Security you can verify, certified for over a decade
Catch-e holds contracts, payroll data and funds movement for hundreds of employers. Protecting that is the job, and Catch-e has held ISO/IEC 27001 certification for over ten years to prove it.
Why ISO 27001 matters in this industry
Certification is not a logo for the footer. In leasing and salary packaging, the data is personal, the money is real and the employers are many. Here is what an independently audited security management system actually protects.
Employee personal information
Novated lease files are dense with PII. Certified controls govern who can access that data, how it is encrypted and how access is reviewed.
Payroll and funds movement
Deduction schedules and disbursements run every pay cycle. Certification enforces change control, segregation of duties and integrity checks.
Multi-employer isolation
One platform, hundreds of employers. Certified controls enforce data separation, role-based access and audit trails between every one of them.
Regulatory alignment
FBT, ATO and privacy law assume tamper-evident records. Certified controls over logging, retention and backups keep the evidence always ready.
ISO/IEC 27001 certified for over 10 years.
Your contracts, payroll data and funds movement run on infrastructure that has held independent security certification for more than a decade, hosted in Australian data centres.
Catch-e holds ISO/IEC 27001:2022 certification, issued by a JASANZ-accredited certification body under certificate number 1833-I-1, available for verification.
Access control, encryption, audit logging and change governance are part of daily operations, not a compliance afterthought.
Independent surveillance audits three times a year keep the certification, and the controls behind it, continuously verified.
27001:2022
How we stay secure
A certificate is the output. This is the work behind it, the practices that run every week of the year, whether or not an auditor is watching.
External audits
An independent, JASANZ-accredited body audits our security management system three times a year, with full recertification every three years.
Internal audits
Between external visits we audit ourselves: internal reviews, risk assessments and corrective actions, each with an owner and a deadline.
Security training
Security awareness training is mandatory for everyone, developers to directors, refreshed continuously, because breaches start with people.
Onshore experts
Security here is a job, not a rotation. Dedicated specialists work in-house, in Australia, across our infrastructure, releases and incidents.
Australian hosting
Your data lives in Australian data centres and stays onshore, simple to answer and simple to prove for every employer and auditor who asks.
99.96% uptime
Payroll does not wait. Redundant infrastructure, monitoring, tested backups and disaster recovery hold the platform at 99.96% availability.
Access & encryption
Role-based access, least privilege, encryption in transit and at rest, and scheduled access reviews. Nobody sees more than their role needs.
Change governance
Every release is reviewed, tested and approved through controlled deployment with rollback plans. Moving fast never means breaking payroll.
Frequently asked questions
Yes. Catch-e holds ISO/IEC 27001 certification, the international standard for information security management systems. This reflects the implementation of formal security controls, policies, risk management processes and continuous improvement practices across the platform and organisation.
Catch-e data is stored in Australian data centres. The platform does not store sensitive operational or payroll data outside of Australia, which is particularly important for organisations with data sovereignty requirements.
Catch-e applies a structured role-based access control model. Users are assigned roles aligned to their operational responsibilities, such as backoffice administration, employer program management or dealer coordination. The platform enforces segregation of duties where required and includes controlled account provisioning and deactivation processes.
Catch-e maintains comprehensive audit logs across operational workflows, recording who performed each action, when it occurred and what changed. This supports compliance reviews, internal audits and dispute resolution. Audit trails are tamper-evident and retained in accordance with operational requirements.
Catch-e encrypts data both in transit (TLS) and at rest. Access to sensitive financial and payroll data is controlled through role-based permissions. The platform also implements environment segregation between production, staging and development environments to prevent unauthorised access to live data.
Catch-e follows secure development practices including code review processes, dependency management, vulnerability scanning and structured release governance. Changes to the platform go through a controlled deployment pipeline with appropriate testing and approval gates before reaching production.
Catch-e maintains a formal incident response framework as part of its ISO 27001 compliance program. This includes defined escalation paths, containment procedures, notification obligations and post-incident review processes.
Yes. The Catch-e team can provide security documentation, compliance summaries and relevant certification information to support enterprise procurement and vendor assessment processes. Contact us via the Contact page to request this documentation.
Ready to work with us?
Leasing and salary packaging programs carry complex financial and operational responsibilities. Catch-e provides the infrastructure to manage them with clarity and control.
Powered by 150+ years of combined industry experience.
See the products
Five products covering the full operational surface of leasing and packaging programs.
Explore productsConnect your systems
Payroll, banking, accounting, servicing and FBT, integrated with what you already run.
Integration options