Security

At Xestro, we understand the critical importance of data security in healthcare. As the only large Australian practice management software provider with ISO 27001 certification covering both our company and our SaaS platform, we maintain the highest standards of information security.

ISO 27001 Certification

Our entire Information Security Management System (ISMS) is independently audited and certified to ISO 27001 standards. This certification covers our full service spectrum, from software development to customer support. It ensures we meet and exceed international best practices for security, providing you with a robust, secure platform for your practice management needs.

Regular External Testing

We don't just claim to be secure – we prove it. Our systems undergo frequent security assessments, including rigorous external penetration testing. This proactive approach helps us identify and address potential vulnerabilities before they can be exploited, ensuring our defences remain strong against evolving cyber threats.

Exceptional Uptime

Reliability is a cornerstone of security. We consistently achieve over 99.9% uptime year on year, ensuring your practice runs smoothly without interruption. Our robust infrastructure and redundant systems work tirelessly to keep your data accessible when you need it, while maintaining the highest security standards.

Multi-Layered Data Protection

Your data's safety is paramount. We employ a comprehensive, multi-tiered backup strategy that includes point-in-time recovery, automated snapshots, and geographically diverse off-site backups. This approach ensures that your critical practice data is protected against a wide range of potential incidents.

Data Encryption and Storage

We take no chances with your sensitive information. All data within our system is protected using strong, industry-standard encryption algorithms, both when it's stored (at rest) and when it's being transmitted (in transit). This ensures that your data remains confidential and integral at all times. Importantly, all your data is stored securely within Australia, ensuring compliance with local data sovereignty requirements.

Advanced Authentication

Security starts with access control. We offer robust two-factor authentication to add an extra layer of security to user logins. Additionally, our unique device authentication system verifies not just users, but also the hardware devices accessing our system, providing an additional safeguard against unauthorised access.

Compliance

We understand the regulatory landscape of healthcare in Australia. Our systems and processes are designed to adhere strictly to the Australian Privacy Principles (APPs). This commitment ensures that your practice and patient data is handled with the utmost care and in full compliance with Australian privacy laws.

Ongoing Vigilance

Security is not a one-time effort – it's an ongoing commitment. As part of our ISO 27001 mandated ISMS, we conduct regular security audits and assessments. Our comprehensive security calendar ensures that we're constantly monitoring, testing, and improving our security measures to stay ahead of potential threats.

Information Security Statement

Information security is critical to the success and ongoing viability of Xestro.

Our core security principle is to ensure the confidentiality, integrity, and availability of the information we manage on behalf of our customers and business partners, as well as our own information.

As such, we aim to provide assurance to internal and external stakeholders together with other interested parties of the security and privacy of their information entrusted to Xestro, whether in storage, processing, or transmission.

To realise this principle, we are committed to the following security objectives:

  • Maintaining a high level of security awareness amongst all our staff by emphasizing that everyone has responsibility and accountability for all protection of information.
  • Implementing effective security controls to assist in maintaining the reputation of the organisation and ensure adequate protection of information.
  • Operating a certified Information Security Management System in accordance with the ISO/IEC 27001 information security standard to provide assurance to customers of good security practices and support the continual improvement of the system.
  • Promoting a disciplined approach to the identification and management of information security risks across the business.
  • Monitoring our systems and investigating all detected security breaches and weaknesses.
  • Ensuring all legal, regulatory, and contractual requirements are met.

This Policy applies to:

  • All full time, part time, temporary or casual Xestro employees.
  • All contractors engaged by Xestro.
  • All suppliers providing services to Xestro.
  • Any other third parties with a valid reason to access Xestro information.

Rest assured, your practice's data is protected by best-in-class security measures, allowing you to focus on what matters most – patient care.
Choose Xestro for peace of mind in an increasingly complex digital healthcare landscape.