Trust and security
Answers your procurement review can check.
iyarn is built for schools, health services and research teams who put sensitive check-in data on the platform. This page is the posture behind that trust: what we're certified for, where data lives, and how it's kept separate, stated so you can verify each claim.
Security questions or a vendor questionnaire? hello@iyarn.com.au
Certification
ISO 27001
Information security
Independently audited, certified, current
Certification
ISO 27001, the audit we sit for, every year.
ISO 27001 is the international standard for information security management. Certification means an independent auditor has examined how we handle risk, access, change and incidents across the whole business, not just the codebase, and keeps examining it for the life of the certificate. Quote certificate 8726-2966-01 in your paperwork; we're happy to supply the certificate itself.
What ISO 27001 examines
Where your data lives
Data residency
Australian owned. Australian hosted.
iyarn is an Australian company and the platform runs on Australian infrastructure. Check-in data stays onshore, which keeps your data sovereignty questions short.
Tenant isolation
Your organisation's data lives in its own lane.
Every organisation on iyarn is a separate tenant. Isolation is enforced in code, and our continuous integration suite includes tests that fail the build if any change would let one tenant's data reach another. It's not a policy on a page, it's a gate every release passes through.
One platform, separate lanes
Isolation enforced in code, tested on every build.
Every change runs the gauntlet.
No code reaches production without passing automated security gates in continuous integration.
Every commit is scanned so credentials never ship in code.
SAST reviews each change for vulnerable patterns before merge.
Third-party packages are checked against known vulnerabilities.
The build fails if a change could cross tenant boundaries.
Your data, your call
Export everything, any time.
AI features are optional, and off by default for schools. They only run if you turn them on.
Data ownership
It's your data. We act like it.
Everything your organisation puts into iyarn comes back out on request: structured, timestamped exports whenever you want them, a live Power BI feed if you run your own reporting, and API connections for enterprise partnerships. No exit fee, no lock-in. And features that process data with AI are opt-in choices you control, never silent defaults.
The paperwork
Privacy and terms, in full.
The complete privacy policy and terms of use live on their own pages, and the security pack answers the standard vendor questionnaire in one document. Your legal team can read them without asking us first.
Security pack
Download the security pack.
One document for your procurement or IT review: certification, data residency, tenant isolation, sub-processors and more, with the ISO 27001 certificate included. Enter your email and it downloads straight away.
Certificate 8726-2966-01, current to 26 April 2029.
Talk to us
Put us through your process.
Send a vendor questionnaire, ask the hard questions, or book a security review. It's a conversation we're set up for.
Prefer email? hello@iyarn.com.au