Security Update
1. Introduction
MyCareerMatch Recruit is a secure, cloud-based student engagement and enrolment platform that connects future students to courses and careers aligned with their personal strengths. The system is hosted on Amazon Web Services (AWS) in Sydney, Australia (ap-southeast-2 region). This document outlines the platform’s approach to information security, data protection, and compliance with recognised standards such as SOC 2 and ISO/IEC 27001.
2. Security Objectives
Our information security practices are designed to ensure the confidentiality, integrity, and availability of all client and user data. The key objectives are:
- Protect personal information from unauthorised access, use, or disclosure.
- Maintain system resilience and uptime to support continuous service delivery.
- Ensure transparency, accountability, and alignment with privacy and data protection regulations.
3. Hosting Environment & Infrastructure
MyCareerMatch Recruit operates on the AWS Cloud, leveraging its global infrastructure and certified compliance framework. AWS is independently audited and maintains compliance with multiple international standards including:
- SOC 1, SOC 2, and SOC 3 (Type II)
- ISO/IEC 27001, 27017, 27018
- PCI DSS Level 1
- CSA STAR Certification
AWS provides end-to-end encryption, role-based access controls, and physical security at all data centres. Further details on AWS compliance are available at https://aws.amazon.com/compliance/.
4. Data Protection & Privacy
- Encryption: All data in transit is encrypted using TLS 1.2/1.3, and all stored data is encrypted with AES-256.
- Data Isolation: Each client instance is logically separated to prevent cross-tenant access.
- Data Locality: All user and client data is stored and processed within Australian AWS data centres.
- Backups: Daily incremental and weekly full backups are maintained for disaster recovery.
- Retention & Deletion: MyCareerMatch Recruit stores user data for a period of 21 days after report generation. This retention window allows users adequate time to download and save their personal report. After this period, all user records are automatically and permanently deleted from the system in accordance with our data minimisation and privacy policies.
- Report Delivery Options: On completion of the quiz, users can choose how to receive their personalised report. Reports are either emailed directly to the user or, if preferred, users may download the report instantly without providing an email address. This option reduces the storage and transmission of personal data and further enhances overall information security.
MyCareerMatch complies with the Australian Privacy Principles (APP 1–13) and is designed in accordance with the General Data Protection Regulation (GDPR) for clients outside Australia.
5. Access Control & Authentication
- Access to the platform is restricted to authorised personnel using multi-factor authentication (MFA).
- Role-Based Access Control (RBAC) ensures users only access data relevant to their role.
- Administrative access is logged, monitored, and reviewed periodically.
- Passwords follow NIST and OWASP security recommendations.
6. Vulnerability Management
MyCareerMatch Recruit employs continuous monitoring and regular security assessments to identify and mitigate potential vulnerabilities:
- Automated vulnerability scans on all production assets.
- Monthly patching and update schedule for application and infrastructure layers.
- Incident response plan defining roles, escalation paths, and notification procedures.
7. Application Security
- Secure coding practices follow the OWASP Top 10 guidelines.
- Web application firewalls (WAF) protect against injection, XSS, and DDoS attacks.
- API endpoints are authenticated and rate-limited.
- Audit logs are maintained for all critical actions.
8. Compliance Alignment
While MyCareerMatch Pty Ltd has not yet undertaken formal SOC 2 or ISO/IEC 27001 certification, the company operates within the principles of these frameworks:
- SOC 2 Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
- ISO/IEC 27001 Controls: Information security policy, access control, cryptography, operational security, supplier relationships, and compliance.
We leverage AWS’s independently verified SOC 2 Type II and ISO 27001 certifications to inherit infrastructure-level controls.
9. Business Continuity & Disaster Recovery
- Business Continuity Plan reviewed annually.
- Replicated systems across multiple availability zones within AWS Sydney.
- Recovery Time Objective (RTO): 4 hours.
- Recovery Point Objective (RPO): 30 minutes.
10. Third-Party Providers & Sub-Processors
MyCareerMatch uses a small number of trusted sub-processors, including:
- AWS (Amazon Web Services) – Cloud hosting and infrastructure.
- SendGrid – Transactional email delivery (TLS encrypted).
- Stripe / PayPal – Payment processing (PCI DSS Level 1 compliant).
All third-party providers undergo security due diligence and are compliant with international data protection standards.
11. Incident Management
Incidents are managed through a defined process:
- Detection and logging.
- Impact assessment.
- Containment and mitigation.
- Notification to affected parties (if applicable).
- Post-incident review and corrective actions.
12. Statement of Alignment
MyCareerMatch Pty Ltd maintains a security and privacy framework aligned with the SOC 2 Trust Service Criteria and ISO/IEC 27001 standards. Although not yet formally certified, all operational and technical controls reflect the intent of these frameworks and leverage AWS’s certified infrastructure to ensure the highest levels of protection and compliance.
13. Contact
For security or compliance enquiries:
Email: nathan@mycareermatchrecruit.com
Website: www.mycareermatchrecruit.com