Data Protection & Security
At Cassandra Research, safeguarding your data isn't just a feature — it's the foundation of our architecture.
Zero-Log Architecture
All user activity is processed in volatile RAM — never written to disk, stored in databases, or logged in retrievable archives.
Privacy by Design
Security is embedded into every layer of our platform from the ground up, not bolted on as an afterthought.
Enterprise-Grade Encryption
All data in transit is protected with TLS 1.3 encryption, and data at rest uses AES-256 encryption standards.
Architectural Anonymity
Our infrastructure ensures that no personally identifiable information is retained after session completion.
Regulatory Compliance
Fully compliant with GDPR, CCPA, and Australia's Privacy Act 1988 across all service divisions.
Sovereign Data Handling
Data processing respects jurisdictional boundaries with region-aware infrastructure deployment.
Our Security Framework
Cassandra Research operates on a 'Privacy by Design' and 'Zero-Log' engineering principle. All user queries and activity are processed exclusively in volatile RAM and are never written to persistent storage, logged in databases, or retained in retrievable archives. This provides architectural anonymity that meets and exceeds global privacy standards.
Encryption Standards
We employ multi-layered encryption across our entire infrastructure:
- Data in Transit: All communications are encrypted using TLS 1.3, the latest transport layer security protocol.
- Data at Rest: Any temporarily cached data uses AES-256 encryption, the same standard used by financial institutions and government agencies.
- Key Management: Encryption keys are rotated regularly and managed through secure, isolated key management infrastructure.
- API Security: All API endpoints are authenticated and rate-limited to prevent unauthorised access.
Compliance & Certifications
Our platform is designed to comply with the following regulatory frameworks:
- Australia's Privacy Act 1988: Full compliance with the Australian Privacy Principles (APPs) governing the handling of personal information.
- GDPR (General Data Protection Regulation): Adherence to EU data protection standards for any data processed from European users.
- CCPA (California Consumer Privacy Act): Compliance with California's consumer privacy rights and data protection requirements.
- ISO 27001 Framework: Our security practices are aligned with ISO 27001 information security management standards.
Access Controls
We enforce strict access controls across our organisation:
- Role-Based Access: Team members only access data necessary for their specific function.
- Multi-Factor Authentication: All internal systems require multi-factor authentication for access.
- Audit Trails: Internal access is logged and regularly audited to ensure compliance.
- Principle of Least Privilege: Every system and user is granted the minimum level of access required.
Incident Response
In the unlikely event of a security incident, our response protocol includes:
- Immediate containment and assessment within 1 hour of detection
- Notification to affected parties within 72 hours as required by GDPR and the Privacy Act 1988
- Full root cause analysis and remediation
- Post-incident review and security hardening
Your Rights
Under applicable data protection laws, you have the right to:
- Access personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your personal data
- Object to or restrict processing of your data
- Data portability — receive your data in a structured, machine-readable format
- Withdraw consent at any time where processing is based on consent
Contact Our Data Protection Team
For any data protection enquiries, requests, or concerns:
This Data Protection & Security policy was last updated on April 9, 2025. We regularly review and update our security practices to address emerging threats and regulatory changes.