Security

Data Protection & Platform Security

Our Commitment

Common Initiative works with vulnerable populations, including refugees and immigrants who may have fled persecution. We understand that the confidentiality and security of their personal data is not just a regulatory requirement, but a matter of profound physical and psychological safety.

Infrastructure & Encryption

Our web infrastructure is built on modern, secure cloud platforms. We employ the following technical safeguards:

  • Encryption in Transit: All data transmitted between your browser and our servers is encrypted using industry-standard TLS (Transport Layer Security).
  • Encryption at Rest: Sensitive database records, particularly those containing application data and personal circumstances, are encrypted at rest.
  • Secure Authentication: Access to mentor and participant portals requires secure authentication protocols to prevent unauthorized access.

Access Control

Data access within Common Initiative is strictly governed by the principle of least privilege. Only authorized case workers, program managers, and system administrators have access to applicant and participant data, and only to the extent necessary to fulfill their roles (e.g., assessing an application or coordinating essential care).

Data Retention

We retain personal data only for as long as necessary to provide our charitable services or as required by Australian law. When data is no longer needed, it is securely deleted or anonymized.

Reporting Vulnerabilities

If you are a security researcher and have discovered a vulnerability on our platform, please report it immediately to security@commoninitiative.com.au. We appreciate your efforts to keep our community safe.