Skip to main content
Our Commitment

Information Security & Trust

Practical, enterprise-grade information security โ€” right-sized for New Zealand businesses.

At VanAir Digital, we take a pragmatic approach to protecting client and business information. Our security practices are being designed to align with internationally recognised frameworks, including ISO 27001 and TISAX, so we can scale responsibly as our business grows.

ISO 27001 aligned approach TISAX future-ready Privacy-conscious delivery Secure-by-design consulting

Our Security Principles

Protect client and business information

Safeguarding your data and our operational integrity is paramount to everything we do.

Apply least-privilege access

Access is granted only to those who need it, for the duration required โ€” nothing more.

Use secure cloud platforms

Leveraging robust, industry-leading cloud infrastructure with strong security controls built in.

Manage risks continuously

Proactive identification and mitigation of potential security threats as our business evolves.

Stay transparent and accountable

Clear communication and demonstrable commitment to our security practices at all times.

Data Protection & Privacy

Protecting your data and respecting your privacy is fundamental to how we operate. We manage all information with care, ensuring it remains confidential and secure.

  • Client, internal, and public data classification to ensure appropriate handling at every stage.
  • Secure cloud storage utilising trusted, encrypted platforms.
  • Controlled access to information, limited by role and business need.
  • Appropriate data retention policies and secure disposal methods when data is no longer required.
  • Alignment with New Zealand Privacy Act 2020 principles across all our operations.
Data Protection
Device Security

Device & Access Security

We implement robust controls to secure all devices and access points to our systems and your project environments.

  • Use of company-managed or approved devices for all business operations.
  • Multi-factor authentication (MFA) required for all key systems and client access.
  • Promotion of strong password practices and password manager use throughout the team.
  • Endpoint protection, including anti-malware and firewalls, where appropriate.
  • Secure onboarding and offboarding procedures for all personnel.

Cloud & Platform Security

Our services rely on secure cloud environments, and we ensure these platforms are configured and managed to the highest standards.

  • Exclusive use of trusted cloud providers such as Microsoft 365 and Azure.
  • Secure configuration of all platforms, adhering to vendor and industry best practices.
  • Comprehensive logging and monitoring capabilities where available.
  • Robust backup and recovery planning to ensure business continuity.
  • Separation of client work and environments where appropriate to maintain data isolation.
Cloud Security
Supplier Security

Supplier & Third-Party Security

We carefully manage the security posture of our suppliers and third-party partners to ensure your data is protected across our entire ecosystem.

  • All suppliers and third-party services are reviewed for security before engagement.
  • Access to client data by suppliers is strictly limited to business need.
  • Confidentiality and security obligations are included in all supplier arrangements.
  • Higher-risk suppliers receive greater scrutiny and more rigorous security assessments.

Incident Management

Despite best efforts, security incidents can occur. We have clear procedures to detect, respond to, and learn from any potential security event.

  • Security incidents are logged, reviewed, and thoroughly investigated.
  • Clients are notified promptly where legally or contractually required.
  • Lessons learned from incidents are actively used to improve our security controls.
  • Clear escalation paths and roles are maintained for rapid and effective response.
Incident Management

Scope of this Policy

This policy applies to VanAir Digital's digital consulting, AI automation, fractional CIO, cybersecurity advisory, and related client delivery services. It covers cloud platforms, business systems, company-managed devices, approved personal devices used for business access, supplier relationships, and client project environments.

Our Vision

Future Certification Roadmap

VanAir Digital is progressively building an Information Security Management System designed with ISO 27001 principles in mind. As the business scales and client requirements mature, we intend to pursue formal ISO 27001 certification. For automotive-related engagements, VanAir Digital will also consider TISAX alignment where required.

Building towards

ISO 27001

Future consideration

TISAX

Currently aligned to

NZ Privacy Act 2020

Security enquiries: hello@vanairdigital.co.nz Responsible disclosure welcome Last updated: May 2026
Chat with us ๐Ÿ‘‹

We use analytics cookies to understand how visitors use our site and improve your experience. Privacy Policy