CHRISTCHURCH

Security

Our Commitment to Security

At Argos, security is at the core of everything we do. As a provider of financial lending software to banks and financial institutions, we understand the importance of safeguarding sensitive financial data. Our managed service offering, hosted in Microsoft Azure, is designed with best-in-class security controls to ensure the confidentiality, integrity, and availability of customer data.

We are in the process of obtaining SOC 2 Type II certification, reinforcing our commitment to industry-recognized security standards.

Security Measures We Take

Enterprise-Grade Infrastructure & Cloud Security

* Our managed service runs on Microsoft Azure, leveraging Azure’s built-in security features, including network isolation, DDoS protection, and private connectivity options

* All customer data is encrypted at rest and in transit using industry-standard AES-256 encryption and TLS 1.2+ protocols

* We use role-based access control (RBAC) and least privilege access principles to restrict access to critical systems

Data Protection & Compliance

* We maintain robust backup and disaster recovery policies, ensuring your data is protected against accidental loss or system failures

* We adhere to financial industry best practices and are working towards SOC 2 Type II certification, demonstrating our commitment to rigorous security controls

Access Control & Authentication

* Multi-Factor Authentication (MFA) is enforced for all internal administrative access

* Customers can integrate with Entra ID for single sign-on (SSO) and identity federation

Secure Development Practices

* Security is embedded throughout our software development lifecycle (SDLC), with regular code reviews and penetration testing by our customers

* We follow secure coding guidelines to protect against common vulnerabilities such as SQL injection

* All deployments go through comprehensive testing and review processes before being released to production

Employee Security & Awareness

* All team members undergo security training to ensure awareness of threats like phishing and social engineering

* We enforce strict internal security policies, including endpoint protection and secure access to company resources

* Our team follows least privilege principles, ensuring only authorised team members can access sensitive data

Incident Response

In the event of a security incident, we have a dedicated incident response process to quickly investigate, contain, and remediate any issues.

Your Security, Our Priority

We take our responsibility to protect your data seriously. Whether you’re using our financial lending software as a managed service or self-hosting, you can trust that security remains our top priority.

If you have any security-related questions, feel free to contact us at securityandcompliance@argos.co.nz