Security and confidentiality

Clear controls. Clear boundaries. No vague guarantees.

Security is designed with each client around its data, systems and risk settings. Jade explains what it controls, what the client controls and what must be agreed together.

Control model

Keep information in the environment you govern.

Client-controlled systems

Work is performed in client-approved cloud applications or through the client’s VPN. Access is provided through named identities.

Authentication and access

MFA, least privilege, role changes and offboarding are set around the client’s identity and security policies.

People and process

Confidentiality expectations, escalation, review and incident reporting are established through employment and engagement processes.

Shared responsibility

Controls only work when ownership is named.

The client owns its information classification, accounts, devices, permissions, technical logging, backup and approval design. Jade manages the Philippine employment relationship and applies the employment, confidentiality and operating requirements agreed for the role.

Agree before onboarding

  • Permitted systems, locations and data handling
  • Device ownership, support and patching
  • MFA, VPN and privileged-access rules
  • Incident contacts and notification pathway
  • Access removal and return of client property
  • Business continuity priorities and recovery steps

Cross-border privacy

Australian and Philippine obligations need to be considered together.

Australian organisations should assess whether APP 8 and other privacy duties apply to overseas disclosure. Accounting and tax practices should also consider Tax Practitioners Board guidance on outsourcing, confidentiality, supervision and competent service.

Jade operates as a Philippine company and is subject to applicable Philippine privacy requirements. The exact controller, processor and disclosure roles depend on the engagement and must be documented; this page is operational information, not legal advice.

No absolute claims

Due diligence should test the real arrangement.

No supplier can promise zero risk. Ask how identities, devices, access, supervision, incident response, continuity and offboarding will work for your specific data and role.

Use the due-diligence checklist →

Questions and answers

Practical details

Where is client data stored?

The operating model is designed for work in client-controlled cloud systems or through client-approved VPN access. Local storage and transfer rules must be agreed for each engagement; Jade does not make a universal data-residency guarantee.

Who provides devices and security software?

The client provides or specifies devices, software, licences, identities and security requirements. The final arrangement is documented before onboarding.

Does Jade guarantee uninterrupted service?

No. Business continuity arrangements are agreed with each client based on roles, location, systems and recovery needs. No control eliminates all incidents or disruption.

Next step

Bring your security requirements into the role brief.

We will map the proposed access, device and operating controls with your team before onboarding.

Start the conversation