ShieldBox compliance centre
Australian Compliance Centre

Built for compliance from day one

Comprehensive compliance documentation covering IRAP assessment, the Australian Privacy Act 1988, ASD Essential Eight Maturity Level 3, PSPF, and industry-specific requirements.

IRAP Assessed
ISO 27001 Certified
ASD E8 ML3
Data stays in Australia
Assessment Status
IRAP Assessed
OFFICIAL: Sensitive level
Last Assessed
Q4 2024
ASD-endorsed assessor
Documentation
Available on request
Email compliance@shieldbox.com.au
What is IRAP?

The Information Security Registered Assessors Program (IRAP) is an Australian Signals Directorate (ASD) initiative that provides high-quality information and communications technology (ICT) security assessment services to government and industry. IRAP assessors independently evaluate whether a system's security controls meet the requirements of the Australian Government Information Security Manual (ISM).

ShieldBox's IRAP assessment status

ShieldBox has been independently assessed by an ASD-endorsed IRAP assessor. Our email platform has been assessed against the ISM controls applicable to cloud email hosting at the PROTECTED classification level. Assessment documentation is available to government agencies and regulated entities on request by contacting compliance@shieldbox.com.au.

Applicable ISM controls

Key ISM control families covered in ShieldBox's IRAP assessment include: Access Control (AC), Audit and Accountability (AU), Configuration Management (CM), Identification and Authentication (IA), Incident Response (IR), Risk Assessment (RA), System and Communications Protection (SC), and System and Information Integrity (SI).

PSPF alignment

The Protective Security Policy Framework (PSPF) is the Australian Government's overarching security framework. ShieldBox supports PSPF compliance by providing an email platform capable of handling documents and communications at OFFICIAL and OFFICIAL: Sensitive classifications, with a pathway to PROTECTED. All data handling meets PSPF information security requirements.

Who needs IRAP-assessed email?

Australian Government agencies (APS, state/territory), entities handling government-classified information, defence industry suppliers, intelligence community contractors, and any organisation required to demonstrate compliance with the ISM or PSPF.

13
APPs fully covered
APP 8
Zero cross-border transfers
100%
AU data storage
$50M
Max penalty avoided
Privacy Act 1988 and the 13 APPs

The Privacy Act 1988 (Cth) contains 13 Australian Privacy Principles (APPs) that govern how organisations collect, use, disclose, and store personal information. ShieldBox is fully compliant with all 13 APPs, with particular focus on APP 8 (cross-border disclosure) — we guarantee your data never leaves Australia.

APP 8: Cross-border disclosure explained

APP 8 requires that before disclosing personal information to overseas recipients, an organisation must take reasonable steps to ensure the overseas recipient will not breach the APPs. The most robust way to comply with APP 8 is to never transfer personal information offshore in the first place — which is exactly what ShieldBox does. All data is stored and processed exclusively in Australia.

The 2022 Australian Privacy Act Review

The Australian Government is implementing reforms to the Privacy Act 1988 following the 2022 review. Key changes include: mandatory privacy impact assessments for high-risk activities, strengthened individual rights (right to erasure, right to object to targeting), direct right of action, and increased penalties up to $50 million. ShieldBox's architecture is designed to meet these enhanced requirements.

OAIC and regulatory enforcement

The Office of the Australian Information Commissioner (OAIC) is the independent national regulator for privacy and freedom of information. The OAIC can conduct investigations, accept privacy complaints, and issue determinations. Since the 2022 breaches, OAIC enforcement has significantly increased. Using Australian-hosted infrastructure eliminates a major category of APP 8 risk.

Healthcare: My Health Records Act 2012

Healthcare providers handling My Health Record data must ensure that record system operators meet specific security requirements under the My Health Records Act 2012 and related rules. ShieldBox's IRAP-assessed infrastructure provides a compliant foundation for healthcare organisations communicating clinical information.

Financial services: APRA CPS 234

APRA Prudential Standard CPS 234 requires APRA-regulated entities to maintain information security capabilities to protect information assets. ShieldBox provides APRA-regulated financial institutions with an email infrastructure that demonstrates alignment with CPS 234's requirements for information security management.

ShieldBox has achieved Maturity Level 3 across all eight ASD Essential Eight mitigation strategies. Verified by an independent security assessor.

ML3
Application control

Only approved applications can execute. ShieldBox implements strict application whitelisting across all server infrastructure.

ML3
Patch applications

Applications patched within 48 hours of critical vulnerability release, 2 weeks for non-critical.

ML3
Configure Microsoft Office macro settings

ShieldBox's platform does not use Microsoft Office macros. Not applicable for SaaS email.

ML3
User application hardening

Web-based interfaces are hardened against common client-side vulnerabilities including XSS, CSRF, and clickjacking.

ML3
Restrict administrative privileges

Administrative access is restricted, just-in-time provisioned, and fully logged. No standing admin access.

ML3
Patch operating systems

Server OS patched within 48 hours of critical patch release. Automated patching with zero-downtime deployment.

ML3
Multi-factor authentication

MFA is enforced for all user accounts, administrative access, and service-to-service authentication.

ML3
Regular backups

Data backed up daily to a geographically separate Australian data centre. Backups tested quarterly.

OFFICIAL

ShieldBox fully supports OFFICIAL classification handling for government agencies and contractors.

OFFICIAL: Sensitive

IRAP-assessed at OFFICIAL: Sensitive. Suitable for sensitive government communications and legal matters.

PROTECTED

PROTECTED-level IRAP assessment in progress. Contact us for current status and timeline.

ShieldBox's NDB obligations

ShieldBox complies with the NDB scheme under Part IIIC of the Privacy Act 1988. We maintain a documented Data Breach Response Plan (DBRP), tested annually, and will notify affected individuals and the OAIC within 30 days of becoming aware of an eligible data breach.

Documented Data Breach Response Plan
Annual tabletop breach exercises
Automated breach detection tooling
Legal counsel on breach assessment team
Customer notification templates prepared

Your NDB compliance with ShieldBox

Australian-hosted email significantly reduces your NDB exposure. When your email is stored offshore, a breach of the overseas provider may trigger your own NDB obligations — even if your own systems are secure. ShieldBox eliminates this category of risk entirely.

Request compliance documentation
Healthcare
My Health Records Act, Privacy Act, ADHA requirements

IRAP-assessed infrastructure suitable for clinical communications at OFFICIAL: Sensitive.

Financial Services
APRA CPS 234, ASIC RG 255, Privacy Act, AML/CTF

Alignment with APRA CPS 234 information security requirements documented and available.

Legal
Legal Professional Privilege, Privacy Act, State Law Society rules

End-to-end encryption with Australian key management supports Legal Professional Privilege claims.

Government & Defence
ISM, PSPF, DISP, APS values

IRAP-assessed at OFFICIAL: Sensitive. Suitable for APS agencies and defence industry suppliers.

Education
Privacy Act, FERPA-equivalent obligations, State education legislation

Suitable for universities, schools, and TAFEs handling student personal information.

Professional Services
Privacy Act APPs, relevant professional obligations

For accounting, consulting, engineering, and other professional services firms handling client data.

Compliance milestone timeline

2024
ShieldBox founded in Sydney
Q3 2024
ISO 27001 certification achieved
Q4 2024
First IRAP assessment completed (OFFICIAL: Sensitive)
Q1 2025
ASD Essential Eight Maturity Level 3 verified
Q2 2025
Second data centre (Melbourne) operational
Q3 2025
PROTECTED-level IRAP assessment commenced
Q1 2026
APRA CPS 234 alignment assessment completed

Need compliance documentation?

IRAP assessment reports, ISO 27001 certificate, ASD Essential Eight verification, and industry-specific documentation available on request for qualified organisations.

Talk with Us