Trust and security

Answers your procurement review can check.

iyarn is built for schools, health services and research teams who put sensitive check-in data on the platform. This page is the posture behind that trust: what we're certified for, where data lives, and how it's kept separate, stated so you can verify each claim.

Security questions or a vendor questionnaire? hello@iyarn.com.au

Certification

ISO 27001

Information security

Certificate8726-2966-01
Held byiyarn
Current to26 April 2029

Independently audited, certified, current

Certification

ISO 27001, the audit we sit for, every year.

ISO 27001 is the international standard for information security management. Certification means an independent auditor has examined how we handle risk, access, change and incidents across the whole business, not just the codebase, and keeps examining it for the life of the certificate. Quote certificate 8726-2966-01 in your paperwork; we're happy to supply the certificate itself.

What ISO 27001 examines

Risk assessment and treatmentin the standard
Access control and authenticationin the standard
Secure development and changein the standard
Incident responsein the standard
Supplier and data handlingin the standard

Where your data lives

Data residency

Australian owned. Australian hosted.

iyarn is an Australian company and the platform runs on Australian infrastructure. Check-in data stays onshore, which keeps your data sovereignty questions short.

Tenant isolation

Your organisation's data lives in its own lane.

Every organisation on iyarn is a separate tenant. Isolation is enforced in code, and our continuous integration suite includes tests that fail the build if any change would let one tenant's data reach another. It's not a policy on a page, it's a gate every release passes through.

One platform, separate lanes

Isolation enforced in code, tested on every build.

Every change runs the gauntlet.

No code reaches production without passing automated security gates in continuous integration.

01Secret scanning

Every commit is scanned so credentials never ship in code.

02Static analysis

SAST reviews each change for vulnerable patterns before merge.

03Dependency scanning

Third-party packages are checked against known vulnerabilities.

04Tenant isolation tests

The build fails if a change could cross tenant boundaries.

Your data, your call

Export everything, any time.

PDFCSVExcelPower BI feed

AI features are optional, and off by default for schools. They only run if you turn them on.

Data ownership

It's your data. We act like it.

Everything your organisation puts into iyarn comes back out on request: structured, timestamped exports whenever you want them, a live Power BI feed if you run your own reporting, and API connections for enterprise partnerships. No exit fee, no lock-in. And features that process data with AI are opt-in choices you control, never silent defaults.

The paperwork

Privacy and terms, in full.

The complete privacy policy and terms of use live on their own pages, and the security pack answers the standard vendor questionnaire in one document. Your legal team can read them without asking us first.

Security pack

Download the security pack.

One document for your procurement or IT review: certification, data residency, tenant isolation, sub-processors and more, with the ISO 27001 certificate included. Enter your email and it downloads straight away.

Certificate 8726-2966-01, current to 26 April 2029.

Instant download. We may follow up about your review. See our privacy policy.

Talk to us

Put us through your process.

Send a vendor questionnaire, ask the hard questions, or book a security review. It's a conversation we're set up for.

Prefer email? hello@iyarn.com.au

We reply from hello@iyarn.com.au. By sending this you agree to our privacy policy.