Information Security Policy
Purpose
This policy outlines the security principles and operational controls used by Redequip Pty Ltd (The Change Gym) to protect diagnostic, coaching, and organisational data across all platforms, including The Change Gym website, IRVEY, and RCC Intelligence workflows.
Security Principles
Redequip operates under the following principles:
Least Privilege — Access is granted only to authorised personnel and only to the extent required.
Data Sovereignty — Diagnostic, coaching, and organisational data is stored exclusively on servers located in Australia.
Defence in Depth — Multiple layers of security controls protect systems and data.
Secure by Default — All platforms enforce HTTPS, modern TLS, and hardened security headers.
Technical Controls
Redequip maintains:
Enforced HTTPS across all services
Modern TLS configurations (A/A+ grade)
Hardened security headers (CSP, HSTS, X‑Frame‑Options, X‑Content‑Type‑Options, Referrer‑Policy, Permissions‑Policy)
Regular vulnerability scanning
Secure authentication and session management
Server‑side validation for all form submissions
Restricted administrative access
Secure backups stored within Australia
Operational Controls
Access to diagnostic and coaching data is limited to authorised staff.
Administrative actions are logged and monitored.
Changes to production systems follow controlled deployment processes.
Third‑party providers are vetted for security posture and contractual confidentiality.
Monitoring and Review
Security controls are reviewed periodically and updated to reflect:
emerging threats
improved practices
government expectations
platform enhancements