Regional cloud deployment
CostrixIQ is designed for supported Australian, European and United States deployment regions, with customer accounts provisioned close to the organisation.
Request a Demo Enterprise & Security
CostrixIQ combines regional cloud deployment, customer-level data isolation, managed access and recovery controls to support commercial teams from opportunity to contract.
Security, residency and access requirements can be discussed for each organisation.
Customer account allocated to a supported regionA clear security foundation
CostrixIQ is designed to protect the commercial information behind live opportunities and projects while giving organisations a practical way to manage identity, residency and data lifecycle requirements.
CostrixIQ is designed for supported Australian, European and United States deployment regions, with customer accounts provisioned close to the organisation.
A separate database is provisioned for each customer, strengthening isolation rather than relying solely on shared-table separation.
Corporate single sign-on, identity-provider MFA and role-based permissions help organisations apply access policies consistently.
Hourly encrypted backups, a 90-day backup retention cycle and monthly restoration testing support a disciplined recovery process.
Data residency
Customers are provisioned in the closest supported region. Core customer data is intended to remain within its allocated region unless another arrangement is specifically agreed.
The architecture is designed to distribute database services across multiple facilities within an operating region, reducing dependence on a single datacentre.
Customer data isolation
CostrixIQ is designed around a database-per-customer architecture. Each customer environment uses a separate database, strengthening data isolation while the platform continues to deliver one consistent enterprise service.
Customer data is separated at the database level rather than relying only on shared-table separation.
Application servicesIdentity and access
CostrixIQ supports enterprise identity controls so access can align with the way an organisation already manages its people, policies and responsibilities.
Support for commonly used corporate identity providers and standards helps users access CostrixIQ through established organisational controls.
For SSO users, MFA and sign-in policies can be enforced through the organisation's identity provider.
Role-based access helps organisations control which users can see and manage relevant platform capabilities and information.
SSO sessions follow identity-provider controls, while standard accounts operate within managed application session policies.
Protection and recovery
Security is supported through layered transport, storage, backup and restoration controls, with production monitoring designed to provide ongoing operational visibility.
Data ownership and lifecycle
CostrixIQ is designed to give customers practical control over their information throughout the relationship and when service ends.
Customer data remains the customer's data.
Customers can export or delete their information, with assistance available where required.
Active customer data is scheduled for deletion within 30 days after service ends, while residual encrypted backups follow the established backup retention cycle.
Specific retention, export, deletion and residency commitments are confirmed in applicable customer documentation.
Operational confidence
The production control set is built around ongoing monitoring, audit logging and structured operational review. Detailed responses can be provided during enterprise assessment.
Infrastructure and service monitoring support visibility across the operating environment.
Audit logging is included in the production launch control set to support traceability of security-relevant activity.
Security, residency, integration and service requirements can be addressed as part of customer due diligence.
Discuss your requirements
Every organisation has different procurement, identity and data requirements. We can discuss the architecture, relevant controls and implementation pathway for your team.
This page provides a general overview only. Specific security, availability, residency and service commitments are confirmed in applicable customer documentation.