Information Security Policy

Purpose

This policy outlines the security principles and operational controls used by Redequip Pty Ltd (The Change Gym) to protect diagnostic, coaching, and organisational data across all platforms, including The Change Gym website, IRVEY, and RCC Intelligence workflows.

Security Principles

Redequip operates under the following principles:

  • Least Privilege — Access is granted only to authorised personnel and only to the extent required.

  • Data Sovereignty — Diagnostic, coaching, and organisational data is stored exclusively on servers located in Australia.

  • Defence in Depth — Multiple layers of security controls protect systems and data.

  • Secure by Default — All platforms enforce HTTPS, modern TLS, and hardened security headers.

Technical Controls

Redequip maintains:

  • Enforced HTTPS across all services

  • Modern TLS configurations (A/A+ grade)

  • Hardened security headers (CSP, HSTS, X‑Frame‑Options, X‑Content‑Type‑Options, Referrer‑Policy, Permissions‑Policy)

  • Regular vulnerability scanning

  • Secure authentication and session management

  • Server‑side validation for all form submissions

  • Restricted administrative access

  • Secure backups stored within Australia

Operational Controls

  • Access to diagnostic and coaching data is limited to authorised staff.

  • Administrative actions are logged and monitored.

  • Changes to production systems follow controlled deployment processes.

  • Third‑party providers are vetted for security posture and contractual confidentiality.

Monitoring and Review

Security controls are reviewed periodically and updated to reflect:

  • emerging threats

  • improved practices

  • government expectations

  • platform enhancements