Security & data handling

Access only what the work requires.

Pacifica's preferred model is to work inside client-approved systems with defined permissions, approval limits and offboarding controls rather than creating unnecessary copies of business data. Australian-based support does not mean unrestricted access: permissions remain role-based and limited to what the engagement requires.

01

Least-privilege access

Access is scoped to the systems and permissions reasonably required for the engagement. Clients remain able to change or revoke access.

02

Named access

Where supported by the client's systems, named user accounts and role-based permissions are preferred over shared credentials.

03

MFA where available

Multi-factor authentication should be enabled where the client's platform supports it and the engagement requires user access.

04

Client-approved platforms

Data should remain in the client's approved accounting, engineering, project, document or marketing systems wherever practical.

05

Approval boundaries

Financial, publishing, technical and operational authority is documented. High-impact actions remain subject to agreed client approval.

06

Controlled offboarding

At the end of an engagement, access should be revoked or transferred, client data returned or handled as agreed, and outstanding responsibilities documented.

Cross-border delivery

Be explicit about where people access data.

Australian support team: Our Australian-based team can provide operating context, oversight and escalation support. Access to client systems or information is still governed by the same least-privilege, named-access and approval controls described on this page.

Pacifica's service capability includes personnel in Hong Kong and the Philippines. Australian clients that provide personal information to an offshore service provider may have their own obligations concerning cross-border disclosure, security and contractual controls. Pacifica therefore expects data location, access and privacy requirements to be identified during onboarding.

Where the client is subject to the Australian Privacy Principles or another privacy regime, the client remains responsible for determining its own legal obligations. Pacifica can incorporate agreed handling restrictions and contractual controls into the service design.

Data mapIdentify the systems, categories of data and countries from which data may be accessed.
Access mapIdentify who needs access, the permission level and the business purpose.
Retention & returnAgree what is retained, where it remains, and what happens at disengagement.
Incident escalationDefine who must be told if there is suspected unauthorised access, loss or disclosure.
Confidentiality

Commercial information is treated as client information.

Engagement-specific confidentiality, privacy, intellectual-property, security and data-processing requirements should be recorded in the relevant proposal, services agreement or data-processing terms. Pacifica does not claim a security certification unless one is actually held and current.

Before access is granted

  • Confirm the data and systems required.
  • Set least-privilege permissions.
  • Set approval and transaction limits.
  • Confirm confidentiality and privacy requirements.
  • Confirm any prohibited storage or transfer locations.
  • Record the offboarding and access-revocation process.
Discuss security requirements →