals and the OAIC within 30 days of becoming aware of an eligible data breach.

Documented Data Breach Response Plan
Annual tabletop breach exercises
Automated breach detection tooling
Legal counsel on breach assessment team
Customer notification templates prepared

Your NDB compliance with ShieldBox

Australian-hosted email significantly reduces your NDB exposure. When your email is stored offshore, a breach of the overseas provider may trigger your own NDB obligations — even if your own systems are secure. ShieldBox eliminates this category of risk entirely.

Request compliance documentation
Healthcare
My Health Records Act, Privacy Act, ADHA requirements

ISO 27001 aligned infrastructure suitable for clinical communications and ADHA requirements.

Financial Services
APRA CPS 234, ASIC RG 255, Privacy Act, AML/CTF

Alignment with APRA CPS 234 information security requirements documented and available.

Legal
Legal Professional Privilege, Privacy Act, State Law Society rules

End-to-end encryption with Australian key management supports Legal Professional Privilege claims.

Government & Defence
ISM, PSPF, DISP, APS values

ASD Essential Eight Maturity Level 3. Suitable for APS agencies and defence industry suppliers.

Education
Privacy Act, FERPA-equivalent obligations, State education legislation

Suitable for universities, schools, and TAFEs handling student personal information.

Professional Services
Privacy Act APPs, relevant professional obligations

For accounting, consulting, engineering, and other professional services firms handling client data.

Compliance milestone timeline

Q1 2026
ShieldBox founded in Sydney
Q1 2026
ISO 27001:2022 ISMS framework implemented
Q2 2026
ASD Essential Eight Maturity Level 3 assessment completed
Q2 2026
Second data centre (Melbourne) operational
Q3 2026
APRA CPS 234 alignment assessment in progress
Q4 2026
ISO 27001:2022 formal certification audit planned

Need compliance documentation?

ISO 27001 alignment documentation, ASD Essential Eight Maturity Level 3 verification, and industry-specific documentation available on request for qualified organisations.

Talk with Us