About
Compliance and security
What does "aligned with" actually mean when Corpshore isn't certified?
This page exists specifically to avoid the vague, rounded-up compliance language that outsourcing providers are sometimes tempted to use. Where Corpshore states its practices "align with" a framework, such as the Australian Privacy Principles or the Essential Eight, that means Corpshore's internal processes and controls are designed to meet the substance of that framework's requirements, without Corpshore holding a formal, independently audited certification against it. Where Corpshore states a certification is "on the roadmap", that means the certification has not been achieved yet. Neither phrase is a certification claim, and this page will be updated the moment that status genuinely changes, rather than leaving stale language in place after the fact.
Who is accountable when personal information is processed offshore?
Under Australian Privacy Principle 8 and section 16C of the Privacy Act 1988 (Cth), an Australian business that discloses personal information to an overseas outsourcing provider must take reasonable steps to ensure that provider does not breach the Australian Privacy Principles. If the overseas recipient does breach an APP, section 16C treats the Australian entity as if it breached the principle itself: accountability does not transfer offshore along with the work. Corpshore's contracts, access controls and reporting are built specifically to support an Australian client meeting that "reasonable steps" obligation, including scoped system access, documented data handling procedures, and reporting a client's own compliance or privacy officer can review directly.
How does the position differ for New Zealand clients?
New Zealand clients benefit from a materially more permissive rule. Under the Privacy Act 2020's Information Privacy Principle 12, personal information sent overseas purely for safe custody or processing on the New Zealand agency's own behalf, where the overseas provider does not use that information for its own purposes, is not treated as a "disclosure" at all. This service-provider exception means a New Zealand client engaging Corpshore for processing work, rather than for a purpose where Corpshore might use the data independently, sits in a different, less restrictive compliance position than an Australian client engaging the same kind of work, and Corpshore's contracts are structured to make that distinction clear rather than applying the stricter Australian standard to every engagement regardless of jurisdiction.
What does Corpshore's security posture actually cover day to day?
Corpshore's practices align with the Essential Eight, a prioritised set of mitigation strategies published by the Australian Cyber Security Centre covering areas including patching applications and operating systems promptly, restricting administrative privileges, application control, configuring Microsoft Office macro settings, user application hardening, multi-factor authentication and regular backups. Alignment with this framework shapes how access to client systems and data is provisioned, monitored and revoked across every engagement, regardless of which Corpshore hub is delivering the work. This is stated as alignment with the framework's substance, not as a claim to any specific maturity level within it, since Corpshore has not undergone the formal, independent assessment that a maturity level claim would require.
What certifications does Corpshore hold today, and what is still on the roadmap?
This page states the current position plainly rather than rounding it up: ISO 27001 is on Corpshore's roadmap rather than currently held. IRAP assessment and ISO 27701 are not claimed under any circumstances, since neither is currently held or in progress. Where a client's own procurement process requires a specific certification as a condition of engagement, that requirement is worth raising directly and early, since Corpshore would rather have that conversation honestly upfront than have a client discover a gap later in a due diligence process.
How is client data segregated and access controlled across engagements?
Access to a client's systems and data is scoped to the specific task a team member is performing, rather than granted broadly across an entire account, and that access is reviewed and revoked as roles or staffing on an engagement change. This scoped-access approach is the same regardless of which BPO, IT outsourcing or AI service is involved, and it is the practical mechanism behind the alignment claims made elsewhere on this page: a framework alignment is only meaningful if it shows up in how access is actually provisioned day to day, not just in a policy document.
How does compliance and security get discussed before an engagement starts?
Any organisation with specific compliance, security or data residency requirements, whether driven by industry regulation, internal policy or a client contract of its own, should raise those requirements during scoping rather than after an engagement has started. A discovery call is the right venue for that conversation, and Corpshore's approach is to confirm what it can and cannot commit to honestly at that stage, rather than agree to a requirement it cannot actually meet.

Frequently asked questions
Is Corpshore ISO 27001 certified?
Not yet. ISO 27001 is on Corpshore's roadmap rather than currently held. This page will be updated as certifications are confirmed.
Who is accountable when data is processed offshore?
For Australian clients, the Australian entity remains accountable under Australian Privacy Principle 8 and section 16C of the Privacy Act 1988 (Cth), even where an overseas provider does the processing.
Is offshore data processing treated differently for New Zealand clients?
Yes. Under the New Zealand Privacy Act 2020's information privacy principle 12, data sent overseas purely for processing on the client's behalf is not treated as a disclosure at all, provided Corpshore does not use it for its own purposes. This is more permissive than the Australian rule.
Does Corpshore hold IRAP assessment or ISO 27701 certification?
No, neither is currently held or in progress, and neither is claimed under any circumstances.
What does it mean when Corpshore says its practices align with the Essential Eight?
It means Corpshore's internal processes and controls are designed to meet the substance of the Essential Eight's mitigation strategies, without Corpshore holding a formal, independently audited maturity level assessment against the framework.
How is access to client systems and data controlled?
Access is scoped to the specific task a team member is performing rather than granted broadly across an account, and it is reviewed and revoked as roles or staffing on an engagement change.
Build your team with Corpshore
Tell us the work, the delivery location and the coverage you need. You will have a considered response within six hours, or book a discovery call now.
Looking for a role rather than a partner? Explore careers at Corpshore