Cloud & Server Security

Cloud & Server Security

Cloud & Servers Security

Cloud & Servers Security Statement

Visual Link IT runs production infrastructure in Australian-region data centres with defense-in-depth security controls.

Hosting

Production environments run on AWS Sydney (ap-southeast-2) and Azure Australia East (australiaeast). On-prem and private-cloud deployments available for regulated industries.

Encryption

In transit: TLS 1.2+ enforced, HSTS, certificate pinning where applicable. At rest: AES-256 encryption on all persistent storage, including database, file storage and backups.

Access controls

Multi-factor authentication required for all administrative access. Role-based access controls (principle of least privilege). Audit logs for all admin actions, retained 1 year minimum.

Network & perimeter

Web Application Firewall (AWS WAF / Cloudflare), DDoS protection, rate limiting. Segregated VPCs per environment. No direct database internet exposure.

Vulnerability management

Automated dependency scanning (Dependabot, Snyk). Penetration testing annually by an independent CREST-accredited tester. Critical patches deployed within 48 hours.

Backup & recovery

Daily full backups, hourly incremental. Backups encrypted, retained 30 days minimum. Recovery time objective: 4 hours. Recovery point objective: 1 hour.

Incident response

Documented incident response plan. 24/7 monitoring with alerting on anomalies. Notifiable data breaches reported to OAIC and affected individuals as required by the Privacy Act 1988.

Last updated: 16 May 2026.

Cloud & Server Security

Call us directly
Send an Enquiry