Built for regulatedfinancial institutions
Single-tenant, sovereign-hosted, ISO 27001 and SOC 2 Type II certified, aligned to APRA CPS 230 and 234, with continuous evidence capture for audit and regulatory examinations.
Compliance & certifications
Audited where it matters, aligned where it should be
Independent attestations and prudential alignment, not marketing claims. Every certification, every alignment statement, evidenced and current.
ISO 27001:2022
ISO 27001
Independently certified information security management system covering all Cloudcase platform operations, hosting, and data handling.
Status
Certified · current
Last audit
June 2026
Control families · audit-ready evidence
Encryption
AES-256 at rest, TLS 1.3 in transit. Customer-managed keys available.
Identity & access
SSO, MFA, role-based and attribute-based access. SoD encoded in workflow.
Logging & evidence
Immutable audit trail per case. Continuous evidence for regulator examinations.
Resilience
Multi-AZ active-active, tested failover, RPO ≤ 5m, RTO ≤ 4h, exit-plan ready.
Trust posture
Single-tenant by default, sovereign by design
Cloudcase is a managed service provider (MSP): every customer runs on their own dedicated tenant, with no shared databases, no shared runtime, no shared blast radius.
Dedicated database, dedicated runtime, dedicated keys
Blast radius isolated to your tenant
You control the rollout cadence of platform updates
Australian data residency enforced at the infrastructure layer
Audit and evidence shaped to your regulator's expectations
No cross-customer data paths, ever
Get the trust pack
Architecture diagrams, SOC 2 report (under NDA), CPS 230 alignment statement, and the full controls matrix.