Security at Commission Intelligence
Yoursoftware Pty Ltd is an Australian software company building Commission Intelligence and related tools for mortgage broking professionals. This page describes our security posture honestly: what we have today, what we're working toward, and how to talk to us if you find a problem.
How to report a security issue
Email security@yoursoftware.com.au. Use the same address even if the issue is in a third-party tool we use.
We commit to:
- Acknowledge your report within 5 business days
- Triage within 10 business days
- Coordinate disclosure with you
- Credit you publicly (or keep your name out of it — your choice)
Our machine-readable security.txt follows RFC 9116.
Coordinated vulnerability disclosure policy
In scope
yoursoftware.com.auand all sub-domains- Any production YourCSM domain
- Any Commission Intelligence production domain
- Any Yoursoftware-operated mobile or desktop application
Out of scope
- Email security best-practice advice without a working exploit
- Outdated TLS cipher reports without a working downgrade
- Findings from automated scanners without a working proof-of-concept
- Social engineering of staff, brokers, family members, or third parties
- Physical attacks on offices
- Denial-of-service / brute-force / spam testing
Safe harbour
Good-faith research consistent with this policy is authorised. We will not pursue civil or criminal action against researchers who follow it. Activity outside this policy is subject to applicable law.
Disclosure window
Please give us a 90-day disclosure window before publishing details. We may request an extension for complex vulnerabilities — and we'll keep you in the loop on progress.
Controls we operate today
| Domain | Control | Status |
|---|---|---|
| Identity | Phishing-resistant MFA (passkey / YubiKey) for all staff accessing RESTRICTED data | In rollout Wk1-4 |
| Identity | Two-person rule for super-admin accounts on Workspace, MyCRM, Netlify, Anthropic Console, 1Password | Wk1 secondary admin onboarded |
| Endpoint | Full-disk encryption (BitLocker) on every device touching client data | Verified per device in Wk5 audit |
| Endpoint | EDR with managed response on every device | Active (N-able via MSP) |
DMARC p=reject + DKIM + SPF | Wk3 | |
| BEC-proof settlement process (callback verification + two-person rule + change-of-details auto-suspend) | Wk3 | |
| Application | SAST + dependency scan + secret scan + IaC scan on every PR | Wk4 |
| Application | Field-level encryption for RESTRICTED data at rest (envelope encryption with per-tenant DEKs once multi-tenant) | v2 builds Wk5-Mo12 |
| AI | Tiered AI use policy (T1-T4) covering DPA + zero-retention + region + HITL | Live |
| AI | AI agent identity store covering every autonomous AI agent we operate | Live |
| AI | Per-call cost cap + per-day cost cap enforced at code boundary | Live (Anthropic SDK wrapper) |
| AI | Prompt-injection defence (input sanitisation + XML tag boundary + injection score + system-prompt protocol) | Helper live; full deploy Wk2 |
| Backup | Workspace third-party backup with 12-month retention + tested restore | Wk7 |
| Logging | SIEM with detection rules for impossible-travel + auto-forward + bulk export + new OAuth grant | Mo 3 (Wazuh) |
| Vendor | DPA on every vendor processing RESTRICTED data; sub-processor list public | Wk6 audit |
Certifications + frameworks
Today
- None issued yet. We are 22 staff. This is honest. Below is what's in flight.
In progress
- CSA STAR Level 1 (CAIQ) — self-attestation, target Mo 2
- SOC 2 Type I — target Mo 9, with AU audit firm
- SOC 2 Type II — target Mo 18, 12-month observation window
- ISO 27001:2022 — target Mo 15-18
- ISO 27017 / 27018 / 27701 — Mo 21-24 add-ons
Frameworks we map to today
NIST CSF 2.0 (with Govern as umbrella) · OWASP ASVS L2 · OWASP LLM Top 10 (2025) · MITRE ATT&CK + ATLAS · CIS Benchmarks · NIST AI RMF 1.0 · ISO/IEC 42001 · APRA CPS 230 alignment (we are not APRA-regulated but our aggregator partner is in scope) · Australian Privacy Principles · OAIC Notifiable Data Breaches · NCCP · ASIC RG 234
Sub-processors
Vendors that may process customer data on behalf of Yoursoftware Pty Ltd or our products. Current list:
| Vendor | Role | Region | DPA |
|---|---|---|---|
| Anthropic (Claude API) | AI inference for YourCSM extraction + Commission Intelligence AI features | US (contracted-region) | Pending Wk6 audit |
| Voyage AI (now Anthropic) | Embedding model for YourCSM document similarity | US | Pending Wk6 audit |
| Google Workspace | Email + Drive + Calendar + Chat | AU + global | Standard Workspace DPA |
| Netlify | Static hosting + serverless functions for productised applications | US | Standard Netlify DPA |
| 1Password | Credential vault for staff | CA | Standard 1Password Business DPA |
| MyCRM (aggregator CRM platform) | Broker CRM for client, lead, and commission data | AU | Aggregator agreement Wk1 review |
| illion | Bank statement retrieval + categorisation | AU | Pending |
| DocuSign | Document signing for client onboarding | AU | Pending |
| Quickli | Serviceability calculation | AU | Pending |
| Supabase | Database + auth + storage for portal v2 | AU (region selection) | Pending — pre-v2 launch |
Acknowledgements
We thank the following researchers for responsible disclosure:
- (None yet — be the first.)
Additional resources
- Request our customer DPA template
- Request our pre-completed SIG Lite + CAIQ v4 (NDA may apply)
- Request access to our Trust Portal (NDA required; opens Mo 3)
- OAIC Notifiable Data Breaches — where to read about your rights as an affected individual
Commission Intelligence is a product of Yoursoftware Pty Ltd. This page describes our security posture. It is not a contract. Specific commitments to customers are in the customer DPA and master service agreement.