Client-controlled systems
Work is performed in client-approved cloud applications or through the client’s VPN. Access is provided through named identities.
Security and confidentiality
Security is designed with each client around its data, systems and risk settings. Jade explains what it controls, what the client controls and what must be agreed together.
Control model
Work is performed in client-approved cloud applications or through the client’s VPN. Access is provided through named identities.
MFA, least privilege, role changes and offboarding are set around the client’s identity and security policies.
Confidentiality expectations, escalation, review and incident reporting are established through employment and engagement processes.
Shared responsibility
The client owns its information classification, accounts, devices, permissions, technical logging, backup and approval design. Jade manages the Philippine employment relationship and applies the employment, confidentiality and operating requirements agreed for the role.
Cross-border privacy
Australian organisations should assess whether APP 8 and other privacy duties apply to overseas disclosure. Accounting and tax practices should also consider Tax Practitioners Board guidance on outsourcing, confidentiality, supervision and competent service.
Jade operates as a Philippine company and is subject to applicable Philippine privacy requirements. The exact controller, processor and disclosure roles depend on the engagement and must be documented; this page is operational information, not legal advice.
No absolute claims
No supplier can promise zero risk. Ask how identities, devices, access, supervision, incident response, continuity and offboarding will work for your specific data and role.
Use the due-diligence checklist →Questions and answers
The operating model is designed for work in client-controlled cloud systems or through client-approved VPN access. Local storage and transfer rules must be agreed for each engagement; Jade does not make a universal data-residency guarantee.
The client provides or specifies devices, software, licences, identities and security requirements. The final arrangement is documented before onboarding.
No. Business continuity arrangements are agreed with each client based on roles, location, systems and recovery needs. No control eliminates all incidents or disruption.
Next step
We will map the proposed access, device and operating controls with your team before onboarding.