Cloud SaaS platform launching soonRegister your interest

Enterprise & Security

Confidence in every commercial decision. Enterprise foundations behind it.

CostrixIQ combines regional cloud deployment, customer-level data isolation, managed access and recovery controls to support commercial teams from opportunity to contract.

Security, residency and access requirements can be discussed for each organisation.

A clear security foundation

Enterprise assurance begins with clear control.

CostrixIQ is designed to protect the commercial information behind live opportunities and projects while giving organisations a practical way to manage identity, residency and data lifecycle requirements.

01

Regional cloud deployment

CostrixIQ is designed for supported Australian, European and United States deployment regions, with customer accounts provisioned close to the organisation.

02

Customer data isolation

A separate database is provisioned for each customer, strengthening isolation rather than relying solely on shared-table separation.

03

Identity and permissions

Corporate single sign-on, identity-provider MFA and role-based permissions help organisations apply access policies consistently.

04

Recovery readiness

Hourly encrypted backups, a 90-day backup retention cycle and monthly restoration testing support a disciplined recovery process.

Data residency

Regional by design. Allocated with purpose.

Customers are provisioned in the closest supported region. Core customer data is intended to remain within its allocated region unless another arrangement is specifically agreed.

Resilience within the region

The architecture is designed to distribute database services across multiple facilities within an operating region, reducing dependence on a single datacentre.

Customer data isolation

A shared platform. A separate data boundary.

CostrixIQ is designed around a database-per-customer architecture. Each customer environment uses a separate database, strengthening data isolation while the platform continues to deliver one consistent enterprise service.

Isolation by design

Customer data is separated at the database level rather than relying only on shared-table separation.

Identity and access

Access follows the organisation, not a separate set of rules.

CostrixIQ supports enterprise identity controls so access can align with the way an organisation already manages its people, policies and responsibilities.

01

Corporate SSO

Support for commonly used corporate identity providers and standards helps users access CostrixIQ through established organisational controls.

02

Multi-factor authentication

For SSO users, MFA and sign-in policies can be enforced through the organisation's identity provider.

03

Roles and permissions

Role-based access helps organisations control which users can see and manage relevant platform capabilities and information.

04

Managed sessions

SSO sessions follow identity-provider controls, while standard accounts operate within managed application session policies.

Protection and recovery

Protected in use. Recoverable by design.

Security is supported through layered transport, storage, backup and restoration controls, with production monitoring designed to provide ongoing operational visibility.

Data ownership and lifecycle

Your data remains your data.

CostrixIQ is designed to give customers practical control over their information throughout the relationship and when service ends.

01

Ownership

Customer data remains the customer's data.

02

Export and control

Customers can export or delete their information, with assistance available where required.

03

End of service

Active customer data is scheduled for deletion within 30 days after service ends, while residual encrypted backups follow the established backup retention cycle.

Specific retention, export, deletion and residency commitments are confirmed in applicable customer documentation.

Operational confidence

Designed for production visibility and accountable operation.

The production control set is built around ongoing monitoring, audit logging and structured operational review. Detailed responses can be provided during enterprise assessment.

Operational visibilityGoogle Cloud monitoring

Infrastructure and service monitoring support visibility across the operating environment.

TraceabilityProduction audit logging

Audit logging is included in the production launch control set to support traceability of security-relevant activity.

Enterprise reviewRequirements discussed directly

Security, residency, integration and service requirements can be addressed as part of customer due diligence.

Discuss your requirements

Bring your security, residency and integration questions into the conversation.

Every organisation has different procurement, identity and data requirements. We can discuss the architecture, relevant controls and implementation pathway for your team.

This page provides a general overview only. Specific security, availability, residency and service commitments are confirmed in applicable customer documentation.