Data Protection & Security

    At Cassandra Research, safeguarding your data isn't just a feature — it's the foundation of our architecture.

    Zero-Log Architecture

    All user activity is processed in volatile RAM — never written to disk, stored in databases, or logged in retrievable archives.

    Privacy by Design

    Security is embedded into every layer of our platform from the ground up, not bolted on as an afterthought.

    Enterprise-Grade Encryption

    All data in transit is protected with TLS 1.3 encryption, and data at rest uses AES-256 encryption standards.

    Architectural Anonymity

    Our infrastructure ensures that no personally identifiable information is retained after session completion.

    Regulatory Compliance

    Fully compliant with GDPR, CCPA, and Australia's Privacy Act 1988 across all service divisions.

    Sovereign Data Handling

    Data processing respects jurisdictional boundaries with region-aware infrastructure deployment.

    Our Security Framework

    Cassandra Research operates on a 'Privacy by Design' and 'Zero-Log' engineering principle. All user queries and activity are processed exclusively in volatile RAM and are never written to persistent storage, logged in databases, or retained in retrievable archives. This provides architectural anonymity that meets and exceeds global privacy standards.

    Encryption Standards

    We employ multi-layered encryption across our entire infrastructure:

    • Data in Transit: All communications are encrypted using TLS 1.3, the latest transport layer security protocol.
    • Data at Rest: Any temporarily cached data uses AES-256 encryption, the same standard used by financial institutions and government agencies.
    • Key Management: Encryption keys are rotated regularly and managed through secure, isolated key management infrastructure.
    • API Security: All API endpoints are authenticated and rate-limited to prevent unauthorised access.

    Compliance & Certifications

    Our platform is designed to comply with the following regulatory frameworks:

    • Australia's Privacy Act 1988: Full compliance with the Australian Privacy Principles (APPs) governing the handling of personal information.
    • GDPR (General Data Protection Regulation): Adherence to EU data protection standards for any data processed from European users.
    • CCPA (California Consumer Privacy Act): Compliance with California's consumer privacy rights and data protection requirements.
    • ISO 27001 Framework: Our security practices are aligned with ISO 27001 information security management standards.

    Access Controls

    We enforce strict access controls across our organisation:

    • Role-Based Access: Team members only access data necessary for their specific function.
    • Multi-Factor Authentication: All internal systems require multi-factor authentication for access.
    • Audit Trails: Internal access is logged and regularly audited to ensure compliance.
    • Principle of Least Privilege: Every system and user is granted the minimum level of access required.

    Incident Response

    In the unlikely event of a security incident, our response protocol includes:

    • Immediate containment and assessment within 1 hour of detection
    • Notification to affected parties within 72 hours as required by GDPR and the Privacy Act 1988
    • Full root cause analysis and remediation
    • Post-incident review and security hardening

    Your Rights

    Under applicable data protection laws, you have the right to:

    • Access personal data we hold about you
    • Request correction of inaccurate data
    • Request deletion of your personal data
    • Object to or restrict processing of your data
    • Data portability — receive your data in a structured, machine-readable format
    • Withdraw consent at any time where processing is based on consent

    Contact Our Data Protection Team

    For any data protection enquiries, requests, or concerns:

    Cassandra Research Pty Ltd

    ABN 70 659 258 367

    Email: service@cassandraresearch.com

    This Data Protection & Security policy was last updated on April 9, 2025. We regularly review and update our security practices to address emerging threats and regulatory changes.