Out Sauce Security Due Diligence Pack โ For Licensees & Advice Practices
Document IDOS-DDP-001
Version3.5
EffectiveJune 2026
Version 3.5 effectiveAugust 2026
ClassificationExternal โ for licensee compliance teams, dealer groups, and advice practices
Document Purpose
This pack is prepared for licensees, dealer groups, compliance teams, and large advice practices conducting due diligence on Out Sauce as an outsourced paraplanning provider.
It has been structured to address the questions most commonly asked during vendor security assessments, drawing on standard industry frameworks (ACSC Essential Eight, APRA CPS 234, ISO 27001) and regulatory expectations established by ASIC through recent enforcement actions.
Out Sauce welcomes due diligence. We have invested in building security infrastructure that is designed to withstand scrutiny โ not just pass it.
Deployment Status
Out Sauce deployed its security framework through a managed services engagement with Destiny IT, commenced March 2026 and completed in 2026. The technical controls described in this document are in place, and managed devices are provisioned to all personnel. The security awareness training program runs on a continuing basis, with modules and phishing simulation delivered through Destiny IT's training platform on a monthly or bi-monthly cycle. This document reflects Out Sauce's security architecture as operating.
How This Pack Is Structured
This pack contains Out Sauce's complete security documentation:
This document โ company overview, framework alignment, architecture summary, policy index, data handling, incident response, AI governance, contractor security, insurance, BCP, compliance evidence
Full policy suite โ 9-document comprehensive information security policy suite
Certificates โ insurance certificates of currency, ISO 27001 certification
Destiny IT Pty Ltd โ specialist Australian financial advice industry IT provider, ISO 27001:2022 certified
Cyber insurance
Minimum $1,000,000 cover (COC available on request)
Professional indemnity
$1,000,000 per claim / $3,000,000 aggregate (AIG, COC available on request)
Why Destiny IT
Out Sauce deliberately chose a specialist IT managed services provider rather than a generalist. Destiny IT specialises in working with financial advice businesses in Australia. They understand the regulatory environment (ASIC, Privacy Act, licensee cyber policies), the data sensitivity (TFNs, health information, financial details), and the specific threat landscape facing financial services. Destiny IT is ISO 27001:2022 certified (Certificate #6686-3757-01, valid to November 2027, certified by Compass Assurance Services under JAS-ANZ accreditation), providing independent assurance of Destiny IT's own information security management systems.
2. REGULATORY CONTEXT
Why This Matters Now
ASIC has established through enforcement actions that cybersecurity is a core compliance obligation under s912A of the Corporations Act 2001. Licensees are required to:
Have effective risk management measures to protect client data from cyber attacks
Ensure authorised representatives and outsourced providers meet the licensee's cybersecurity standards
Maintain adequate cybersecurity policies, training, monitoring, and specialist expertise
Exercise adequate supervision over outsourced service providers' cybersecurity
What this means for you: Working with an outsourced paraplanning provider that cannot demonstrate robust cybersecurity creates regulatory risk for your business and your licensee. Out Sauce's security framework is designed to significantly reduce that risk.
3. SECURITY FRAMEWORK ALIGNMENT
Framework / Standard
Out Sauce Position
Evidence
ACSC Essential Eight
Targeting Maturity Level 2 across all eight strategies, delivered through Destiny IT managed services
Principles applied by analogy โ information security capability commensurate with threats. Not directly APRA-regulated but framework applied as best practice.
Operational resilience principles adopted. Out Sauce as a service provider demonstrates capability consistent with CPS 230 expectations of material service providers.
Policy structure follows ISO 27001 domains. Out Sauce's IT security provider (Destiny IT) holds ISO 27001:2022 certification. Formal Out Sauce certification under consideration as the business scales.
Out Sauce is currently a small-business operator and not itself an APP entity for client information; the advice firm is the responsible APP entity. Out Sauce voluntarily applies APP-aligned standards across all 13 Australian Privacy Principles and is preparing for the APPs to apply directly as the small-business exemption is removed.
The responsible entity (the advice firm) carries the statutory NDB obligation; Out Sauce detects, contains, assesses, and notifies the firm promptly to support its determination, aligned to statutory timeframes (30 days Privacy Act; 7 days per licensee Cyber Policy). Where Out Sauce is the responsible entity for information it holds in its own right, it notifies consistently with the NDB scheme.
Destiny IT application management โ only approved software on managed devices. Contractors have no install rights.
ML2
Patch applications
Automatic updates with regular patching as part of Destiny IT managed services. Destiny IT monitors and confirms deployment.
ML2
Configure macro settings
Managed by Destiny IT โ macros restricted to signed/trusted only.
ML2
User application hardening
Attack surface minimised through Destiny IT managed device configuration.
ML2
Restrict admin privileges
Admin access limited to Out Sauce Operations + Destiny IT (security only). Contractors have zero admin rights.
ML2
Patch operating systems
Managed by Destiny IT โ automatic OS patching on all endpoints.
ML2
Multi-factor authentication
Required on all systems accessing client data. Authenticator app enforced (not SMS).
ML2
Regular backups
Daily automated cloud backups with automated restore integrity verification. The Out Sauce portal is additionally backed up nightly to an independent second provider in Australia, written under a 30-day immutability lock with write-only credentials, so backups are retained in a form that cannot be altered or erased.
ML2
4. SECURITY ARCHITECTURE
4.1 Technical Controls
Layer
Control
Details
Endpoint
Managed devices
All Out Sauce work is performed on company-provisioned, Destiny IT-managed laptops issued to all personnel. No BYOD for client data work.
Endpoint
EDR
Continuous endpoint detection and response on all managed devices
Endpoint
Application management
Only approved software; admin rights restricted to Out Sauce Operations + Destiny IT
Endpoint
Device management (MDM)
Central configuration, remote lock/wipe capability, screen lock at 10 minutes with dynamic locking enabled
Identity
MFA
Required for all client data systems. Authenticator app enforced. Email-based auth prohibited.
Identity
Password management
Enterprise password manager deployed to all personnel by Destiny IT, 16-char minimum, no reuse within 10 changes, 90-day rotation
Identity
Account lockout
5 failed attempt threshold
Network
Anti-spam / anti-phishing
Advanced email filtering via Destiny IT managed services
Data
DLP
Data loss prevention controls configured on managed devices by Destiny IT as part of Out Sauce onboarding
Data
Encryption at rest
Full-disk encryption on all endpoints; encrypted cloud storage
Data
Encryption in transit
TLS for all transmissions; encrypted email for sensitive data
Data
Cloud backups
Daily automated cloud backup, geographically redundant. Portal data additionally copied nightly to an independent provider in Melbourne under a 30-day immutability lock
Monitoring
SIEM
Security event logging, correlation, alerting โ all security-relevant activity captured
Monitoring
MDR
24/7 managed detection and response via Destiny IT
Patching
Automatic updates
Regular patching as part of Destiny IT managed services
Training
Security awareness
Continuing program delivered through Destiny IT's training platform: modules and phishing simulations for all personnel on a monthly or bi-monthly cycle, minimum 2 hours per person per year.
4.2 Administrative Controls
Control
Details
Evidence
Policy suite
9-document comprehensive information security policy suite
Three collected classes (General, Personal, Sensitive) with specific handling rules per class, plus two derived classes (3.4 De-Identified and Aggregated Intelligence, 3.5 Out Sauce Know-How)
All contractors provide informed consent to EDR, SIEM, DLP monitoring. Security monitoring of managed devices and systems is carried out by our IT security provider, Destiny IT, for information security and regulatory compliance only. It is never used for performance management, productivity tracking, or work supervision. Separately, like any professional services firm, Out Sauce manages workload, turnaround, and quality as part of running the service. That management uses ordinary work records in the portal, not security monitoring. Internal software may help analyse those work records, and decisions about workload and engagement are always made by a person.
Three collected classes (General/Personal/Sensitive) plus two derived classes (3.4 De-Identified and Aggregated Intelligence, 3.5 Out Sauce Know-How), approved handling/transfer methods, AI data rules, TFN handling per TFNR 2015
Product providers / government agencies (where primary methods unavailable)
Post, or password-protected document (16-char, sent via separate channel)
6.3 Prohibited Practices
No client data on personal devices, USB, removable media, or personal cloud
No client data in personal email accounts
No client data in unapproved third-party AI tools
No unencrypted transfer of sensitive information
No duplication of sensitive data (e.g., TFNs) across multiple documents โ single-source storage
No Airdrop/Bluetooth transfer of client data
6.4 Retention & Disposal
Client files (the finished advice documents) are owned and retained by the Client's firm, which holds the 7-year obligation under the Corporations Act and licensee requirements. Out Sauce produces and returns the work and does not retain the client file.
While in use, client data is handled only in approved systems (approved financial planning software, managed cloud platform)
Out Sauce keeps working copies of client data only as long as needed to deliver the engagement, then securely disposes of them (managed by Destiny IT). Out Sauce's own business records (for example contractor, incident, and training records, and its own invoices and work records such as job status, turnaround, and workload) are retained per their applicable obligations.
Contractor data return and certified destruction on termination
The Out Sauce Internal Knowledge Base (OS-KB-001) is a separate Out Sauce-operated store that holds de-identified and aggregated organisational knowledge (class 3.4) and Out Sauce Know-How (class 3.5, Out Sauce's own firm-attributed working knowledge, which never contains a firm's customers' personal information) โ neither of which is client data. It keeps no copy of any deliverable; raw source documents are neither stored in nor retrievable through it; and transient compile-time inputs from client working files are disposed of after the compile step. The retained corpus contains no client data, and Out Sauce does not retain the client file itself, so disposing of a client file (which the licensee holds) requires no extraction from this store. See Section 8 (AI Governance) and OS-DHP-001 s8.1.
Out Sauce's internal software (OS-OPS-001) is not a store at all. It reads Out Sauce's own operational records in place and retains nothing of what it reads: no copies, no transcripts, no learning. Nothing is held, so there is nothing to dispose of. See Section 8.2 and OS-DHP-001 s8.1.2.
7. INCIDENT RESPONSE
Item
Out Sauce Standard
Evidence
Plan
Documented 6-phase Cyber Incident Response Plan with 4 severity levels
Assessment commenced within 24 hours of awareness, aligned to the responsible firm's statutory timeframe (30 days Privacy Act) so the firm can meet its NDB obligation
Minimum $1,000,000 cover including incident response, business interruption, notification costs, third-party claims
COC available on request
8. AI GOVERNANCE
Current status: Out Sauce's use of AI follows the same rules everywhere. No AI system reads client information unless the information is processed entirely within Australia, and the use has been assessed and approved under the Out Sauce vendor and AI governance framework and is recorded in the Approved AI Tools Register. The register records every use approved for client information, with its permitted inputs, outputs, and conditions, and is available on request.
Out Sauce governs two distinct categories of AI use under those rules. Third-party AI tools used by personnel are governed by the Contractors Agreement Schedule B and the Approved AI Tools Register (OS-AIT-001); the default rule is that a tool not on that register is not approved for any Out Sauce data. Separately, Out Sauce operates systems of its own: the Out Sauce Internal Knowledge Base (OS-KB-001, Australia-hosted), which learns and retains de-identified patterns (class 3.4) and Out Sauce Know-How (class 3.5) under the conditions set out in Section 8.1; and internal software (OS-OPS-001), which answers Out Sauce's own operational questions from live records and keeps nothing of what it reads, under the conditions set out in Section 8.2. Neither is yet in operational use: Sections 8.1 and 8.2 describe their governing design and operating commitment, and OS-OPS-001 remains in development pending its pre-use gate. Both run under Out Sauce control rather than as personnel tools, and neither changes the third-party position above. Out Sauce continues to assess AI tools against security, privacy, and regulatory requirements on an ongoing basis.
OS-OPS-001 status: Out Sauce is developing this software for its own operations. It is currently in development and processes no Out Sauce data. Until its status in the Approved AI Tools Register (OS-AIT-001) reads Approved, that register's default position applies to it: no use with any Out Sauce data.
Item
Out Sauce Standard
Evidence
Framework
Formal AI governance policy embedded in the Contractors Agreement (OS-SCHB-001, Schedule B, Technology & AI Use Policy), with the Approved AI Tools Register maintained as OS-AIT-001. The register governs Out Sauce's own systems as well as third-party tools, and is available on request.
Maintained list of approved AI tools and systems; each assessed for data handling, security, and regulatory compliance before approval, and recorded with its permitted inputs, outputs, and conditions. The default rule is that anything not on the register is not approved for any Out Sauce data.
No AI tool or system touches client information unless it has been assessed, approved, and recorded in the Approved AI Tools Register, and the processing stays entirely within Australia. Sensitive Information (financial details, TFNs, health info) is never input into any AI tool or system. No client data is placed in third-party AI tools. The internal knowledge base reads General Information freely and Personal Information in client working files only as a transient, in-Australia compile-time input that is read, de-identified, and discarded, never retained. Internal software (OS-OPS-001) reads Out Sauce's own operational records only: never sensitive information, document contents, or client working files.
Two systems are operated by Out Sauce itself, distinct from contractor tools. The Out Sauce Internal Knowledge Base (OS-KB-001) processes client data only within Australia, on a transient basis, to produce de-identified and aggregated organisational knowledge (class 3.4) and Out Sauce Know-How (class 3.5, Out Sauce's own working knowledge, AU-only permanently); full conditions in Section 8.1. Internal software (OS-OPS-001) answers Out Sauce's own operational questions from its live operational records, read-only, processed entirely within Australia, retaining nothing of what it reads; full conditions in Section 8.2.
All AI-assisted deliverables reviewed by qualified paraplanner before delivery. AI does not replace professional judgement. The internal knowledge base makes no client-facing advice and no automated decision affecting any individual. Internal software (OS-OPS-001) is read-only and used by authorised Out Sauce staff only; a person makes every decision, including decisions about workload and engagement, and it likewise makes no client-facing advice and no automated decision affecting any individual.
AI contribution to deliverables disclosed on request. Transparency is a core principle.
OS-SCHB-001 (Schedule B) s3.4
Accountability
Paraplanner retains full professional responsibility for all outputs regardless of AI use
OS-SCHB-001 (Schedule B) s3.6
Regulatory alignment
ASIC REP 798 (AI governance in financial services), DTA Model AI Clauses v2.0, Australia's AI Ethics Principles (fairness, transparency, accountability, privacy, reliability, contestability, human oversight)
About OS-SCHB-001. Schedule B, the Technology & AI Use Policy, is not a standalone document. It forms part of the Out Sauce Contractors Agreement, which every contract paraplanner signs, and it binds them contractually rather than by policy. It is produced with the Contractors Agreement template, which is available on request (Section 13).
Separately from the third-party tool rules above, Out Sauce operates its knowledge base (OS-KB-001). This is an Out Sauce-operated system, not a personnel tool. Out Sauce's other own system, internal software (OS-OPS-001), is a separate system covered in Section 8.2; it is not part of the knowledge base and shares none of its functions.
Purpose: to build and maintain a single internal store of de-identified and aggregated knowledge (class 3.4) and Out Sauce Know-How (class 3.5) about how Out Sauce works (its methods, processes, drafting conventions, accumulated experience, and its working understanding of how each client firm and its advisers prefer their work prepared), so that Out Sauce delivers more consistent and higher-quality work.
Permitted inputs by classification:
General: unrestricted.
Personal (client working files): permitted only as a transient compile-time input, read inside the Out Sauce-managed environment to identify the pattern, then discarded. Not retained. Adviser identities and working preferences are relationship data Out Sauce already holds about a firm's portal users; their retention in class 3.5 pages is governed by that class (OS-DHP-001 s3.5).
Sensitive (tax file numbers, health information, account numbers): never ingested; excluded or redacted before the knowledge base reads anything.
Hosting and processing: the knowledge base operates under Out Sauce control. Identifiable client information is processed only within Australia and is never sent to any AI model or service that would transfer it outside Australia; this includes the de-identification step itself. Once information has been de-identified and aggregated (class 3.4) it is no longer client information; Out Sauce Know-How (class 3.5) identifies the client firm it relates to and therefore remains within Australia permanently (OS-VMP-001 s5.1). The specific AI models and services used are assessed and approved under the Out Sauce Third-Party & Vendor Management Policy (OS-VMP-001) before use, and no model is approved for identifiable client information unless it meets this in-Australia requirement.
Output and retention: the knowledge base retains two classes of information, neither of which is client data: de-identified and aggregated knowledge (class 3.4, from which no person, client, or firm can be reconstructed) and Out Sauce Know-How (class 3.5, Out Sauce's own firm-attributed working knowledge, which never contains Sensitive Information or a firm's customers' personal information and never reproduces any advice or deliverable). It keeps no copy of any deliverable, and raw source documents are neither stored in nor retrievable through the system. No output is retained until it passes the check for its class (end-customer de-identification is tested within every firm-attributed page, per firm and adviser slice); output that fails is discarded, not stored.
Oversight: output is reviewed before reliance. The knowledge base makes no client-facing advice and no automated decision affecting any individual. It does not approve any third-party AI tool for client data and does not change the prohibitions in Out Sauce's data handling policy.
Out Sauce has designed internal software to answer its own questions about its own live operational records, such as job status, turnaround, workload, and invoicing. It is not in use; what follows describes that design, and the Status below governs. As designed it is read-only and for authorised Out Sauce staff only, a person makes every decision, and it retains nothing of what it reads: no copies, no transcripts, no learning. It never reads sensitive information, document contents, or client working files, and it processes information entirely within Australia.
Status: This software is currently in development and processes no Out Sauce data. Until its status in the Approved AI Tools Register (OS-AIT-001) reads Approved, that register's default position applies to it: no use with any Out Sauce data.
Permitted inputs: Out Sauce's own operational records only (job status, turnaround, workload, invoicing). Client working files, document contents, and Sensitive Information are outside its reach by design.
Retention: nothing of what it reads is retained, so there is nothing to extract and nothing to destroy. That zero-retention control is a condition of approval, and vendor-side verification of it forms part of the pre-use gate; it is stated here as the control that must hold, not as a control already independently verified.
Oversight: a person makes every decision, including decisions about workload and engagement. The software makes no client-facing advice and no automated decision affecting any individual, and it is never used as a security monitoring tool (see Section 9).
Nationally Coordinated Criminal History Check (National Police Check), identity verification, reference checks and a skills assessment, all completed before engagement and before any access is granted
Comprehensive Contractors Agreement v2.3 (July 2026) with technology, AI, security, data handling, and incident reporting obligations contractually embedded
Contractors Agreement + Schedules
Operating model
100% onshore (Australia). All paraplanning work performed by Australian-based contractors.
Contractors Agreement cl 1
Devices
Every contractor will receive an Out Sauce-provisioned, Destiny IT-managed laptop. No personal devices permitted for Out Sauce client work. Out Sauce absorbs all equipment costs. Devices are deployed.
Schedule A (Equipment Loan)
Training
Minimum 2 hours/year security awareness training + monthly or bi-monthly phishing simulations. Completion is tracked and auditable in the Training Register (OS-TR-001).
EDR, SIEM, DLP on all managed devices. Informed consent obtained. Security monitoring of managed devices and systems is carried out by our IT security provider, Destiny IT, for information security and regulatory compliance only. It is never used for performance management, productivity tracking, or work supervision. Separately, like any professional services firm, Out Sauce manages workload, turnaround, and quality as part of running the service. That management uses ordinary work records in the portal, not security monitoring. Internal software may help analyse those work records, and decisions about workload and engagement are always made by a person.
Contractors Agreement cl 8.5; Schedule A ยง5
Incident reporting
24-hour mandatory reporting obligation for any suspected security incident
Contractors Agreement cl 10.3
Data handling
Bound by Out Sauce's data classification (General, Personal, Sensitive, plus the derived classes 3.4 De-Identified and Aggregated Intelligence and 3.5 Out Sauce Know-How) and approved handling methods. No personal cloud, no USB, no unapproved third-party AI.
Minimum $1,000,000 cover. Includes: incident response, business interruption, notification costs, third-party claims, cyber extortion, data recovery.
COC available on request
Professional indemnity
$1,000,000 per claim / $3,000,000 aggregate. AIG Professional Indemnity, valid to Sep 2026.
COC available on request
Certificates of Currency
Out Sauce Cyber COC (CFC, valid to Sep 2026) and PI COC (AIG, valid to Sep 2026) on file. The Destiny IT COC attached (Chubb PremierTech2) is current and runs to 1 October 2027.
COCs on file
Reading the certificates. Both Out Sauce certificates name Weekes Financial Pty Ltd (ACN 678 702 013) as the insured. That is the legal entity behind Out Sauce Paraplanning, as set out in Section 1; "Out Sauce" is the shortened trading name used in branding. The cyber certificate also carries a business activity descriptor drawn from the insurer's own classification list, which does not match the description of services in Section 1. That field records the insurer's own category for the entity and is not a description of the paraplanning services Out Sauce provides. Out Sauce is aware of it and is in communication with its insurer.
The attached Destiny IT certificate names D3ST1NY PTY LTD as the insured. That is the legal entity trading as Destiny IT, the managed IT provider named in Section 4.1 and in the vendor register at OS-VMP-001 s5. The certificate issued under the previous placement carried the trading name alongside the company name; the current one records the company name only.
Automated restore integrity verification via backup platform; full restore testing available on request. The portal's nightly off-platform backup runs an integrity check on each night's database copy before upload and aborts rather than shipping a copy that fails. Monthly, an independent check outside that infrastructure retrieves the most recent backup, decrypts it and verifies its integrity, confirming the copy can actually be retrieved and opened
Out Sauce's paraplanning work is performed by Out Sauce's own independent contract paraplanners. Out Sauce does not further subcontract client work to third parties.
Does Out Sauce use offshore providers?
No. All Out Sauce paraplanning work is performed onshore in Australia by Australian-based contractors.
How does Out Sauce manage vendor/fourth-party risk?
Out Sauce maintains a Third-Party & Vendor Management Policy (OS-VMP-001) with tiered risk assessment. Destiny IT is Out Sauce's primary IT vendor, assessed as Tier 1 (Critical).
Does Out Sauce provide visibility into its vendor ecosystem?
Yes. Out Sauce can provide a list of all material vendors/subprocessors and their risk tier classification on request.
13. COMPLIANCE EVIDENCE
Document
Included
This due diligence pack
Yes
Full policy suite (9 policies + 3 registers/programs)
ClassificationInternal โ provided to clients and licensees on request
Purpose
This document lists all AI tools approved for use by Out Sauce personnel in the course of Out Sauce business. It is maintained by Out Sauce and may be updated from time to time.
Default position: If a tool is not on this list, it is not approved for use with any Out Sauce data.
Current Status
Out Sauce's use of AI follows the same rules everywhere. No AI system reads client information unless the information is processed entirely within Australia, and the use has been assessed and approved under the Out Sauce vendor and AI governance framework and is recorded in this register. This register records every use approved for client information, with its permitted inputs, outputs, and conditions, and is available on request.
Two kinds of use are governed separately below: personnel use of external AI services, and Out Sauce-operated systems.
Personnel use of external AI services (ChatGPT, Claude, Gemini, Copilot, and any other generative AI service) is limited to general research, professional development, and non-client work that involves no Out Sauce data of any classification. No third-party AI tool is currently approved for any work involving Out Sauce client data. A third-party tool becomes available for client work only once it has been assessed, formally added to this list, and notified to personnel.
Separately, Out Sauce operates internal systems of its own, Australia-hosted and listed in the Approved Out Sauce Internal AI Systems section below with their permitted inputs, outputs, and conditions. The roster's current entries are the knowledge base (OS-KB-001), which learns and retains de-identified patterns and Out Sauce Know-How; and internal software (OS-OPS-001), which answers Out Sauce's own operational questions from live records and keeps nothing of what it reads. The knowledge base is approved to process client data on a transient, in-Australia basis, to produce de-identified organisational knowledge (class 3.4) and Out Sauce Know-How (class 3.5). OS-OPS-001 is in development; the roster entry below sets out the terms it will run under once live, and until its status reads Approved the default position above applies to it: no use with any Out Sauce data.
These are Out Sauce-operated systems rather than personnel tools. Authorised staff use of a listed internal system, through that system's approved harness, is not personnel use of external AI services: it is governed by that system's roster entry and its conditions, not by the paragraph above. No Out Sauce-operated system approves any third-party tool for client data or changes the prohibition above.
Out Sauce continues to review AI tools against security, privacy, and regulatory requirements on an ongoing basis.
Approved Out Sauce Internal AI Systems
AI systems operated by Out Sauce itself, as distinct from third-party tools used by personnel. These run under Out Sauce control within Australia and are governed separately from the personnel tool rules above. Listing is not approval: each entry's Status field states whether that system is approved, and an entry that is not yet approved is subject to the default position above.
To build and maintain a single internal store of de-identified and aggregated knowledge (class 3.4) and Out Sauce Know-How (class 3.5) about how Out Sauce works (its methods, processes, drafting conventions, modelling approaches, accumulated experience, and its working understanding of how each client firm and its advisers prefer their work prepared), so that Out Sauce delivers more consistent and higher-quality work.
Permitted inputs
General: unrestricted. Personal (client working files): permitted only as a transient compile-time input, read inside the Out Sauce-managed environment to identify the pattern, then discarded, not retained. Adviser identities and preferences are relationship data Out Sauce already holds; their retention in class 3.5 pages is governed by that class (OS-DHP-001 ยง3.5), not the transient-read rule. Sensitive (tax file numbers, health information, account numbers): never ingested; excluded or redacted before the knowledge base reads anything.
Permitted outputs
Two classes. De-identified and aggregated knowledge (class 3.4): contains no Personal or Sensitive Information and is not reasonably re-identifiable by any party. Out Sauce Know-How (class 3.5): firm/adviser-attributed working knowledge โ identifiable to the firm it describes, by design โ which never contains Sensitive Information, never contains Personal Information of a client firm's customers (the "not reasonably re-identifiable" standard is scoped to end customers and is tested per firm/adviser slice), and never reproduces any advice or deliverable. No output is retained until it passes the check for its class; output that fails is discarded, not stored (a pattern that fails attributed may be kept as class 3.4 only).
Source documents
Raw source documents (including SOAs) are neither stored in nor retrievable through the system.
Hosting & processing
The knowledge base operates under Out Sauce control, within Australia. Client information is processed only within Australia, including the de-identification step, and is never sent to any AI model or service that would transfer it outside Australia. Once information has been de-identified and aggregated (class 3.4) it is no longer client information; Out Sauce Know-How (class 3.5) identifies a client firm and therefore remains AU-only permanently (OS-VMP-001 ยง5.1). The specific AI models and services used are assessed and approved under the Out Sauce Third-Party & Vendor Management Policy (OS-VMP-001) before use.
Human oversight
Output is reviewed before reliance. The knowledge base makes no client-facing advice and no automated decision affecting any individual.
Conditions: the system operates only under Out Sauce control; client firms that have opted out of AI use are excluded before ingestion; de-identification is verified before any output is retained (failing output is discarded, not stored); it does not approve any third-party AI tool for client data and does not change the Prohibited Uses below.
OS-OPS-001: Out Sauce Internal Operations Software
Field
Detail
Owner
Out Sauce Operations
Status
Out Sauce is developing this software for its own operations. This entry sets out the terms it will run under once it is live. It is currently in development and processes no Out Sauce data. Until this status reads Approved, the register's default position applies to it: no use with any Out Sauce data.
Purpose
To answer Out Sauce's own questions about its own live operational records, such as job status, turnaround, workload, and invoicing, so that Out Sauce can manage its service. It is read-only and used by authorised Out Sauce staff only, a person makes every decision, and it retains nothing of what it reads: no copies, no transcripts, no learning. It never reads sensitive information, document contents, or client working files, and it processes information entirely within Australia.
Permitted inputs
A query-time read of a named allowlist of Out Sauce operational fields only: job metadata (identifier, service type, firm, status, dates), turnaround and workload figures, invoice and remittance amounts, and contractor work records (Personal-class business records, OS-DHP-001 ยง3.2 and the note at ยง3.3). Everything else is structurally unreachable rather than merely prohibited. Named exclusions: free-text job titles and job descriptions; the line-item detail on invoices and remittances; document bodies and message bodies; any Sensitive Information (OS-DHP-001 ยง3.3); bank and account numbers. Client firms that have opted out of AI use are invisible to the system, excluded from every query and every aggregate.
Permitted outputs
Answers to an authorised Out Sauce administrator only. No client-facing output, no advice, and no automated action.
Source documents
Document bodies, message bodies, and client working files are structurally unreachable. Nothing is stored in or retrievable through the system.
Hosting & processing
Query-time processing of live identifiable operational data, carried out entirely within Australia, under Out Sauce control. The specific AI model and service used is assessed and approved under the Out Sauce Third-Party & Vendor Management Policy (OS-VMP-001) before use.
Human oversight
A person makes every decision. The software triggers no action, sends nothing, and writes nothing, and it makes no automated decision affecting any individual.
Conditions: the model is Australia-pinned per OS-VMP-001; retention is zero end-to-end, on the Out Sauce side and the inference vendor side alike (no transcripts and no logs carrying query text, tool arguments, tool results, or model responses); a person makes every decision; and the system is accessed only through the approved Out Sauce harness โ it is never connected to, or queried from, general-purpose AI tools or CLI sessions.
Data Classification Key
Classification
Description
General
Non-sensitive business information with no privacy implications
Personal
Information about an identified or identifiable individual (names, contact details, employment, super fund, insurer, policy numbers)
Sensitive
Financial details, TFNs, health info, account numbers, government identifiers
How This List Is Updated
Out Sauce Operations assesses the tool against security, privacy, and regulatory requirements
Assessment considers: where data is processed/stored, data retention, encryption, compliance with Privacy Act and licensee requirements
If approved, the tool is added to this list with conditions and data classification restrictions
All Out Sauce personnel are notified via email of the change
Changes take effect on the date of notification
Out Sauce Operations may remove any tool from this list at any time by email notification, effective immediately
Prohibited Uses (All AI Tools, Including Future Approved Tools)
Regardless of approval status, the following are always prohibited:
Inputting Sensitive Information (TFNs, health info, financial details, account numbers) into any AI tool unless specifically approved for Sensitive data (no Out Sauce system, including OS-KB-001 and OS-OPS-001, is approved to ingest Sensitive Information)
Using AI to make financial advice recommendations without qualified paraplanner review
Relying on AI outputs without professional verification
Using AI tools via personal accounts for Out Sauce work
Disabling or circumventing any data loss prevention controls to use AI tools
APPROVAL
Approved by:
Clinton Weekes
Position:
Director โ Weekes Financial Pty Ltd
Date:
July 2026
Next review:
March 2027
This document is referenced by Out Sauce Contractor Agreement v2.3, Schedule B (Technology & AI Use Policy, OS-SCHB-001) and the Out Sauce Data Handling & Classification Policy (OS-DHP-001).
ClassificationInternal โ may be shared with clients, licensees, and partners on request
1. PURPOSE
This policy establishes Out Sauce's commitment to protecting the confidentiality, integrity, and availability of information assets โ including client data, business systems, and intellectual property.
Out Sauce operates in a regulated environment where the security of client financial data is not just good practice โ it is a legal obligation and a core part of the value we deliver. This policy sets the standard we hold ourselves to: not the minimum required, but the standard that positions Out Sauce as a market leader in secure paraplanning services.
2. SCOPE
This policy applies to:
People: Out Sauce Operations, all contract paraplanners, any future employees or contractors, and approved delegates
Systems: All Out Sauce-owned and managed devices, software, cloud services, communication platforms, and data repositories
Data: All information created, received, stored, processed, or transmitted in the course of Out Sauce business, regardless of format
Third parties: IT service providers (Destiny IT), software vendors, and any entity with access to Out Sauce systems or data
3. SECURITY PRINCIPLES
Out Sauce's information security framework is built on six principles:
3.1 Defence in Depth
No single control point. Multiple, overlapping layers of security โ managed devices, EDR, SIEM, DLP, MFA, encryption, training, and monitoring โ ensure that a failure in one layer does not compromise the whole.
3.2 Least Privilege
Every person and system gets the minimum access required to perform their function. Access is granted deliberately, reviewed regularly, and revoked promptly when no longer needed.
3.3 Security Enables Innovation
A strong security framework is what lets Out Sauce adopt AI, automation, and modern tools safely. Tools are approved through a governed process rather than left unmanaged or blocked by default. This governed-approval gate applies equally to Out Sauce's own internal AI systems (currently the knowledge base and the internal software, OS-OPS-001 โ see the Approved AI Tools Register, OS-AIT-001) and to third-party tools. Building AI in-house does not bypass the assessment, approval, and oversight that any external tool must pass.
3.4 Assume Breach
We plan and design as though a breach has already occurred or is imminent. This means: monitoring, logging, rapid detection, tested response procedures, and minimising blast radius.
3.5 Human-Centred Security
The strongest security framework fails if people don't understand or follow it. Policies are written in plain language. Training is practical and relevant. Security should be the easy path, not the hard one.
3.6 Continuous Improvement
Security is not a project with a finish date. Out Sauce reviews, tests, and improves its security posture continuously โ through formal annual reviews, post-incident analysis, and ongoing threat awareness.
4. GOVERNANCE
4.1 Roles and Responsibilities
Role
Person / Entity
Responsibilities
Information Security Owner
Out Sauce Operations
Overall accountability for information security. Approves policies, risk assessments, and security investments. Final authority on security decisions.
Operations
Out Sauce Operations
Day-to-day security administration, contractor onboarding/offboarding, training coordination, access reviews
IT Security Provider
Destiny IT Pty Ltd
Managed endpoint security, EDR, SIEM, DLP, patching, monitoring, incident response (first technical response), security awareness training and phishing simulations
Contract Paraplanners
~10 independent contractors
Comply with policies, use managed devices, complete training, report incidents, handle data per classification
Licensees
Applicable licensee(s)
Set minimum cybersecurity standards via their cyber policies. Out Sauce reports incidents and maintains compliance evidence.
4.2 Policy Review
Annual review: Full policy suite reviewed every 12 months (anniversary of effective date)
Triggered review: Policies reviewed out of cycle following:
A security incident
A material change in operations (e.g., new systems, significant growth)
A regulatory change (e.g., new ASIC guidance, Privacy Act reform, licensee policy update)
A change in threat landscape (e.g., new attack vector relevant to Out Sauce)
Review record: Each review documented with date, reviewer, changes made, and next review date
4.3 Compliance and Enforcement
All Out Sauce personnel (employees and contractors) must comply with this policy suite
Non-compliance by contractors is addressed under the Contractors Agreement (material breach provisions)
Non-compliance by employees is addressed through internal performance management
Serious or repeated non-compliance may result in termination and reporting to regulators where required
5. REGULATORY FRAMEWORK
Out Sauce operates within the following regulatory framework. This policy suite is designed to meet or exceed all applicable requirements.
5.1 Primary Legislation
Legislation / Standard
Relevance to Out Sauce
Corporations Act 2001 (s912A)
General obligations of financial services licensees. Adequate risk management, including cybersecurity, is a core obligation. Out Sauce supports licensees in meeting these obligations.
Privacy Act 1988
Governs collection, use, storage, and disclosure of personal information. Out Sauce is currently a small-business operator and not itself an APP entity for client information; the advice firm is the responsible APP entity, and Out Sauce voluntarily applies APP-aligned standards. Under the Notifiable Data Breaches (NDB) scheme the responsible entity assesses within 30 days and notifies the OAIC/individuals if the breach is eligible; Out Sauce notifies the firm promptly and supports that process.
AML/CTF Act 2006
Client identification and verification requirements. Impacts data retention and handling of identity documents.
5.2 Regulatory Guidance
Guidance
Relevance
ASIC Report 429 โ Cyber resilience
Establishes ASIC's expectation that financial services entities have cyber resilience capability
ASIC Report 798 โ AI governance
Flags gaps in AI risk frameworks in financial services. Out Sauce addresses this proactively through its AI governance framework: the Approved AI Tools Register (OS-AIT-001), which governs both third-party tools and internal AI systems, and the internal-AI controls in OS-DHP-001 ยง8.1. Schedule B remains the contractor-facing instrument for personnel use of third-party tools.
ASIC enforcement actions
ASIC has established through enforcement actions that cybersecurity failures are actionable breaches of s912A. Out Sauce's framework is designed to defend against these regulatory risks.
5.3 Industry Standards (Applied by Analogy)
Standard
How Out Sauce Applies It
ACSC Essential Eight
Out Sauce targets Maturity Level 2 across all eight strategies, delivered through Destiny IT's managed services
APRA CPS 234
Although Out Sauce is not directly APRA-regulated, the principles of CPS 234 (information security capability commensurate with threats) inform our framework
ISO 27001
Out Sauce's policy structure follows ISO 27001 domains without pursuing formal certification (disproportionate for current scale). Certification may be pursued as Out Sauce grows. Out Sauce's IT security provider (Destiny IT) holds ISO 27001:2022 certification.
5.4 Licensee Requirements
Requirement
Out Sauce Response
Licensee cyber policy standards
Licensee due diligence requirements are addressed in the Out Sauce Security Due Diligence Pack (OS-DDP-001) and the underlying policy suite.
6. SECURITY ARCHITECTURE
Note: These controls were deployed as part of Out Sauce's engagement with Destiny IT managed services, commenced March 2026.
6.1 Overview
Out Sauce's security architecture is delivered through a partnership with Destiny IT, a specialist managed services provider for the Australian financial advice industry. Destiny IT is ISO 27001:2022 certified, providing independent assurance of Destiny IT's own information security management systems. This provides enterprise-grade security at a scale appropriate for Out Sauce's operations.
6.2 Technical Controls
Layer
Control
Provider
Details
Endpoint
Managed devices
Destiny IT
All Out Sauce work is performed on company-provisioned, centrally managed laptops issued to all personnel
Endpoint
EDR (Endpoint Detection & Response)
Destiny IT
Continuous monitoring for malware, ransomware, and advanced threats
Endpoint
Application management
Destiny IT
Only approved software installed; admin rights restricted
Endpoint
Device management (MDM)
Destiny IT
Remote configuration, lock, and wipe capability
Identity
MFA (Multi-Factor Authentication)
Destiny IT / approved cloud platform
Required for all systems accessing client data. Authenticator app preferred over SMS.
Identity
Enterprise password management
Destiny IT
Deployed across all Out Sauce personnel. 16-character minimum, no reuse, no browser storage.
Network
Advanced anti-spam
Destiny IT
Email filtering and phishing protection
Network
Remote access security
Destiny IT / approved cloud platform
VPN available via managed services platform; MFA with conditional access policies (device compliance, geographical restrictions, MFA on every login) as primary remote access control for cloud-native operations
Data
DLP (Data Loss Prevention)
Destiny IT
USB transfer blocked by default; additional DLP controls configured as part of Out Sauce onboarding
Data
Cloud backups
Destiny IT
Automated backup of all approved cloud platform data
Data
Encryption in transit
Approved cloud platform / Destiny IT
TLS for all data transmission; encrypted email for sensitive data
Data
Encryption at rest
Approved cloud platform / Destiny IT
Full-disk encryption on endpoints; encrypted cloud storage
Monitoring
SIEM
Destiny IT
Security event logging, correlation, and alerting
Monitoring
MDR (Managed Detection & Response)
Destiny IT
24/7 threat monitoring across approved cloud platform and endpoints
Training
Security awareness + phishing simulation
Destiny IT
Video-based training via Destiny IT's security provider, delivered monthly or bi-monthly. Includes phishing resistance testing.
Patching
Automatic updates
Destiny IT
Patches applied to Essential Eight requirements within 48 hours, as part of managed services. Deployment is monitored and confirmed.
6.3 Administrative Controls
Control
Details
Policy suite
This document set โ establishes rules, procedures, and expectations
Contractor agreements
Security, data handling, AI, and incident reporting obligations built into agreements
Access reviews
Quarterly review of who has access to what systems
Onboarding/offboarding
Formal procedures for granting and revoking access
Vendor management
Security assessment of all third-party providers
Incident response plan
Documented, tested procedures for security incidents
Training program
Annual security awareness training (minimum 2 hours) and monthly or bi-monthly phishing simulations (exceeds licensee minimums). Delivered on a continuing basis through Destiny IT's training platform.
6.4 Physical Controls
Control
Details
Device security
Screen lock (10-minute auto-timeout with dynamic locking enabled), secure storage when not in use
No removable media
Client data must not be stored on USB, external drives, or removable media
Asset disposal
Managed by Destiny IT โ secure data erasure before disposal or redeployment
Home office
Contractors must use managed device in a reasonably secure environment (not shared public spaces for extended work with client data visible)
6.5 Asset Management
Asset type
How it is managed
Endpoints
Every device used for Out Sauce work is company-provisioned and enrolled in central device management by Destiny IT. Personal devices are not permitted. The device asset inventory is maintained by Destiny IT as part of the managed service.
Assignment
Each device is issued to a named person, recorded against that person in the Access Register (OS-AR-001), and returned to Destiny IT at offboarding (OS-AMP-001 ยง5.4, ยง5.5).
Software
Only approved software is installed. Application management and administrative rights are controlled by Destiny IT (ยง6.2). Approved AI tools are registered separately (OS-AIT-001).
Vendors and services
Registered and tiered under OS-VMP-001 ยง5, with a named register maintained internally.
Information
Classified and handled under OS-DHP-001, which governs where each class may be stored, how it is transferred, and how long it is kept.
Disposal
Secure data erasure by Destiny IT before disposal or redeployment (ยง6.4).
6.6 Change Management
Change type
How it is controlled
Out Sauce portal
Every change is made under version control and carries its author, its reason and its full history. Automated tests, linting, secret scanning and security scanning must pass before a change can be released.
Managed environment
Changes to endpoints, identity, email security and monitoring are made by Destiny IT under its own change process, within the scope of the managed services agreement.
Role and permission changes follow OS-AMP-001 ยง5.3 and are recorded in the Access Register.
Policy
Amendments follow ยง4.2 of this policy and are stamped in the Policy Review Register.
Any change that materially affects the security of client information is assessed for risk before it is made, and is recorded in the Risk Assessment Register where it changes a rated risk.
7. RISK MANAGEMENT
7.1 Risk Appetite
Out Sauce has zero tolerance for:
Deliberate misuse of client data
Failure to report known security incidents
Circumvention of security controls
Out Sauce has managed tolerance for:
Residual risk after proportionate controls are applied
Emerging threats that require ongoing monitoring and response
Operational friction from security controls (mitigated through training and tool selection)
7.2 Risk Assessment
Out Sauce conducts formal risk assessments:
Annually โ comprehensive review of threat landscape, control effectiveness, and residual risk
On change โ when new systems, services, or significant operational changes are introduced
Post-incident โ following any security incident, to identify root cause and control gaps
7.3 Key Risk Areas
Risk Area
Threat
Controls
Phishing / social engineering
Credential theft, malware delivery
Anti-spam, MFA, training, phishing simulation
Ransomware
Data encryption, business disruption
EDR, backups, MDR, incident response plan
Data exfiltration
Unauthorised transfer of client data
DLP, managed devices, approved tools only
Insider threat
Contractor misuse of data access
Least privilege, monitoring, data classification
Third-party compromise
Vendor breach impacting Out Sauce
Vendor management policy, cloud platform security
AI data leakage
Client data input into unapproved AI
Approved AI tools only, training, policy
AI secondary use / re-identification
Re-identification of de-identified aggregates; internal AI as a new exfiltration surface
For the knowledge base: de-identification before pooling. For the internal software (OS-OPS-001): an allowlist read model that excludes free-text fields and document bodies, zero retention of what is read, and a human decision on every output. Across both: purpose limitation, human oversight, no automated decision-making, vendor assessment (OS-VMP-001); detail in OS-RAR-001 (RSK-009, RSK-010)
Regulatory non-compliance
ASIC enforcement, licensee breach
Policy suite, training, audit trail
Business disruption
System outage, natural disaster
Cloud-based operations, backups, BCP
8. SECURITY INCIDENT MANAGEMENT
Security incidents are managed under the Cyber Incident Response Plan (OS-CIRP-001). Key commitments:
Detection: 24/7 monitoring via Destiny IT MDR and SIEM
Reporting: All personnel must report suspected incidents within 24 hours
Assessment: Out Sauce assesses the incident to support the responsible firm's Eligible Data Breach determination. The firm, as the APP entity, carries the statutory assessment (30-day Privacy Act period); licensee policies typically require formal assessment within 7 days
Notification chain: Personnel โ Out Sauce โ Destiny IT โ Licensee / advice firm (the responsible entity), which notifies affected clients and the OAIC/regulators as required
Post-incident: Root cause analysis, control improvement, lessons learned
9. DATA PROTECTION
Data protection is governed by the Data Handling & Classification Policy (OS-DHP-001) and the Privacy & Data Protection Policy (OS-PDP-001). Key commitments:
Data classification of information we collect: General / Personal / Sensitive, plus two derived classes (3.4 De-Identified and Aggregated Intelligence, 3.5 Out Sauce Know-How)
Handling requirements specific to each classification
Approved transfer methods by classification
Client files (the finished advice documents) are retained by the Client's firm, which holds the 7-year obligation (Corporations Act and licensee requirements); Out Sauce returns the work and does not retain the client file
Out Sauce keeps working copies of client data only as long as needed to deliver, then securely disposes of them
No client data on personal devices, USB, personal cloud, or unapproved systems
Internal AI pattern learning (the OS-KB-001 knowledge base) is governed by OS-DHP-001 ยง8.1 and OS-PDP-001: purpose limitation and secondary-use controls apply, de-identification before pooling applies to the cross-firm global layer (class 3.4; the firm-attributed Out Sauce Know-How layer, class 3.5, is governed by OS-DHP-001 ยง3.5 and stays in Australia permanently), and Sensitive client data is never ingested
Internal AI query-time reads (the internal software, OS-OPS-001) are governed by OS-DHP-001 ยง8.1.2: reads of operational fields only, under the approved mode in OS-DHP-001 ยง8.1, with zero retention of what is read (no copies, no transcripts, no learning), never Sensitive class, processed only within Australia, and a human decision on every output. This software is currently in development and processes no Out Sauce data; until its status in the Approved AI Tools Register (OS-AIT-001) reads Approved, that register's default position applies to it: no use with any Out Sauce data
10. BUSINESS CONTINUITY
Business continuity is governed by the Business Continuity & Disaster Recovery Plan (OS-BCP-001). Key commitments:
ClassificationInternal โ provided to clients and licensees on request
1. PURPOSE
This plan provides step-by-step procedures for identifying, containing, investigating, and recovering from cyber security incidents. It ensures Out Sauce can respond rapidly and meet its regulatory obligations under the Privacy Act (Notifiable Data Breaches scheme), licensee cyber policy requirements, and ASIC expectations.
2. SCOPE
This plan covers any actual or suspected Security Incident affecting:
Out Sauce systems, devices, or data
Client data handled by Out Sauce or its contractors
Third-party systems that process Out Sauce data (e.g., approved cloud platform, financial planning software)
3. DEFINITIONS
Term
Definition
Security Incident
Any actual or suspected unauthorised access to, disclosure of, loss of, or interference with Out Sauce systems or data. Includes phishing, malware, ransomware, credential compromise, data breach, device loss/theft, and social engineering.
Eligible Data Breach
A data breach likely to result in serious harm to affected individuals, as defined under Part IIIC of the Privacy Act 1988.
Near Miss
An event that could have resulted in a Security Incident but was detected and prevented. Near misses are logged for learning purposes.
4. INCIDENT RESPONSE TEAM
Note: This plan reflects Out Sauce's incident response framework being established as part of the Destiny IT managed services deployment (March 2026).
Role
Person / Entity
Responsibility
Incident Commander
Out Sauce Operations
Overall authority. Makes escalation, notification, and communication decisions.
Operations Support
Out Sauce Operations
Contractor communication, documentation, administrative support
Technical Response
Destiny IT
Technical investigation, containment, eradication, and recovery. 24/7 monitoring and alerting.
Legal advice on obligations, notifications, regulatory response
5. INCIDENT SEVERITY LEVELS
Level
Description
Examples
Response Time
CRITICAL
Active data exfiltration, ransomware, or compromise of systems containing client data
Ransomware encrypting devices; confirmed unauthorised access to client records; active attacker in systems
Immediate โ Destiny IT alerted within minutes; Out Sauce Operations notified within 1 hour
HIGH
Confirmed security breach with potential for data exposure, but no confirmed data loss
Compromised credentials; malware detected on managed device; phishing email clicked with credential entry
Within 4 hours โ Destiny IT investigates; Out Sauce Operations notified same day
MEDIUM
Suspected incident requiring investigation
Unusual login activity; DLP alert triggered; contractor reports lost device
Within 24 hours โ Destiny IT investigates; Out Sauce Operations notified within 24 hours
LOW
Near miss or minor policy violation
Phishing email received but not clicked; contractor attempts to install unapproved software (blocked)
Within 48 hours โ logged for review; addressed in next training/review cycle
6. INCIDENT RESPONSE PHASES
Phase 1: DETECTION & REPORTING
How incidents are detected:
Destiny IT monitoring (EDR, SIEM, MDR) โ automated alerts
Contractor or employee reports (within 24 hours of becoming aware)
Client or third-party notification
Licensee or regulator notification
Self-identification during reviews or audits
Reporting requirements:
Who
Reports To
Timeframe
Contractor
Out Sauce Operations
Within 24 hours of awareness
Out Sauce internal (Operations)
Destiny IT
Immediately / as soon as practicable
Destiny IT
Out Sauce Operations
Per monitoring SLA (automated alerts are real-time)
What to report:
What happened (or what you suspect happened)
When it was discovered
What systems/data may be affected
What actions have been taken so far
Contact details for follow-up
Reporting channel: Phone call to Out Sauce Operations + follow-up email to clinton@outsauce.au. For CRITICAL severity, phone call is mandatory โ do not rely on email alone.
Phase 2: ASSESSMENT & TRIAGE
Within the first 4 hours (CRITICAL/HIGH) or 24 hours (MEDIUM):
Confirm the incident โ Is this a real incident, a false positive, or a near miss?
Classify severity โ Use the severity table above
Identify scope โ What systems, data, and people are affected?
Determine data type โ Is client data involved? What classification (General / Personal / Sensitive)?
Assess NDB threshold โ Could this be an Eligible Data Breach under the Privacy Act?
Decision tree:
Incident confirmed?
โโโ NO โ Log as near miss. Review in next training cycle. STOP.
โโโ UNSURE โ Investigate further (Destiny IT). Set 24-hour review point.
โโโ YES โ Continue to Phase 3 (Containment)
โ
Client data involved?
โโโ NO โ Contain and resolve. Log incident. Review controls. STOP.
โโโ YES โ Continue NDB assessment (Phase 5)
Phase 3: CONTAINMENT
Objective: Stop the incident from getting worse. Preserve evidence.
Immediate containment actions (Destiny IT + Out Sauce Operations):
Action
Responsibility
Notes
Isolate affected device(s)
Destiny IT
Network isolation, disable remote access
Disable compromised accounts
Destiny IT
Reset passwords, revoke tokens
Block malicious IPs/domains
Destiny IT
Firewall and email filtering updates
Preserve logs and evidence
Destiny IT
Do NOT attempt to "clean up" before preserving
Notify affected contractors
Out Sauce Operations
"Stop using the device / system until further notice"
Activate cyber insurance
Out Sauce Operations
If CRITICAL or HIGH with likely data breach
CRITICAL RULE: Do NOT attempt to investigate or remediate independently. Preserve everything and let Destiny IT handle the technical response.
Phase 4: ERADICATION & RECOVERY
Objective: Remove the threat and restore normal operations.
Action
Responsibility
Details
Identify root cause
Destiny IT
How did the attacker get in? What vulnerability was exploited?
Remove malware/threat
Destiny IT
Clean or reimage affected devices
Patch vulnerability
Destiny IT
Apply patches, update configurations
Restore from backup
Destiny IT
If data was encrypted/destroyed
Reset all credentials
Destiny IT + Out Sauce
All affected accounts, plus any accounts that shared credentials
Verify system integrity
Destiny IT
Confirm systems are clean before reconnecting
Resume operations
Out Sauce Operations
Notify contractors they can resume; monitor closely
Phase 5: NOTIFICATION & REGULATORY OBLIGATIONS
Privacy Act โ Notifiable Data Breaches (NDB) scheme:
Step
Timeframe
Action
1. Assessment
Start within 24 hours of awareness; complete within statutory timeframes (30 days Privacy Act; 7 days per licensee requirements)
Assess whether breach is likely to result in serious harm. Consider: type of data, sensitivity, who accessed it, what they could do with it, was it encrypted.
2. Reasonable steps
Concurrent with assessment
Take steps to reduce harm (e.g., password resets, account monitoring). If remediation eliminates serious harm risk, NDB notification may not be required.
3. Notify OAIC
If Eligible Data Breach: "as soon as practicable" after assessment
Statement to OAIC including: entity details, description of breach, type of information, recommended steps for individuals.
4. Notify individuals
If Eligible Data Breach: "as soon as practicable"
Same statement as OAIC, delivered to affected individuals (or public notice if individual notification not practicable).
Advice firm notification:
Out Sauce's engagement is with the advice firm, which is the responsible APP entity
for its own clients' information. Out Sauce notifies the affected advice firm and
provides what that firm needs to meet its own obligations, including any notification
its licensee requires. Where a firm is self-licensed, it is its own licensee and the
steps below are the whole of the notification path.
Step
Timeframe
Action
1. Initial report
Within 24 hours of Out Sauce becoming aware
Notify the affected advice firm. Provide initial facts.
2. Assessment update
Within 7 days
Provide formal assessment of whether the incident is an Eligible Data Breach, in a form the firm can pass to its licensee
3. Ongoing updates
As required
Keep the advice firm informed of investigation, remediation, and notifications
Other notifications:
Party
When
How
Affected clients
If their data was compromised
Personal contact (phone/email) from Out Sauce Operations โ do not delegate to contractors
ACSC
If criminal activity suspected
Report via cyber.gov.au
Police
If theft, fraud, or criminal activity
QLD Police + AFP (if cross-jurisdictional)
Cyber insurer
CRITICAL or HIGH with potential liability
Per policy terms โ typically within 24-48 hours
Phase 6: POST-INCIDENT REVIEW
Within 14 days of incident closure:
Root cause analysis โ What happened and why?
Control effectiveness โ Did existing controls work? What failed?
Response effectiveness โ Was the response plan followed? What worked well? What needs improvement?
Lessons learned โ What changes are needed to policies, controls, or training?
Action items โ Specific, assigned, time-bound actions to prevent recurrence
Document: Post-incident report filed and retained for 7 years. Policy suite updated if required.
7. TESTING
This plan is tested through:
Test Type
Frequency
Participants
Tabletop exercise
Annual
Out Sauce Operations, Destiny IT
Phishing simulation
Monthly or bi-monthly (via Destiny IT)
All contractors + internal
Backup restore verification
Ongoing (automated); full manual test on request
Destiny IT
Communication test
Annual
Verify all contact details are current
A tabletop exercise walks through a realistic scenario (e.g., "a contractor clicks a phishing link and enters their approved cloud platform credentials") and tests the team's response against this plan.
8. RECORD KEEPING
All incident records are retained for 7 years, including:
ClassificationInternal โ shared with contractors as part of onboarding
1. PURPOSE
This policy establishes how Out Sauce classifies, handles, stores, transfers, processes, and retains information, particularly client data, including where that processing is carried out by Out Sauce-operated systems and not only by personnel. It ensures all personnel understand their obligations and that Out Sauce meets its regulatory requirements under the Privacy Act, licensee cyber policy standards, and Corporations Act.
2. SCOPE
Applies to all information created, received, stored, processed, or transmitted by Out Sauce personnel (employees and contractors) or by Out Sauce-operated systems in the course of Out Sauce business, regardless of format (digital, paper, verbal).
3. DATA CLASSIFICATION
All information handled in Out Sauce operations falls into one of five classifications:
3.1 General Information
Definition: Non-sensitive business information with no privacy implications.
Examples:
Public business information (Out Sauce website content, marketing materials)
General industry data, market research, public regulatory guidance
Internal process documentation (non-confidential)
General communication not referencing specific clients
Handling requirements:
Standard care
May be stored on managed device, approved cloud storage, or approved tools
No special transfer requirements
No restriction on approved AI tools for this classification
3.2 Personal Information
Definition: Information as defined in the Privacy Act 1988 โ information or an opinion about an identified individual, or an individual who is reasonably identifiable.
Examples:
Client names, dates of birth, contact details (address, phone, email)
Employment details and history
Government identifiers (Medicare, driver's licence, passport โ but NOT TFN, which is Sensitive)
Store only in approved systems (approved cloud platform, financial planning software managed on Out Sauce devices)
Transfer only via approved methods (see Section 4)
Must not be emailed without encryption unless limited to: client name, contact details, super fund name, insurance provider name, policy number
Must not be input into AI tools unless the tool is on the Approved list AND approved for Personal Information (Out Sauce-operated systems are governed separately; see Section 8.1)
Must not be stored on personal devices, USB, personal cloud, or unapproved systems
Access limited to personnel who need it for their current engagement (the knowledge base's cross-firm learning operates only on de-identified material, class 3.4; firm-attributed working knowledge is governed by class 3.5 and Section 8.1)
3.3 Sensitive Information
Definition: A subset of personal information attracting heightened regulatory protection under the Privacy Act, licensee cyber policy standards, and applicable financial services regulation.
Sensitive information under the Privacy Act: Racial/ethnic origin, political opinions, religious beliefs, union membership, sexual orientation, criminal record, biometric data
Handling requirements:
Highest protection level
Store only in approved systems with access controls (financial planning software, approved cloud platform with access restrictions)
Transfer only via approved secure methods (see Section 4)
Must never be emailed without encryption
Must never be input into AI tools unless specifically approved for Sensitive Information by Out Sauce (no Out Sauce-operated system ingests Sensitive Information; see Section 8.1)
TFNs must be stored in one location only (approved financial planning software) โ not duplicated across file notes, spreadsheets, or emails
Access strictly limited to personnel with a current, specific need
Printed copies must be securely destroyed after use (cross-cut shredding)
Note on Out Sauce's own business records. Out Sauce's own billing and payment records (job
metadata, invoice and remittance amounts, and contractor work records) are Personal-class business
records under 3.2, in the same category as "salary" in that class's examples. The "Financial details"
line above refers to end-client financial position: the actual finances of a client firm's customers,
which is the genuinely sensitive category this policy protects. It does not extend to Out Sauce's own
operating figures. Bank account numbers and account balances remain Sensitive under this section in
every case. The basis for this reading is recorded because it rests on interpretation: in a
financial-services data policy, "sensitive financial information" means the client's financial
position; an invoice or remittance amount arising from Out Sauce's own operations is an operating
business record, distinct from a client's transaction history; and keeping account numbers Sensitive
holds the careful line between the two.
3.4 De-Identified and Aggregated
Definition: Patterns, methods, and know-how learned across multiple engagements, from which no individual person, client, or firm can be reconstructed, and which does not include or reproduce any specific advice or deliverable. Unlike the classes above, this information is derived by Out Sauce rather than collected, and it is the resting classification for the output of Out Sauce's internal knowledge base (OS-KB-001).
Qualifying tests: Information is classified here only where all of the following hold:
it is a pattern or method, not a specific recommendation;
it holds true across multiple engagements, rather than being drawn from a single job; and
no individual or firm can be reconstructed from it.
Handling requirements:
May be stored, retained, and used without restriction, including after an engagement ends, as it is neither Client Data nor Confidential Information
Held within the Out Sauce-managed environment (Australian data centres)
No special transfer restrictions, as it contains no Personal or Sensitive Information
3.5 Out Sauce Know-How
Definition: The methodologies, processes, know-how, techniques, insights, and working knowledge that Out Sauce develops or refines in the course of providing its services, including its understanding of how each client firm and its advisers prefer their work prepared. Like class 3.4 it is derived by Out Sauce rather than collected; unlike class 3.4 it is attributed โ a page may name a client firm and its advisers, by design. It is Out Sauce's own work product and is neither Client Data nor Confidential Information.
Boundaries (what this class never contains):
Sensitive Information โ never
Personal Information of a client firm's customers (end clients) โ never; end-customer de-identification applies within every firm-attributed page, tested per firm/adviser slice (a pattern that passes the class 3.4 tests globally but fails when attributed is kept in class 3.4 only)
Copies of any deliverable, or any specific advice โ never
The adviser names and working preferences it does contain are Personal Information of a client firm's portal users, held by Out Sauce in its own right and disclosed in the Out Sauce privacy policy.
Handling requirements:
Internal-only: held within the Out Sauce-managed environment (Australian data centres) inside OS-KB-001; never shared externally, never client-facing by default (any future surfacing is a deliberate decision, never a default)
Processed and stored only within Australia, permanently. Because class 3.5 identifies a client firm, it remains identifiable client information for the purposes of the model-locus rule and is never sent to any AI model or service that would transfer it outside Australia. This is a deliberate, permanent position (adopted 2026-07-11), not a provisional one; see OS-VMP-001 ยง5.1.
Retained while useful, including after an engagement ends
Access least-privilege, per the access-management policy
4. APPROVED TRANSFER METHODS
Data Classification
Approved Transfer Methods
NOT Approved
General
Email, approved collaboration tools, approved cloud sharing, approved AI tools
Unencrypted email (except limited fields โ see 3.2), personal cloud, USB, personal messaging
Sensitive
Approved cloud platform (encrypted email), approved client portals with access controls, direct system-to-system transfer (e.g., between approved financial planning software instances), password-protected documents (password sent via separate channel)
Unencrypted email, any personal system, USB, AI tools (unless specifically approved)
These methods meet or exceed leading licensee cyber policy requirements for data transfer by classification.
General, Personal, Sensitive (with access controls)
Destiny IT
Out Sauce managed device (local storage)
General, Personal (temporary working copies only)
Destiny IT
Out Sauce may also operate internal workflow and communication tools for task coordination and general business communications. These tools are assessed under the Out Sauce vendor management framework and are restricted to General and limited Personal information only. Client Sensitive data (Tier 3) is stored and transferred exclusively via approved financial planning software and the managed cloud platform. Out Sauce-operated systems, including the knowledge base (OS-KB-001) and the internal operations software (OS-OPS-001), are distinct internal systems governed by Section 8.1, not by this paragraph.
5.2 Prohibited Storage
Client data (Personal or Sensitive) must never be stored on:
Personal devices (laptops, phones, tablets not managed by Destiny IT)
USB drives, external hard drives, or removable media
Personal cloud storage (personal Google Drive, Dropbox, iCloud, personal OneDrive)
Personal email accounts
Consumer AI tools or services not on the Approved Tools list
Paper files retained beyond immediate use (must be destroyed after use)
5.3 Data Minimisation
Collect and retain only the client data necessary for the engagement
Do not duplicate Sensitive Information across multiple locations (e.g., TFN in one place only)
Working copies of client files on managed devices should be moved to approved cloud storage on completion and not retained locally longer than necessary
6. DATA RETENTION
6.1 Retention Periods
Data Type
Retention Period
Authority
Client files (SOAs, ROAs, file notes)
Owned and retained by the Client's firm (the licensee), not by Out Sauce. The licensee holds the 7-year obligation.
Corporations Act s1101C; licensee requirements
Out Sauce working copies of client data
Kept only as long as needed to deliver the engagement, then securely disposed of (not retained long-term)
Out Sauce policy (data minimisation; see 5.2)
AML/CTF identification records
7 years from relationship end
AML/CTF Act 2006
Contractor agreements and records
7 years from agreement end
General business practice
Security incident records
7 years from incident closure
Out Sauce policy (aligns with other retention)
Training records
7 years
licensee requirements
General business correspondence
3 years
General business practice
De-Identified and Aggregated knowledge (class 3.4)
Retained while useful; not Client Data
Out Sauce policy (see 3.4, 8.1)
Out Sauce Know-How (class 3.5)
Retained while useful, including after an engagement ends; not Client Data
Out Sauce policy (see 3.5, 8.1)
Out Sauce operational and business records (jobs, invoices, remittances, work records)
Retained per Australian tax and record-keeping law and ordinary business obligations
Out Sauce policy (mirrors the portal privacy policy)
6.2 Secure Destruction
After the retention period expires:
Digital data: Secure deletion using approved tools, or device destruction managed by Destiny IT
Paper records: Cross-cut shredding
Devices: Secure data erasure and certified disposal managed by Destiny IT
Knowledge base (OS-KB-001): The knowledge base retains only De-Identified and Aggregated information (class 3.4) and Out Sauce Know-How (class 3.5), neither of which is Client Data. Transient Personal inputs read from client working files during compilation are disposed of after the compile step and are not retained. Because the retained corpus contains no Client Data, and Out Sauce does not retain the client file itself, disposing of a client file (which the licensee holds) requires no extraction from the corpus (see Section 8.1).
7. SPECIAL CATEGORIES
7.1 Tax File Numbers (TFNs)
TFNs attract additional protections under the Privacy Act and the Tax Administration Act 1953:
Store in approved financial planning software โ single-source principle (do not duplicate across multiple documents)
Never include in email body (even encrypted email โ use secure portal or system-to-system)
Never duplicate across file notes, spreadsheets, or working documents
Access strictly limited
7.2 Health Information
Health information (relevant to risk insurance advice) is Sensitive Information:
Store in approved financial planning software or approved cloud platform with access controls
Transfer via encrypted channels only
Consider redaction after the specific advice engagement is complete (retain minimum necessary)
7.3 Identity Documents
Copies of passports, driver's licences, birth certificates (used for AML/CTF verification):
Retain per AML/CTF Act requirements (7 years from relationship end)
Store in approved financial planning software or approved cloud platform with access controls
After AML/CTF verification, redact government-issued numbers where possible (per industry best practice)
Securely destroy after retention period
8. AI & DATA
The following rules govern third-party AI tools used by Out Sauce personnel. Out Sauce-operated systems are separate internal systems, governed by Section 8.1.
Classification
AI Tools Permitted?
Conditions
General
Yes โ any Approved AI Tool
Standard use
Personal
Only Approved AI Tools specifically cleared for Personal Information
Must be on Approved Tools list; data must not leave Out Sauce-managed environment
Sensitive
Only if specifically approved by Out Sauce for that data type
Extremely limited; requires explicit Out Sauce approval; most AI tools are NOT approved for Sensitive data
Default rule: When in doubt, do NOT input data into an AI tool. Ask Out Sauce for clarification.
8.1 Out Sauce-Operated Systems
The rules above govern third-party AI tools used by personnel. Separately, Out Sauce operates internal systems of its own. These are Out Sauce-operated systems, not personnel tools, and each is governed by its own entry below.
Out Sauce's use of AI follows the same rules everywhere. No AI system reads client information unless the information is processed entirely within Australia, and the use has been assessed and approved under the Out Sauce vendor and AI governance framework and is recorded in the Approved AI Tools Register (OS-AIT-001). That register records every use approved for client information, with its permitted inputs, outputs, and conditions, and is available on request. The roster's current Out Sauce-operated systems are the knowledge base, which learns and retains de-identified patterns and Out Sauce Know-How; and internal software, which answers Out Sauce's own operational questions from live records and keeps nothing of what it reads.
Locus rule (applies to every Out Sauce-operated system): Identifiable client information (Personal Information, and any information that identifies a client) is processed only within Australia and is never sent to any AI model or service that would transfer it outside Australia. Specific AI models and services are assessed and approved under the Out Sauce vendor management framework (OS-VMP-001) before use, and no model is approved for identifiable client information unless it meets this in-Australia requirement.
Oversight (applies to every Out Sauce-operated system): A person makes every decision. No Out Sauce-operated system makes an automated decision affecting any individual, approves any third-party AI tool for Client Data, or changes the prohibitions in this policy.
8.1.1 Out Sauce Internal Knowledge Base (OS-KB-001)
Purpose: To build and maintain a single internal store of De-Identified and Aggregated knowledge (class 3.4) and Out Sauce Know-How (class 3.5) about how Out Sauce works (its methods, processes, drafting conventions, accumulated experience, and its working understanding of how each client firm and its advisers prefer their work prepared), so that Out Sauce delivers more consistent and higher-quality work. It draws on the advice documentation Out Sauce produces and on Out Sauce's own internal operating knowledge. The input rules below govern how that documentation is handled.
Permitted inputs by classification:
General: unrestricted.
Personal (client working files): permitted only as a transient compile-time input, read inside the Out Sauce-managed environment to identify the pattern, then discarded. Not retained. (Adviser identities and working preferences are relationship data Out Sauce already holds about a firm's portal users; their retention inside class 3.5 pages is governed by that class, not by this transient-read rule.)
Sensitive: never ingested. Sensitive Information (including tax file numbers, health information, and account numbers) is excluded or redacted before the knowledge base reads anything. No approval under Section 3.3 or the table above is granted for Sensitive input to this system.
Hosting and processing: The knowledge base operates under Out Sauce's control. The locus rule in 8.1 applies, and for the knowledge base it includes the de-identification step itself.
Output and retention: The knowledge base retains two classes of information: De-Identified and Aggregated information (class 3.4, the cross-firm layer, from which no person, client, or firm can be reconstructed) and Out Sauce Know-How (class 3.5, the firm/adviser-attributed layer, which never contains a firm's customers' Personal Information; see 3.5 for its boundaries and the per-slice test). It keeps no copy of any deliverable, and raw source documents are neither stored in nor retrievable through the system. Because the retained corpus contains no Client Data, destruction of a client file does not require extraction from the corpus. Class 3.5 material is processed and stored only within Australia, permanently (see 3.5 and OS-VMP-001 ยง5.1).
Oversight: Output is reviewed before reliance. The knowledge base makes no client-facing advice.
8.1.2 Out Sauce Internal Operations Software (OS-OPS-001)
Out Sauce has designed internal software to answer its own questions about its own live operational records, such as job status, turnaround, workload, and invoicing. It is not in use; what follows describes that design, and the Status below governs. As designed it is read-only, for authorised Out Sauce staff only, and it retains nothing of what it reads. It is a distinct system from the knowledge base, with a distinct purpose and distinct rules, and it forms no part of it.
Status: This software is currently in development and processes no Out Sauce data. Until its status in the Approved AI Tools Register (OS-AIT-001) reads Approved, that register's default position applies to it: no use with any Out Sauce data. The rules below govern it once approved, and bind from the moment it is.
Purpose: To answer Out Sauce's own operational questions from its own live records, so that Out Sauce can manage workload, turnaround, quality, and billing as part of running the service. It produces no client-facing output and no advice.
Permitted inputs by classification:
General: unrestricted.
Personal (Out Sauce's own operational records): a query-time read of a named allowlist of operational fields only. The allowlist covers job metadata (identifier, service type, firm, status, and dates), turnaround and workload figures, invoice and remittance amounts, and contractor work records, all of which are Personal-class business records under the note in 3.3. Everything outside the allowlist is structurally unreachable rather than merely prohibited: free-text job titles and descriptions, the line-item detail on invoices and remittances, document contents, message contents, and client working files cannot be reached at all. Firms that have opted out of AI use are excluded from every query and every aggregate.
Sensitive: never. No Sensitive Information (Section 3.3) is within reach of this system, and bank and account numbers are excluded by the allowlist itself, not by instruction. No approval under Section 3.3 or the table above is granted for Sensitive input to this system.
Hosting and processing: The software operates under Out Sauce's control. Its processing is query-time processing of live identifiable operational data, carried out entirely within Australia; the locus rule in 8.1 applies.
Output and retention: It retains nothing of what it reads. There are no copies, no transcripts, and no learning: nothing read at query time is stored, and nothing is retrievable through the system afterwards. Query text, tool arguments, tool results, and model responses are never logged; only operational metadata (timestamp, user identifier, model identifier, token counts, latency, and error class) is. Retention of the underlying operational records themselves is governed by Section 6.1 and is unchanged by this system.
Oversight: Output goes to an authorised Out Sauce administrator, and a person makes every decision. The software triggers no action, sends nothing, and writes nothing.
9. BREACH OF THIS POLICY
Deliberate or reckless breach of this policy is treated as a serious matter:
Contractors: Material breach under Contractors Agreement โ may result in immediate termination
Employees: Disciplinary action up to and including termination
Regulatory consequences: Depending on the breach, Out Sauce may be required to report to the applicable licensee, OAIC, or ASIC
Inadvertent breaches (e.g., accidentally emailing the wrong file) should be reported immediately. Self-reporting is treated constructively โ the goal is to contain and learn, not to punish honest mistakes.
This policy defines acceptable use of Out Sauce technology, systems, and information assets by Out Sauce employees. Contractor technology obligations are governed by the Contractors Agreement (Schedule B โ Technology & AI Use Policy), which mirrors and extends this policy.
2. SCOPE
Applies to all Out Sauce-owned or managed technology used by Out Sauce employees, including:
Out Sauce managed devices (laptops, any future desktops or mobile devices)
Any cloud services accessed through Out Sauce accounts
Internet access through Out Sauce managed devices
3. GENERAL PRINCIPLES
Out Sauce technology is provided for business purposes. Incidental personal use is acceptable provided it does not compromise security, consume excessive resources, or expose Out Sauce systems to risk.
Security monitoring of managed devices and systems is carried out by our IT security provider, Destiny IT, for information security and regulatory compliance only. It is never used for performance management, productivity tracking, or work supervision.
Users must not attempt to circumvent, disable, or interfere with security controls.
4. APPROVED USE
4.1 Software and Applications
Only software approved by Out Sauce and managed by Destiny IT may be installed on managed devices
Browser extensions must be approved โ do not install extensions without checking with Destiny IT
SaaS applications accessed via browser must be on the Approved Tools list when used with client data
Requests for new software should be directed to Out Sauce Operations โ Destiny IT for security assessment
4.2 Email and Communication
Use Out Sauce managed email for all business communication
Do not use personal email for any Out Sauce business
Do not forward Out Sauce email to personal accounts
Be cautious with email attachments and links โ report suspicious emails via Destiny IT's reporting mechanism
Do not send Sensitive Information via unencrypted email (see Data Handling Policy)
4.3 Internet Use
Internet use on managed devices should be primarily business-related
Incidental personal browsing is acceptable (news, weather, personal banking via secure sites)
Do not access sites that could compromise device security (pirated software, suspicious downloads)
Use mobile hotspot rather than public Wi-Fi; if public Wi-Fi is unavoidable, use approved VPN
4.4 Cloud Storage
Use Out Sauce-managed approved cloud storage for document storage
Do not sync Out Sauce data to personal cloud accounts
Do not share Out Sauce files via personal file-sharing services
4.5 AI Tools
Use only Approved AI Tools (see Contractors Agreement Schedule B (Technology & AI Use Policy, OS-SCHB-001) and the Approved AI Tools Register, OS-AIT-001)
Do not input Personal or Sensitive client data into any AI tool not specifically approved for that purpose
Disclose AI use in deliverables where AI materially contributed to content
You remain responsible for all outputs โ AI does not reduce your accountability
The rules above govern personnel use of third-party AI tools. Out Sauce's own internal AI systems are listed in OS-AIT-001 and governed under OS-AIT-001 and OS-DHP-001 ยง8.1. Listing is not approval: each entry is usable only while its own status in the register reads Approved. A system listed and approved there is not a "tool not specifically approved" under the prohibition above:
The knowledge base (OS-KB-001) reads Personal client information in client working files only transiently to identify the pattern, retains only de-identified aggregated data (class 3.4) and Out Sauce Know-How (class 3.5 โ Out Sauce's own working knowledge, never a firm's clients' personal information), and never ingests Sensitive client information.
The internal software (OS-OPS-001) answers Out Sauce's own questions about its own live operational records, such as job status, turnaround, workload, and invoicing. It is read-only and used by authorised Out Sauce staff only, a person makes every decision, and it retains nothing of what it reads: no copies, no transcripts, no learning. It never reads sensitive information, document contents, or client working files, and it processes information entirely within Australia. Governed by OS-DHP-001 ยง8.1.2. This software is currently in development and processes no Out Sauce data; until its status in the Approved AI Tools Register (OS-AIT-001) reads Approved, that register's default position applies to it: no use with any Out Sauce data.
5. PROHIBITED USE
The following are prohibited on Out Sauce managed devices and systems:
Installing unapproved software or browser extensions
Connecting any AI tool, agent, or session other than the approved harness to the internal software's data interface (the OS-OPS-001 MCP server). General-purpose AI CLI sessions and chat assistants must never be pointed at it.
Attempting to gain administrative access or elevate privileges
Disabling, modifying, or circumventing any security software or controls
Connecting USB drives or removable media containing client data
Transferring client data via Airdrop, Bluetooth, or other wireless file-sharing methods
Leaving Bluetooth enabled when not actively in use
Storing client data on personal devices, personal cloud, or personal email
Sharing passwords or login credentials with any other person
Saving passwords in browser autocomplete (use approved password manager only)
Using Out Sauce systems for illegal activity
Downloading or distributing pirated software, media, or content
Accessing or distributing inappropriate or offensive material
Using Out Sauce email or systems to impersonate another person
Making public statements about security incidents without Out Sauce Operations approval
6. PASSWORDS AND AUTHENTICATION
Use the approved enterprise password manager for all Out Sauce-related credentials
Passwords must be minimum 16 characters
Passwords must be unique โ do not reuse across accounts
Do not save passwords in browsers โ use the password manager only
MFA (authenticator app preferred) must be enabled on all systems accessing client data
Report any suspected credential compromise immediately
7. PHYSICAL SECURITY
Lock managed devices when unattended (screen lock: 10-minute auto-timeout)
Store managed devices securely when not in use (not visible in vehicles, not left in public spaces)
Do not leave managed devices unattended in public places
Report lost or stolen devices within 24 hours (Destiny IT can remote-lock and wipe)
Secure printed client documents โ shred when no longer needed
8. REMOTE WORKING
Out Sauce operates as a remote-first business. When working remotely:
Use the managed device for all Out Sauce work involving client data
Ensure your working environment is reasonably private (client data not visible on screen to unauthorised people)
Use mobile hotspot or secure home network โ avoid public Wi-Fi without VPN
Lock device when stepping away, even briefly
9. REPORTING
Report the following to Out Sauce Operations and/or Destiny IT:
Suspected phishing emails or social engineering attempts
Any unusual device behaviour (slowness, unexpected pop-ups, unfamiliar software)
Lost or stolen devices
Any suspected security incident (see Cyber Incident Response Plan)
Any situation where you're unsure whether an action is permitted under this policy
ClassificationInternal โ provided to clients and licensees on request
1. PURPOSE
This policy governs how access to Out Sauce systems, data, and resources is granted, managed, reviewed, and revoked. It implements the principle of least privilege โ every person gets only the access they need, when they need it.
2. SCOPE
Applies to all access to Out Sauce systems and data, including:
Any cloud services or SaaS platforms used for Out Sauce business
Physical access to Out Sauce equipment
3. PRINCIPLES
Least privilege: Grant the minimum access needed to perform the role
Need to know: Access to client data is limited to the specific engagements a person is working on
Separation of duties: Where practicable, no single person has unchecked access to all systems (the Director as sole principal is an exception โ mitigated by monitoring and audit trails)
Timely revocation: Access is removed promptly when no longer needed
Accountability: All access is attributed to a named individual โ no shared accounts
4. ACCESS ROLES
4.1 Out Sauce Access Roles
Role
Systems
Access Level
Assigned To
Operations / Admin
All Out Sauce systems, approved cloud platform admin, approved financial planning software (full)
Approved cloud platform accounts provisioned for their work
Approved financial planning software access limited to the specific clients they are assigned to work on
No admin rights on any system
No access to Out Sauce business/financial data, other contractors' work, or internal strategic documents
5. ACCESS LIFECYCLE
5.0 Personnel Vetting
Vetting is completed before a person is engaged and before any access is granted. It applies to every contract paraplanner, and to any employee whose role involves access to client information.
Check
What it covers
Responsible
Criminal history
Nationally Coordinated Criminal History Check (National Police Check)
Out Sauce Operations
Identity
Government-issued photographic identification, confirmed against the person named in the agreement
Out Sauce Operations
References
Direct contact with prior professional referees
Out Sauce Operations
Skills
Assessment of paraplanning competence against the work to be performed
Out Sauce Operations
No person is engaged, and no account or device is provisioned, until all four are complete.
Vetting records are held by Out Sauce Operations, are handled as Personal Information under OS-DHP-001, and are not disclosed outside Out Sauce. Vetting of a contractor's delegate is governed by the Contractors Agreement clause 5.1(b).
5.1 Onboarding โ New Contractor
Step
Action
Responsible
Timing
1
Personnel vetting completed (ยง5.0)
Out Sauce Operations
Before engagement
2
Signed Contractors Agreement received (including Schedules A, B, C)
Out Sauce Operations
Before any access granted
3
Security awareness training scheduled
Out Sauce Operations + Destiny IT
Within 30 days of device receipt
4
Managed device provisioned and configured
Destiny IT
Before first engagement
5
Approved cloud platform account created (managed tenant)
Out Sauce Business Continuity & Disaster Recovery Plan
Document IDOS-BCP-001
Version1.3
EffectiveMarch 2026
Version 1.3 effectiveAugust 2026
OwnerOut Sauce Operations
Review cycleAnnual or after any activation
ClassificationInternal โ provided to clients and licensees on request
1. PURPOSE
This plan ensures Out Sauce can maintain or rapidly restore critical business operations following a disruption โ whether from a cyber incident, system failure, natural disaster, or other cause. It establishes recovery priorities, procedures, and communication protocols.
2. Out Sauce BUSINESS PROFILE
Item
Detail
Business model
Cloud-first, remote workforce
Critical function
Paraplanning services (SOAs, ROAs, file notes) for financial advice clients
Out Sauce's cloud-first, remote model is inherently resilient. There is no single physical location whose loss would halt operations. The primary risks are: system/cloud outages, cyber incidents, and key person unavailability.
3. RECOVERY OBJECTIVES
Metric
Target
Rationale
Recovery Time Objective (RTO)
24 hours for critical systems; 72 hours for full operations
Clients expect responsive service; most work can tolerate 1-day gap
Recovery Point Objective (RPO)
24 hours (maximum data loss)
Approved cloud platform backups run daily (Destiny IT); work saved to cloud is near-real-time
Maximum Tolerable Downtime (MTD)
5 business days
Beyond this, client relationships and regulatory obligations are at risk
Next reviewAugust 2027, or on a material change to the business or its systems.
Method. Each function above was assessed for its operational, client, regulatory and financial impact at four points after a loss of service: 4 hours, 24 hours, 72 hours and 5 business days. Those judgements set the priority order in the table above and the recovery objectives in ยง3.
Function
4 hours
24 hours
72 hours
5 business days
Client communication
Queries queue. No delivery affected.
Live jobs cannot be clarified; firms begin chasing.
Firms escalate. Confidence starts to erode.
Firms treat Out Sauce as unreachable and place work elsewhere.
Access to existing client files
Work in progress pauses. No client-visible effect.
Delivery dates slip across all live jobs.
Committed deadlines are missed. Advisers' own client meetings are affected.
Advisers reconstruct the work themselves or reassign it.
Paraplanning production
Absorbed within normal turnaround.
Turnaround commitments at risk.
Turnaround commitments breached.
Material breach of service expectations across the client base.
Invoicing and payments
None.
None.
Cash collection delayed. Contractor payment timing at risk.
Contractor payments late, which is a direct people risk.
Regulatory impact. No Out Sauce function carries a statutory clock of its own. The regulatory exposure that does exist runs through incident notification: where a disruption is also a data breach, the assessment and notification obligations in OS-CIRP-001 ยง6 apply and are unaffected by the state of production systems.
Financial impact. Revenue is earned on delivered work, so a short disruption defers income rather than destroying it. The point at which the loss becomes permanent is the point at which advice firms redirect work, which the table above places at around five business days. That is why the Maximum Tolerable Downtime in ยง3 is set there.
Single points of failure identified. The managed IT provider, the cloud platform, and key person availability (ยง5.5). Each has a documented response in ยง5. The advice firm's own planning software is a dependency Out Sauce does not control, addressed at ยง5.3.
Assumptions. All work is performed on managed devices against cloud-hosted systems, so no Out Sauce function depends on a physical office. Personnel are geographically distributed, so a regional event affects a subset rather than the whole business.
5. DISRUPTION SCENARIOS AND RESPONSES
5.1 Scenario: Single Managed Device Failure
ImpactOne contractor unable to work
LikelihoodMedium
Contractor reports device failure to Out Sauce and Destiny IT
Destiny IT diagnoses remotely โ if recoverable, fix within SLA
If device is unrecoverable, Destiny IT manages device replacement or repair under manufacturer warranty arrangements
Contractor's cloud-stored work is intact (approved cloud platform backup)
RTO: 24-48 hours for device replacement; 0 data loss
5.2 Scenario: Cloud Platform Outage
ImpactAll users unable to access email, files, collaboration tools
LikelihoodLow (cloud platform provider SLA 99.9%+ (per vendor published SLA))
Monitor cloud platform service health dashboard
Communicate with contractors via phone/SMS (contact list maintained offline)
For short outages (<4 hours): wait for restoration
For extended outages (>4 hours): contractors continue offline work on managed devices; Out Sauce communicates client delays via phone
RTO: Dependent on cloud platform provider (SLA 99.9%+ (per vendor published SLA)) โ typically <4 hours for major outages
5.3 Scenario: Financial Planning Software Outage
ImpactUnable to access client files or produce SOAs
LikelihoodLow
Monitor vendor status page
Notify contractors of outage
Redirect contractors to work that doesn't require the platform (admin tasks, offline research)
Notify affected clients of potential delays
RTO: Dependent on vendor โ typically <24 hours
5.4 Scenario: Cyber Incident (Ransomware / Data Breach)
ImpactPotentially all systems and data
LikelihoodMedium
Activate Cyber Incident Response Plan (OS-CIRP-001) โ takes priority over BCP
Destiny IT leads technical response (containment, investigation)
Out Sauce communicates with contractors: "Stop all Out Sauce work until cleared"
Out Sauce communicates with affected clients per incident response plan
Recovery from approved cloud platform backups once Destiny IT confirms systems are clean
Out Sauce portal: recovery from the independent off-platform backup (6.4). It is held with a different provider, under separate credentials that cannot delete it, and under a 30-day immutability lock, so it remains available even if the portal's own hosting platform, credentials or infrastructure are compromised
RTO: 24-72 hours depending on severity
5.5 Scenario: Key Person Unavailability
ImpactBusiness operations and decision-making
LikelihoodLow (illness, accident)
ResponseIf any single Out Sauce team member (including Out Sauce Operations lead) is unavailable, remaining Out Sauce Operations staff sustain operations:
Short-term (<1 week): Other Out Sauce team members manage day-to-day operations. Contractors continue existing engagements autonomously. Destiny IT continues security operations independently.
Extended (>1 week): Out Sauce Operations contacts applicable licensees for guidance on obligations. Consider activating a nominated emergency contact (e.g., trusted industry peer or professional adviser) who can make decisions if needed.
All critical passwords and account access are documented in a secure location accessible to the Out Sauce Operations team.
5.6 Scenario: Internet Outage (Individual)
ImpactOne person unable to work remotely
LikelihoodMedium
Use mobile phone hotspot as backup internet connection
If prolonged, work from alternative location with internet access
Notify Out Sauce if unable to meet engagement deadlines
5.7 Scenario: Natural Disaster (Regional)
ImpactPotentially multiple users in affected area
LikelihoodLow
Cloud-first model means geographic redundancy is built in โ approved cloud platform data is replicated across provider data centres
Users outside the affected area continue working normally
Affected users resume when safe and connectivity restored
Client communication priorities maintained via phone
Synced to approved cloud storage; backed up via approved cloud platform
Near-real-time (cloud storage sync)
Per cloud platform backup retention
Destiny IT
Out Sauce portal database
Continuous streaming replication to cloud object storage on the hosting platform
Continuous (point-in-time recovery), plus one full snapshot daily
30-day point-in-time recovery window
Out Sauce
Out Sauce portal database and stored documents
Independent off-platform copy to a second cloud provider (see 6.4)
Nightly
30-day immutability lock. Documents 7 years; recruitment CVs 35 days
Out Sauce
6.2 Backup Testing
Automated restore verification: Destiny IT's backup platform performs automated restore integrity verification to confirm recoverability on an ongoing basis. Full manual restore testing is available on request as an additional service.
Out Sauce portal, nightly: each off-platform backup takes a checkpointed copy of the portal database and runs an integrity check on that copy before it is encrypted and uploaded. A failed check aborts the run rather than shipping a corrupt file, and the failure is raised through the backup monitor.
Out Sauce portal, monthly recovery verification: an independent check, running outside the infrastructure that produces the backups, retrieves the most recent off-platform copy, decrypts it using a key deliberately held nowhere on the servers that write it, and runs an integrity check on the decrypted result. It also fails if the most recent backup is more than three days old, so a backup that opens perfectly but has stopped being produced is caught rather than passed. This verifies that a backup can actually be retrieved and opened, not merely that it was written. Results report to a dead-man's-switch monitor, which alerts both on failure and on the check not running at all.
These two checks verify retrievability and integrity. They are distinct from a full restore rehearsal, in which a working system is rebuilt from a backup copy.
Out Sauce portal, full restore rehearsal: performed quarterly, and after any material change to the portal's hosting or architecture. A working copy of the portal is rebuilt from the independent off-platform backup (ยง6.4) into an isolated environment, with no change made to the live system, and the restored data is checked for completeness against the source. The elapsed time is measured.
Most recent rehearsal, 12 August 2026: pass. The rehearsal used the independent off-platform copy described in ยง6.4, restoring the nightly backup taken on 11 August 2026. Retrieving that copy, decrypting it and opening a working portal database from it took five seconds, and the rehearsal was performed twice with the same result. Verified on the restored copy: the database integrity check and the referential integrity check were both clean; all 27 encrypted fields decrypted successfully with no failures, covering contractor bank details and two-factor authentication secrets; all 46 stored document records held in the portal were present in the backup, with none unrecoverable; and five documents sampled across file types and sizes, from 193 bytes to 856 KB, restored byte for byte identical to the originals. Record counts matched the source system, the only differences being records created in the hours after the backup was taken, which is consistent with the recovery point objective in ยง3. One defect was found in the written recovery procedure itself, rather than in the backup, and was corrected the same day. The five second figure is the time to restore the data. It is not a measure of rebuilding the hosting environment end to end, so the Recovery Time Objective in ยง3 remains a target rather than a demonstrated time.
Rehearsal record: each rehearsal is recorded with its date, the backup copy used, the elapsed time, the completeness result, and any finding raised. Findings are tracked to closure and the record is available to a licensee on request.
Post-incident: If backups are used in incident recovery, the process is documented and reviewed
6.3 Backup Security
Backups are encrypted and isolated from the production network (per industry best practice)
Backup access is restricted to Destiny IT administrators
Backup integrity is monitored by Destiny IT
Out Sauce portal, off-platform copy: the database is encrypted before it leaves Out Sauce infrastructure. The keys required to read it are not held on the server that writes the backup, so a full compromise of that server does not expose the backups it has produced. Stored documents in the same copy are held under the storage provider's encryption at rest.
Write-only credentials: the credentials used to write the off-platform backup hold no read and no delete permission, so they cannot be used to retrieve or destroy it.
The Out Sauce portal holds client data, so its backup does not depend on a single provider. In addition to the continuous replication recorded in 6.1, a nightly copy of the portal database and its stored documents is written to a second cloud provider, independent of the platform that hosts the portal. A failure, account compromise or provider-side incident affecting one cannot reach the other.
Property
Position
Location
Melbourne, Australia. The copy does not leave Australia
Schedule
Nightly, 03:30 AEST. A run missed because the host was unavailable executes when it next starts, rather than being skipped
Immutability
Objects are written under a 30-day compliance lock. For that period they cannot be altered or deleted by anyone, Out Sauce included. This is what allows the copy to survive an incident that reaches the portal's own infrastructure
Access
Write-only credentials, holding no read and no delete permission
Encryption
Database encrypted before upload, to two independently held keys so that losing one remains recoverable. Documents held under provider-side encryption at rest
Retention
Database: nightly copies, plus a monthly copy retained long term. Documents: 7 years. Recruitment CVs: 35 days, held separately so recruitment material never falls under the long retention rule
Monitoring
A dead-man's-switch monitor alerts on failure or on a backup that does not run
Independence
Separate provider, separate account, separate credentials from the hosting platform
7. COMMUNICATION PLAN
7.1 During Disruption
Audience
Communication Method
Responsible
Timing
Contractors
Phone/SMS (primary), email if available
Out Sauce Operations
Within 2 hours of disruption
Clients (affected)
Phone call from Out Sauce Operations
Out Sauce Operations
Within 4 hours
Destiny IT
Phone + email (established support channels)
Out Sauce Operations
Immediately
Applicable licensee
Per licensee cyber policy (if applicable)
Out Sauce Operations
Per incident response plan
7.2 Planned Maintenance
Planned maintenance that will interrupt an advice firm's access to the Out Sauce portal is notified to that firm by email at least five business days in advance. The notice states the date, the expected start time, the expected duration, and which functions are affected.
Maintenance is scheduled outside 8am to 6pm AEST on business days wherever the work allows it.
Emergency maintenance, meaning work that cannot wait without putting security or data integrity at risk, is notified as soon as practicable, and always before the work starts where that is possible.
7.3 Contact List
Out Sauce maintains an offline (printed) contact list containing:
All contractor mobile numbers and personal email addresses
Destiny IT support phone number
Licensee risk team contacts
Cyber insurance claims contact
Key client contacts
This list is kept in a secure physical location accessible to Out Sauce Operations, and updated quarterly.
8. TESTING
Test
Frequency
Scope
Contact list verification
Quarterly
Confirm all numbers/emails are current
Backup restore verification
Ongoing (automated)
Backup platform self-tests restore integrity; full manual restore available on request
Portal recovery verification
Monthly
Independent retrieval, decryption and integrity check of the most recent off-platform copy (ยง6.2)
Portal full restore rehearsal
Quarterly
Rebuild a working portal from the off-platform backup, verify data completeness, measure elapsed time (ยง6.2)
Tabletop exercise
Annual
Walk through a scenario (combined with incident response plan testing)
Communication test
Annual
Test ability to reach all contractors via phone/SMS
9. PLAN MAINTENANCE
Reviewed annually or after any activation
Updated when: new systems introduced, team size changes significantly, contact details change
Out Sauce Operations is responsible for ensuring the plan remains current
ClassificationInternal โ summary available externally on request
1. PURPOSE
This policy establishes how Out Sauce collects, uses, stores, discloses, and protects personal information to a standard consistent with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and the Notifiable Data Breaches (NDB) scheme. Out Sauce is a paraplanning subcontractor and currently a small-business operator that is not itself an APP entity for the client information it handles; the advice firm is the responsible APP entity. Out Sauce voluntarily applies APP-aligned standards, supports advice firms within their compliance frameworks, and is preparing for the APPs to apply directly as the small-business exemption is removed.
2. SCOPE
Applies to all personal information handled by Out Sauce in the course of business, including:
Information about clients of financial advice firms (Out Sauce's clients' customers)
Information about Out Sauce's own clients (the advice firms)
Information about Out Sauce contractors and employees
Information about prospective clients, contractors, or employees
3. AUSTRALIAN PRIVACY PRINCIPLES โ Out Sauce ALIGNMENT
APP 1 โ Open and Transparent Management of Personal Information
Out Sauce maintains this policy and the Data Handling & Classification Policy (OS-DHP-001) to document how personal information is managed. These policies are available to individuals on request.
Automated processing: Out Sauce's AI and automated systems. Out Sauce's use of AI follows the same rules everywhere. No AI system reads client information unless the information is processed entirely within Australia, and the use has been assessed and approved under the Out Sauce vendor and AI governance framework and is recorded in the Approved AI Tools Register. The register records every use approved for client information, with its permitted inputs, outputs, and conditions, and is available on request. The systems Out Sauce operates are the knowledge base, which learns and retains de-identified patterns and Out Sauce Know-How; and internal software, which answers Out Sauce's own operational questions from live records and keeps nothing of what it reads.
The knowledge base (OS-KB-001). The knowledge base identifies general patterns and methods from the work Out Sauce produces, so that Out Sauce delivers more consistent and higher-quality services. It holds two kinds of learning. Cross-engagement patterns are pooled only on a de-identified and aggregated basis (data class 3.4): a standard the knowledge base must actually meet, meaning patterns, methods, and know-how learned across multiple engagements, from which no individual person, client, or firm can be reconstructed, and which do not include or reproduce any specific advice or deliverable. Separately, it holds Out Sauce Know-How (data class 3.5): Out Sauce's own working knowledge of how each client firm and its advisers prefer their work prepared. Know-How can include the names and working preferences of a firm's advisers โ personal information Out Sauce holds about its portal users in its own right and discloses in its privacy collection notices โ but it never includes personal information of a firm's clients and never includes copies of any documents. Personal information in client working files is read only transiently, to identify the pattern, and is then discarded; it is de-identified before any pattern is pooled across engagements. Sensitive information (including tax file numbers, health information, and account numbers) is never read by the knowledge base; it is excluded or redacted before the knowledge base reads anything. Identifiable client information, including during the de-identification step, is processed only within Australia and is never sent to an AI model or service outside Australia; firm-attributed Know-How likewise remains within Australia permanently (the models and services used are assessed and approved under Out Sauce's vendor management framework before use). The knowledge base makes no automated decision affecting any individual: its output is general organisational knowledge, reviewed before reliance, not a decision about a person. Full handling rules are in the Data Handling & Classification Policy (OS-DHP-001, Section 8.1).
The internal operations software (OS-OPS-001). Out Sauce has designed internal software to answer its own questions about its own live operational records, such as job status, turnaround, workload, and invoicing. It is not in use; what follows describes that design, and the status at the end of this paragraph governs. As designed it is read-only and for authorised Out Sauce staff only, a person makes every decision, and it retains nothing of what it reads: no copies, no transcripts, no learning. It never reads sensitive information, document contents, or client working files, and it processes information entirely within Australia. Its output is decision support for Out Sauce's own operational management: it makes no automated decision affecting any individual, and every decision that follows is made by a person. Full handling rules are in the Data Handling & Classification Policy (OS-DHP-001, Section 8.1.2). This software is currently in development and processes no Out Sauce data; until its status in the Approved AI Tools Register (OS-AIT-001) reads Approved, that register's default position applies to it: no use with any Out Sauce data.
APP 2 โ Anonymity and Pseudonymity
Where practicable, Out Sauce allows individuals to interact anonymously (e.g., general enquiries). However, the nature of paraplanning services requires identification of clients for regulatory and professional purposes.
APP 3 โ Collection of Personal Information
Out Sauce collects personal information only where reasonably necessary for providing paraplanning services
Personal information collected for that purpose is also read transiently, on a de-identified basis, to identify the general service-improvement patterns described under APP 1. This is not a separate collection and does not expand what is collected
Collection is from the advice firm (Out Sauce's client) โ Out Sauce does not typically collect information directly from end consumers
Out Sauce collects Sensitive Information only where required for the specific advice engagement (e.g., health information for risk insurance, financial details for investment advice)
Individuals are notified of collection through the advice firm's own privacy notices
APP 4 โ Dealing with Unsolicited Information
If Out Sauce receives personal information it did not request and does not need:
Assess whether it would have been permitted to collect it
If not, destroy or de-identify the information as soon as practicable
APP 5 โ Notification of Collection
Out Sauce relies on the advice firm (as the primary entity in the client relationship) to notify individuals about collection. Out Sauce's privacy information is available on request for inclusion in advice firm disclosures. This notice chain extends to the knowledge base described under APP 1: because Out Sauce processes the advice firm's client information, advice firms should ensure their own privacy notices reflect that their paraplanning provider may read that information transiently, on a de-identified basis, to derive general service-improvement patterns. (Out Sauce's own working knowledge of how the firm and its advisers prefer their work prepared concerns the firm and its advisers, not the firm's clients, so it does not enter this notice chain; it is disclosed directly to firms and advisers in Out Sauce's privacy policy.) (The internal operations software (OS-OPS-001) does not enter this notice chain either: its query-time read of Out Sauce's own operational records, to answer Out Sauce's own questions about the service it is delivering, is use for the primary purpose under the firm's existing service-provider disclosures, and it retains nothing of what it reads.) Out Sauce will supply summary wording for this purpose on request.
APP 6 โ Use or Disclosure of Personal Information
Out Sauce uses personal information only for:
The purpose for which it was collected (providing paraplanning services)
A directly related secondary purpose the individual would reasonably expect
Where required or authorised by law (e.g., regulatory reporting, AML/CTF obligations)
Out Sauce does not:
Sell personal information
Use personal information for direct marketing
Disclose personal information to overseas recipients (unless the advice firm's client has overseas connections and disclosure is necessary for the engagement)
Share personal information between unrelated Out Sauce clients
Out Sauce's internal knowledge base (OS-KB-001) identifies general patterns and methods to improve its services. Cross-engagement learning happens only on a de-identified and aggregated basis: personal information is de-identified before any pattern is pooled across engagements. Because de-identified and aggregated material is not personal information, that learning is not a use or disclosure of personal information, does not share personal information between clients, and is consistent with the commitments above. Separately, Out Sauce Know-How (APP 1) records how each client firm and its advisers prefer their work prepared. Where it notes an adviser's name and working preferences, that is a use of the adviser's personal information โ information Out Sauce holds in its own right as service-relationship data. It stands on its own APP 6 footing: it is disclosed in Out Sauce's privacy policy, it is directly related to the purpose for which the information was collected (delivering and improving the service the adviser receives), and it is a use an adviser would reasonably expect of a professional services provider. It never involves a firm's clients' personal information and is never disclosed to any other client.
Separately again, the internal operations software (OS-OPS-001) answers Out Sauce's own questions about its own live operational records, such as job status, turnaround, workload, and invoicing. That is use for the primary purpose for which the information was collected, and for the ordinary business administration of delivering the service. It does not learn, it pools nothing across engagements, and it retains nothing of what it reads, so it shares no personal information between clients and creates no secondary use. Both systems are described under APP 1.
APP 7 โ Direct Marketing
Out Sauce does not use personal information collected through paraplanning services for direct marketing.
APP 8 โ Cross-Border Disclosure
Overseas disclosure is limited to the single service provider below, used as a routine part of running the business. It is named in the portal's privacy notice, so individuals are told who their information is disclosed to and where.
Accounting and invoicing (United States). Contact and billing details are held in the accounting platform.
Before any overseas disclosure Out Sauce takes steps that are reasonable in the circumstances to ensure the recipient handles personal information consistently with the Australian Privacy Principles, including through the data processing terms in its agreement with that provider.
Everything else remains in Australia. Portal invitations and notification email are delivered through a transactional email provider that holds and processes that data in Australia. Client working files, Deliverables, document contents and message contents are stored and processed only within Australia (OS-DHP-001 ยง8.1), and the portal's independent backup copy is held in a second Australian region (OS-BCP-001 ยง6.4).
If a client engagement itself requires an overseas disclosure (for example, international estate planning), Out Sauce complies with APP 8 and the advice firm's instructions.
The internal knowledge base (APP 1) does not create a cross-border disclosure. Identifiable client information, including during the de-identification step, is processed only within Australia and is never sent to an AI model or service that would transfer it outside Australia. Once material has been de-identified and aggregated it is no longer personal information, so APP 8 does not apply to it. Out Sauce Know-How (class 3.5) is stored and processed only within Australia, permanently, so it creates no cross-border disclosure either.
The internal operations software (APP 1) creates no cross-border disclosure either. It processes information entirely within Australia and is never sent to an AI model or service that would transfer it outside Australia, and it retains nothing of what it reads.
APP 9 โ Government-Related Identifiers
Out Sauce does not adopt, use, or disclose government identifiers (e.g., TFN, Medicare number) as its own identifier. Government identifiers are handled per the Data Handling & Classification Policy (Sensitive Information classification).
APP 10 โ Quality of Personal Information
Out Sauce takes reasonable steps to ensure personal information is accurate, up-to-date, and complete. Where Out Sauce identifies inaccuracies in client data, it notifies the advice firm.
APP 11 โ Security of Personal Information
Out Sauce protects personal information through:
The full security framework documented in the Information Security Policy (OS-ISP-001)
Destiny IT managed services (EDR, SIEM, DLP, encryption, patching)
Data classification and handling requirements (OS-DHP-001)
Contractor obligations (Contractors Agreement, Schedule B)
When personal information is no longer needed and not subject to retention requirements, it is securely destroyed (see Data Handling & Classification Policy, Section 6).
The internal knowledge base (APP 1) does not hold client personal information for the long term. Personal information in client working files read during compilation is transient and is discarded after the pattern is identified; what the knowledge base retains is de-identified and aggregated patterns (not personal information) and Out Sauce Know-How (Out Sauce's own working knowledge, which never contains a firm's clients' personal information). The adviser names and working preferences within Out Sauce Know-How are relationship data Out Sauce holds in its own right, retained while useful and secured under this policy's controls. A persistent knowledge base is therefore consistent with this principle: destroying client personal information when it is no longer needed does not require deleting de-identified patterns or Out Sauce's own working knowledge, because neither contains a firm's clients' personal information (see OS-DHP-001, Sections 3.5, 6 and 8.1).
The internal operations software (APP 1) holds nothing at all. Its reads are query-time only and it retains nothing of what it reads: no copies, no transcripts, no learning. Nothing is held, so there is nothing to destroy and no retention period applies to it. It reads operational records only, never sensitive information, document contents, or client working files, and it processes information entirely within Australia (see OS-DHP-001, Section 8.1.2).
APP 12 โ Access to Personal Information
Individuals have a right to request access to the personal information held about them. The advice firm, as the responsible APP entity, is the primary channel for access requests, and in practice most requests come through the firm. Out Sauce supports the firm and, for any request it handles directly, will:
Respond to access requests within 30 days
Provide information in the format requested (where reasonable)
Not charge for making a request (may charge reasonable costs for providing access)
Refuse access only where permitted by law (e.g., commercially sensitive information, ongoing legal proceedings)
APP 13 โ Correction of Personal Information
If Out Sauce becomes aware that personal information is inaccurate, out of date, incomplete, or misleading:
Out Sauce takes reasonable steps to correct the information
Notifies the advice firm of the correction
If Out Sauce refuses a correction request, it provides written reasons and information about complaint mechanisms
4. NOTIFIABLE DATA BREACHES
Out Sauce is currently a small-business operator and is not itself an APP entity for client information; the advice firm is the responsible entity that carries the statutory NDB obligation. Out Sauce's role is to detect, contain, assess, and notify the responsible firm promptly so the firm can meet its obligations. Where Out Sauce is the responsible entity for a breach of information it holds in its own right, it makes the required notifications consistently with the NDB scheme.
4.1 When Does the NDB Scheme Apply?
A data breach is "eligible" for notification if:
There is unauthorised access to, disclosure of, or loss of personal information
A reasonable person would conclude the breach is likely to result in serious harm to any of the affected individuals
Out Sauce has been unable to prevent the likely risk of serious harm through remedial action
4.2 Out Sauce's Breach Response Process (supporting the responsible entity)
Step
Timeframe
Action
Detect
Ongoing (24/7 via Destiny IT monitoring)
Incident identified through monitoring, contractor report, or third-party notification
Contain
Immediately
Per Cyber Incident Response Plan โ stop the breach from getting worse
Assess
Begin within 24 hours of awareness; aligned to the responsible firm's statutory timeframe (30 days Privacy Act) and licensee cyber policy (typically 7 days)
Assess the incident to support the firm's eligibility determination, considering type of data, volume, who accessed it, encryption status, and likelihood of serious harm
Remediate
Concurrent
Take steps to reduce risk of harm (password resets, account monitoring, etc.)
Notify the firm / licensee
Within 24 hours of Out Sauce awareness; formal assessment within 7 days
Notify the responsible advice firm promptly with the detail it needs (nature of the breach, information involved, steps taken) so it can meet its NDB obligations and any licensee cyber policy requirements
Support OAIC / individual notification
As required by the responsible entity
The firm, as the APP entity, notifies the OAIC and affected individuals where the breach is eligible; Out Sauce provides the assessment detail and supporting information. Where Out Sauce is itself the responsible entity, it makes these notifications consistently with the NDB scheme
4.3 Serious Harm Assessment Factors
When assessing whether serious harm is likely, Out Sauce considers:
The kind of information involved (TFN, financial details, health info = higher risk)
Whether the information is encrypted or otherwise protected
The person(s) who obtained or could obtain the information
Whether the breach could result in identity theft, financial loss, or reputational damage
The nature of the harm that could result
4.4 Record Keeping
Out Sauce maintains records of:
All data breaches (whether or not eligible for notification)
All NDB assessments
All notifications made
All remedial actions taken
Records retained for 7 years.
5. PRIVACY RISK MANAGEMENT
Out Sauce recognises that privacy obligations continue to evolve, with increasing expectations around proportionality, data minimisation, and informed consent for monitoring. Out Sauce proactively manages these risks through:
Device and security monitoring: Out Sauce ensures security monitoring on managed devices is proportionate, informed consent is obtained, and that it is carried out for information security and regulatory compliance only, never for performance management, productivity tracking, or work supervision. The Contractors Agreement (Schedule A, Clause 5) addresses this. Managing workload, turnaround, and quality from ordinary portal work records is a separate activity, described in Section 6.2.
Data minimisation: Out Sauce does not collect or retain more personal information than necessary. The internal knowledge base (APP 1) is consistent with this: it retains de-identified and aggregated patterns and Out Sauce's own working knowledge (never a firm's clients' personal information, never document copies), and the client-file personal information it reads during compilation is transient and then discarded. The internal operations software (APP 1) is consistent with it by design: it reads existing operational records at query time and retains nothing of what it reads, so it collects nothing new and adds nothing to what Out Sauce holds.
Proportionality: Security measures are proportionate to the risk.
Out Sauce mitigates privacy risk through:
Explicit, informed consent for security monitoring (Schedule A)
Clear limitation of security monitoring on managed devices to security purposes (it is never used for performance management, productivity tracking, or work supervision)
Data minimisation principles (Data Handling Policy)
Regular review of monitoring scope and proportionality
6. CONTRACTOR AND EMPLOYEE PRIVACY
6.1 Information Out Sauce Holds About Contractors
Business entity details, ABN, contact information
Bank details for payment
Insurance certificates of currency
Training completion records
Security incident reports (if any)
Device assignment and access records
Portal work records: job assignments, turnaround and delivery times, quality outcomes, and fee-adjustment records
This information is collected with consent (via the Contractors Agreement) and used only for managing the contractor relationship and delivering the service.
6.2 Monitoring and Privacy
Security monitoring of managed devices and systems is carried out by our IT security provider, Destiny IT, for information security and regulatory compliance only. It is never used for performance management, productivity tracking, or work supervision. Separately, like any professional services firm, Out Sauce manages workload, turnaround, and quality as part of running the service. That management uses ordinary work records in the portal, not security monitoring. Internal software may help analyse those work records, and decisions about workload and engagement are always made by a person. That software (OS-OPS-001) is currently in development and processes no Out Sauce data; until its status in the Approved AI Tools Register (OS-AIT-001) reads Approved, that register's default position applies to it: no use with any Out Sauce data.
Security monitoring on managed devices is limited to threat detection and data protection
Monitoring data is accessible only to Destiny IT (for security) and Out Sauce (for incident response)
Contractors are fully informed of monitoring scope before consenting
6.3 Employee Privacy
Out Sauce holds standard employment records for Out Sauce Operations (exempt from APPs under the employee records exemption)
Despite the exemption, Out Sauce applies the same standards as for contractor information
7. COMPLAINTS
If any individual believes Out Sauce has breached their privacy:
This policy governs how Out Sauce assesses, engages, monitors, and manages third-party vendors and service providers that have access to Out Sauce systems, data, or operations. It ensures that Out Sauce's security and privacy standards are maintained across the supply chain.
2. SCOPE
Applies to all third-party relationships where the third party:
Accesses, processes, or stores Out Sauce or client data
Provides IT or technology services to Out Sauce
Has connectivity to Out Sauce systems or infrastructure
Provides professional services involving confidential business information
3. THIRD-PARTY RISK TIERS
Tier
Criteria
Examples
Assessment Level
Tier 1 โ Critical
Ongoing access to client data or Out Sauce systems; business-critical service
Limited or no access to client data; general business services
Office supplies, general SaaS tools not handling client data, website hosting
Basic assessment
4. ASSESSMENT CRITERIA
4.1 Pre-Engagement Assessment
Before engaging a Tier 1 or Tier 2 vendor, Out Sauce carries out a documentary review: an assessment of what the vendor publishes and what it commits to contractually. Out Sauce is a small business and does not hold negotiating power over the large platform vendors it uses, so it does not issue bespoke security questionnaires or require vendors to produce evidence beyond their published certifications and terms. What it does instead is check that those published positions exist, are current, and are adequate for the data involved.
Criterion
What Out Sauce Looks For
Security posture
Published certifications (ISO 27001, SOC 2) and the currency of the associated certificate or report
Data residency
Where data is stored and processed, whether the service can be pinned to Australian regions, and whether that is a contractual commitment or a configuration setting
Data handling
Encryption at rest and in transit, stated retention and deletion practices, access controls
Privacy compliance
Published privacy policy, APP or equivalent compliance position, and the terms of the vendor's data processing agreement
Subcontracting
The vendor's published sub-processor list and its notification terms for changes to it
AI / model vendors
Whether the vendor trains on or reuses our inputs; inference data residency (jurisdiction); de-identification guarantees; absence of automated decision-making on client outcomes
Service continuity
Published SLA and uptime commitments
Insurance is not sought from software vendors. Requiring a certificate of currency from a global SaaS provider is not achievable for a business of Out Sauce's size, and Out Sauce does not claim to do it. Where a third party supplies services rather than software, and the relationship supports it, certificates of currency are obtained and held. The managed IT provider is the current instance, recorded in ยง5.
4.2 Requirements Out Sauce Meets as an External Outsource Provider
Leading licensee cyber policy standards set requirements for external outsource providers. Out Sauce meets these in its own right, as the provider:
Professional Indemnity Insurance held by Out Sauce. This is business-wide cover and it extends to the contract paraplanners engaged on client work, so cover does not depend on any individual contractor holding a separate policy.
Cyber Insurance Policy held by Out Sauce.
Certificates of Currency for both, provided to licensees on request.
Approved transfer methods only for client data: the advice firm's own planning software, approved cloud storage, or encrypted email.
Software licensing held by Out Sauce.
These obligations sit with Out Sauce as the outsource provider to the licensee. They are not passed down to Out Sauce's own software vendors, which are assessed under ยง4.1 by documentary review instead.
5. CURRENT VENDOR REGISTER
Vendors are recorded here by the function they perform rather than by product name. This is deliberate. A licensee's due diligence interest is in whether a vendor management process exists, whether each vendor has been assessed, and what assurance is held for the data involved, and every one of those questions is answered below. Publishing a component-by-component inventory of Out Sauce's technology stack answers none of them and creates a reconnaissance aid for anyone targeting the business. A named register is maintained internally and is available to a licensee on request.
Two exceptions are named. The managed IT provider is named because the relationship itself is part of Out Sauce's security posture and licensees ask about it directly. Service providers that receive personal information are named separately in Out Sauce's privacy policy, where naming them serves a different purpose: telling individuals who their information is disclosed to, including overseas.
Tier 3 services, which have limited or no access to client data, are not individually registered.
Vendor
Tier
Service
Data Access
Assurance Held
Last Review
Destiny IT
1 โ Critical
Managed IT services, security, monitoring
Full system access (security admin)
ISO 27001:2022, certificate 6686-3757-01, issued by Compass Assurance Services under JAS-ANZ accreditation M5310713AO, certified 14 November 2024, expires 14 November 2027. Chubb PremierTech2 COC to 1 October 2027
March 2026
Cloud platform provider
1 โ Critical
Cloud productivity, email and storage; hosting for the Out Sauce portal and its database
Out Sauce business data and client data, in Australian regions
ISO 27001 and SOC 2 certified. Australian region pinning. Published data processing terms
July 2026
Independent backup storage
1 โ Critical
Nightly off-platform backup of the portal database and documents, held with a provider independent of the primary cloud platform so that a failure or compromise of one does not reach the other
A copy of the portal database, encrypted before it leaves Out Sauce so the provider cannot read it, and copies of stored documents held under provider-side encryption at rest
ISO 27001 and SOC 2 certified. Melbourne, Australia. Write-only credentials holding no read and no delete permission. 30-day immutability lock
July 2026
Electronic signature provider
2 โ Significant
Electronic signing of service and contractor agreements
ISO 27001 and SOC 2 certified. Documents stored in Australia
July 2026
Application hosting (signing service)
2 โ Significant
Hosting for the service that assembles signing envelopes and serves executed agreements back to the portal
Signatory names, contact details, executed agreements in transit
SOC 2 Type II. Infrastructure in ISO 27001 certified datacentres. Sydney, Australia
July 2026
Approved accounting software
2 โ Significant
Accounting, invoicing
Out Sauce financial data, contractor payment data. United States
ISO 27001 and SOC 2 certified. Published data processing terms
July 2026
Transactional email provider
2 โ Significant
Portal invitations and notification email
Recipient names and email addresses. Australia
ISO 27001 and SOC 2 certified. Sydney, Australia. Published data processing terms
July 2026
Network and DNS provider
2 โ Significant
Domain, DNS and network edge services
Traffic in transit. No stored client data
ISO 27001 and SOC 2 certified
July 2026
Destiny IT's ISO 27001 certificate and its cyber liability certificate of currency may be provided to any Out Sauce client on request.
Overseas disclosure is limited to the single vendor marked United States above, and is disclosed to individuals in Out Sauce's privacy policy. All other client data remains in Australia.
5.0 Advice firm planning software is not an Out Sauce vendor
Out Sauce works inside each advice firm's own financial planning system, under access that the firm grants and controls. Out Sauce does not select, procure, pay for or administer that software, holds no contract with its publisher, and cannot obtain vendor assurance in respect of it. It is therefore not an Out Sauce vendor and is not registered above.
This is a deliberate position rather than a gap. Because the work is done inside the firm's own system, Out Sauce holds no separate copy of the firm's client file data, and the firm retains full control over Out Sauce's access to it, including the ability to withdraw that access immediately. Out Sauce's obligations in respect of that access are governed by the Access Management Policy (OS-AMP-001) and the Data Handling & Classification Policy (OS-DHP-001), and by the terms of the firm's own engagement with its software provider.
5.1 AI Model Processing
Out Sauce's use of AI follows the same rules everywhere. No AI system reads client information unless the information is processed entirely within Australia, and the use has been assessed and approved under the Out Sauce vendor and AI governance framework and is recorded in the Approved AI Tools Register. The register records every use approved for client information, with its permitted inputs, outputs, and conditions, and is available on request.
The systems Out Sauce operates itself are listed in that register (OS-AIT-001) and currently comprise the knowledge base, which learns and retains de-identified patterns and Out Sauce Know-How; and internal software, which answers Out Sauce's own operational questions from live records and keeps nothing of what it reads. The model-locus position for client information is:
Identifiable client information (Personal Information, and any information that identifies a client) is processed only within Australia, including during de-identification, and is never sent to an AI model or service that would transfer it outside Australia. Once information has been de-identified and aggregated it is no longer client information and may be processed under the Out Sauce vendor management framework. The specific AI models and services used are assessed and approved under that framework before use.
Out Sauce does not currently engage a third-party AI model vendor for client data. Any stage-2 AI model or service that processes De-Identified and Aggregated material (data class 3.4) will be assessed under ยง4 (including the AI / model vendor criterion) and registered here as a Tier 1 sub-processor before use. Specific tools are named at build time. The stage-1 in-Australia de-identification guarantee is held by OS-DHP-001 ยง8.1; approved AI tooling is governed by OS-AIT-001; the re-identification and secondary-use risk (including any stage-2 model as an exfiltration surface) is tracked in the Risk Assessment Register (OS-RAR-001).
Third processing mode: query-time processing of live operational data. Out Sauce's internal operations software (OS-OPS-001, governed by OS-DHP-001 ยง8.1.2) fits neither stage above. It processes live identifiable operational data at query time rather than de-identifying it first, so it is governed as a third processing mode with its own conditions: processing entirely within Australia; only through a tool assessed and approved under this framework and registered in OS-AIT-001; and zero retention of what is read, vendor-side included, meaning no training, no content logging, and no retention by the inference provider (register D5). The inference vendor supporting that mode is assessed under ยง4, including the AI / model vendor criterion, and registered in the vendor register above as a Tier 1 sub-processor before any use, mirroring the commitment made for any stage-2 model in the paragraph above. This software is currently in development and processes no Out Sauce data; until its status in the Approved AI Tools Register (OS-AIT-001) reads Approved, that register's default position applies to it: no use with any Out Sauce data.
Out Sauce Know-How (data class 3.5) โ deliberate position, adopted July 2026: firm-attributed know-how identifies a client firm (and can identify its advisers), so it remains "information that identifies a client" under the model-locus statement above and never qualifies for stage-2 processing. Class 3.5 material is processed and stored only within Australia, permanently. This is not a provisional gap awaiting a future stage-2 assessment; it is the adopted position (OS-DHP-001 ยง3.5): the stage-2 freedom applies to class 3.4 only. Any AI model or service that processes class 3.5 material must meet the same in-Australia requirement as identifiable client information.
6. ONGOING MONITORING
6.1 Annual Review
All Tier 1 and Tier 2 vendors are reviewed annually. The review repeats the documentary check at ยง4.1:
Confirm the vendor's security certifications remain current, and that no certification has lapsed or narrowed in scope
Confirm stated data residency is unchanged
Review any changes to the vendor's terms, data processing agreement, or published sub-processor list
Review any security incident the vendor has disclosed publicly or notified to Out Sauce
Where a certificate of currency is held (see ยง4.1), confirm it remains current and obtain the renewal
6.2 Continuous Monitoring
For Tier 1 vendors:
Subscribe to vendor security bulletins and incident notifications
Monitor vendor uptime and service quality against SLA
Review any changes to vendor's privacy policy or terms of service
6.3 Incident Response
If a vendor experiences a security incident that may affect Out Sauce data:
Activate Cyber Incident Response Plan (OS-CIRP-001)
Demand information from the vendor about scope, impact, and remediation
Assess whether Out Sauce's own NDB obligations are triggered
Notify applicable licensee if required
6.4 Notifying Clients of Vendor and Data Location Changes
Out Sauce notifies each affected advice firm in writing before it adds or replaces a Tier 1 or Tier 2 vendor that handles that firm's data, and before the country or region in which that data is held changes.
Notice is given at least 30 days before the change takes effect. Where that is not possible because of a vendor failure, a security incident, or a vendor's own notice period, notice is given as soon as practicable and the reason for the shorter period is stated.
The notice sets out which vendor is changing, the function it performs, where the data will be held, and the assurance held for the incoming vendor.
The change is assessed under ยง4.1 before it takes effect, and the register at ยง5 and the internal named register are updated at the same time. Where a vendor changes its own sub-processors or the location of the data it holds, Out Sauce passes that notice on to the affected firms.
7. CONTRACT REQUIREMENTS
Out Sauce's agreements with Tier 1 and Tier 2 vendors should include (where Out Sauce has negotiating power):
Requirement
Purpose
Confidentiality obligations
Protect Out Sauce and client data
Data handling and storage location
Ensure data remains in approved jurisdictions
Notification of security incidents
Timely notification to Out Sauce
Right to audit
Out Sauce can assess vendor's compliance (proportionate to relationship)
Data return/destruction on termination
Out Sauce can recover its data and ensure it's destroyed
Subcontracting restrictions
Vendor must notify Out Sauce of material subcontracting
Compliance with applicable laws
Privacy Act, relevant regulations
Practical note: Out Sauce has no negotiating power over the terms offered by large platform vendors, and does not represent otherwise. For those vendors the terms above are read rather than negotiated: Out Sauce relies on the vendor's published security certifications, standard terms, data processing agreement and SLAs, and the assessment is whether those published positions are adequate for the data involved. Where they are not, the vendor is not used for that data. Negotiated terms are sought only where the relationship supports it, which in practice means the managed IT provider.
8. OFFBOARDING VENDORS
When a vendor relationship ends:
Revoke vendor's access to Out Sauce systems (within 24 hours)
Request return or certified destruction of Out Sauce data
Rotate any credentials the vendor had access to
Update vendor register
Retain records of the vendor relationship for 7 years
ClassificationExternal โ included in Out Sauce Security Submission Pack
1. PURPOSE
This framework establishes Out Sauce's security awareness and training program. Its goal is to ensure every person handling Out Sauce data understands the risks, knows the rules, and can recognise and respond to threats.
2. SCOPE
Applies to:
Out Sauce employees (Out Sauce Operations)
All contract paraplanners
Any future employees, contractors, or approved delegates
3. TRAINING REQUIREMENTS
Requirement
Standard
Annual security awareness training
Minimum 2 hours per year for all personnel
Phishing simulations
Simulated phishing exercises for all personnel
Policy acknowledgment
Annual acknowledgment of Out Sauce policy suite
Onboarding
Security orientation before or within 30 days of receiving managed device
4. TRAINING PROGRAM
4.1 Security Awareness Training
Security awareness training and phishing simulations are provided through Out Sauce's managed IT services agreement with Destiny IT. This is an included service covering all managed users.
Training is delivered via a video platform through Destiny IT's security provider, with content delivered on a monthly or bi-monthly basis. Training covers security awareness relevant to Out Sauce's operating environment, including recognition and response to cyber threats.
4.2 Out Sauce-Delivered Training
Out Sauce delivers the following directly:
Onboarding orientation โ Out Sauce security framework, key policies, data handling rules, managed device overview
Policy updates โ notification and summary when policies are updated
Incident debriefs โ lessons learned following any security incident
AI and data handling โ Out Sauce's data classification and approved handling methods
4.3 Phishing Simulations
Simulated phishing exercises are provided by Destiny IT as part of its security services to Out Sauce, and will be delivered monthly or bi-monthly depending on requirements. Phishing resistance testing is integrated with the security awareness training platform. Results are used for training purposes โ not performance management.
5. TRACKING AND EVIDENCE
5.1 Training Register
Training completion and phishing simulation results are recorded in the training platform delivered through Destiny IT.
Out Sauce maintains a consolidated training register documenting:
Who completed what training
When it was completed
Completion evidence
Phishing simulation results
The consolidated register is maintained by Out Sauce Operations as an internal record.
5.2 Licensee Reporting
Training completion and phishing simulation results are recorded in the training platform delivered through Destiny IT
Where reporting on training is required, it is arranged through the responsible advice firm
This register provides a centralised record of all Out Sauce policy and procedure documents, their review status, and review history. It ensures that the Out Sauce security and operational document suite remains current, accurate, and aligned with regulatory requirements, threat landscape changes, and business operations.
All Out Sauce documents must be reviewed at least annually or when triggered by specific events outlined in this register.
Dating convention. Each document's own header carries two dates. Effective is the date the document first took effect and does not change when the document is amended. Version X.Y effective is the date the version named in the header took effect, which for an amended document is the date of its most recent amendment. A document still at version 1.0 carries only the first of these, because the two dates are the same. The Current Version Date column below mirrors each document's Version X.Y effective date, so the register and the document itself can be checked against one another.
In addition to the scheduled annual review, any Out Sauce document must be reviewed immediately when any of the following triggers occur:
3.1 Security Incident
A cyber security incident has occurred that exposed a gap or weakness in existing policy
A near-miss event that revealed inadequate controls or procedures
A phishing simulation result indicating systemic training or policy failures
3.2 Regulatory Change
New or amended ASIC regulatory guidance affecting financial services security obligations
Changes to the Privacy Act, Australian Privacy Principles, or notifiable data breach scheme
New or updated licensee security requirements or due diligence expectations
Changes to industry standards referenced in Out Sauce policies (e.g., Essential Eight, ISO 27001)
3.3 Operational Change
Onboarding of a new licensee or significant change to licensee arrangements
Addition or removal of a third-party vendor or IT service provider
Material change to Out Sauce business operations, staffing model, or service delivery
Introduction of new technology, tools, or platforms into the Out Sauce environment
Changes to the Destiny IT managed service scope or configuration
3.4 Threat Landscape Change
Emergence of a new threat category relevant to Out Sauce operations (e.g., novel AI-based attack vectors)
Industry-wide security advisory or alert affecting financial services practices
Notification from Destiny IT or other security partners of elevated threat conditions
4. Review Procedure
4.1 Initiation
Scheduled reviews: Out Sauce Operations initiates the review process no later than 30 days before the documented Next Review Date
Triggered reviews: The person identifying the trigger notifies Out Sauce Operations, who initiates the review within 5 business days
4.2 Review Steps
Out Sauce Operations retrieves the current version of the document from the document repository
The document is assessed against:
Current regulatory requirements and licensee obligations
Current operational practices and technology environment
Any incidents, near-misses, or audit findings since last review
Feedback from personnel, licensees, or Destiny IT
Required changes are drafted and documented
If changes affect other documents in the suite, those documents are flagged for concurrent review
4.3 Approval
All policy changes must be approved by Out Sauce Operations before publication
Material changes (new sections, removed controls, changed classification levels) require documented approval rationale
Minor changes (formatting, typographical corrections, reference updates) may be approved by Out Sauce Operations
4.4 Distribution
Updated documents are published to the Out Sauce document repository
All affected personnel are notified of changes and required to acknowledge updated policies
Advice firms are notified where changes affect due diligence pack content. The updated pack and any accompanying note are available for the firm's licensee on request, and it is the firm's decision whether to pass them on. Where a firm is self-licensed, it is its own licensee and this notification is the whole of the path
The Review Schedule table in this register is updated with the new version, effective date, and next review date
APPROVAL
Approved by:
Clinton Weekes
Position:
Director โ Weekes Financial Pty Ltd
Date:
August 2026
Next review:
March 2027
This document is classified as Internal and is maintained by Out Sauce Operations. It is available to licensees upon request as part of the Out Sauce due diligence pack.
This register documents the Out Sauce information security risk assessment methodology, maintains a current record of identified risks, and tracks risk treatment over time. It supports Out Sauce obligations under licensee due diligence requirements and demonstrates a structured, ongoing approach to identifying, assessing, and managing information security risks across the business.
This register is maintained by Out Sauce Operations and reviewed at least annually, or following any significant incident, operational change, or regulatory development.
2. Risk Rating Methodology
2.1 Likelihood Scale
Rating
Level
Description
1
Rare
May occur only in exceptional circumstances. No history of occurrence.
2
Unlikely
Could occur at some point but not expected. Has occurred elsewhere in the industry.
3
Possible
Might occur. Has occurred in similar organisations or environments.
4
Likely
Will probably occur in most circumstances. Has occurred at Out Sauce or close peers.
5
Almost Certain
Expected to occur frequently. Is occurring or has recently occurred.
2.2 Impact Scale
Rating
Level
Description
1
Insignificant
No measurable impact on operations, data, or reputation. No regulatory consequence.
2
Minor
Minor operational disruption (<4 hours). No client data affected. Minor inconvenience.
3
Moderate
Operational disruption (4-24 hours). Limited data exposure. Advice firm notification may be required, and that firm may in turn need to notify its licensee.
4
Major
Significant disruption (1-5 days). Client data compromised. Regulatory notification required. Licensee relationship at risk.
5
Catastrophic
Extended outage (>5 days). Large-scale data breach. OAIC notification required. Potential loss of licensee authorisations. Business viability threatened.
2.3 Risk Rating Matrix
Insignificant (1)
Minor (2)
Moderate (3)
Major (4)
Catastrophic (5)
Almost Certain (5)
Medium (5)
High (10)
High (15)
Critical (20)
Critical (25)
Likely (4)
Medium (4)
Medium (8)
High (12)
Critical (16)
Critical (20)
Possible (3)
Low (3)
Medium (6)
Medium (9)
High (12)
Critical (15)
Unlikely (2)
Low (2)
Low (4)
Medium (6)
Medium (8)
High (10)
Rare (1)
Low (1)
Low (2)
Low (3)
Medium (4)
Medium (5)
2.4 Risk Rating Thresholds
Rating
Score Range
Required Action
Low
1-3
Accept. Monitor during scheduled reviews.
Medium
4-9
Treat. Ensure controls are operating effectively. Review quarterly.
High
10-15
Treat urgently. Implement additional controls. Review monthly until reduced.
Critical
16-25
Immediate action required. Escalate to Out Sauce Operations. Do not proceed with affected activity until mitigated.
2.5 Risk Appetite Statement
Out Sauce maintains zero tolerance for:
Deliberate misuse of client data by any personnel
Use of unapproved tools or platforms for processing client information
Circumvention of security controls or policies
Out Sauce maintains managed tolerance for:
Residual risks that remain after all reasonable and proportionate controls have been applied
Risks rated Low or Medium after treatment, where the cost of further mitigation is disproportionate to the risk reduction achieved
Operational risks inherent in the delivery of financial planning services (e.g., reliance on third-party platforms)
3. Risk Register
Risk ID
Category
Risk Description
Likelihood
Impact
Inherent Rating
Controls in Place
Residual Likelihood
Residual Impact
Residual Rating
Risk Owner
Last assessed
Review Date
Status
RSK-001
Cyber Threat
Phishing / Social Engineering โ Credential theft or malware delivery via deceptive emails, calls, or messages targeting Out Sauce personnel
4 (Likely)
4 (Major)
Critical (16)
Anti-spam/anti-phishing filtering via Destiny IT; MFA on all accounts; security awareness training (ongoing); monthly or bi-monthly phishing simulations (ongoing); managed endpoint detection
2 (Unlikely)
3 (Moderate)
Medium (6)
Out Sauce Operations
March 2026
March 2027
Active
RSK-002
Cyber Threat
Ransomware โ Encryption of Out Sauce data and systems causing business disruption and potential data loss
3 (Possible)
5 (Catastrophic)
Critical (15)
Endpoint detection and response (EDR) managed by Destiny IT; automated cloud backups; managed detection and response (MDR); documented incident response plan; network segmentation
2 (Unlikely)
4 (Major)
Medium (8)
Out Sauce Operations
March 2026
March 2027
Active
RSK-003
Data Security
Data Exfiltration โ Unauthorised transfer or extraction of client data from Out Sauce systems via email, removable media, or cloud services
3 (Possible)
4 (Major)
High (12)
Data loss prevention controls; managed devices only; approved collaboration tools enforced; data classification policy; USB restrictions; cloud platform conditional access
2 (Unlikely)
3 (Moderate)
Medium (6)
Out Sauce Operations
March 2026
March 2027
Active
RSK-004
Insider Threat
Insider Threat / Contractor Misuse โ Deliberate or accidental misuse of access privileges by Out Sauce personnel or contractors
2 (Unlikely)
4 (Major)
Medium (8)
Least privilege access model; quarterly access reviews; data classification and handling policy; activity monitoring via Destiny IT; contractor agreements with security obligations; offboarding procedures
1 (Rare)
3 (Moderate)
Low (3)
Out Sauce Operations
March 2026
March 2027
Active
RSK-005
Third-Party
Third-Party Compromise โ Security breach at a vendor or service provider resulting in Out Sauce data exposure or service disruption
3 (Possible)
4 (Major)
High (12)
Vendor management policy and register; cloud platform security controls managed by Destiny IT; vendor due diligence assessments; contractual security requirements; monitoring of vendor security posture
2 (Unlikely)
3 (Moderate)
Medium (6)
Out Sauce Operations
March 2026
March 2027
Active
RSK-006
AI & Technology
AI Data Leakage โ Client data entered into unapproved AI tools resulting in data exposure, privacy breach, or loss of control
3 (Possible)
4 (Major)
High (12)
Approved AI tools list maintained and enforced; AI governance policy; security awareness training covering AI risks (ongoing); human review requirement for all AI outputs; data classification restrictions on AI use
1 (Rare)
3 (Moderate)
Low (3)
Out Sauce Operations
March 2026
March 2027
Active
RSK-007
Compliance
Regulatory Non-Compliance โ Failure to meet ASIC, APPs, or licensee security obligations resulting in enforcement action or loss of authorisation
2 (Unlikely)
5 (Catastrophic)
High (10)
Comprehensive policy suite aligned to regulatory requirements; security awareness training (ongoing); audit trail and evidence collection; policy review register; licensee due diligence pack
1 (Rare)
4 (Major)
Medium (4)
Out Sauce Operations
March 2026
March 2027
Active
RSK-008
Operational
Business Disruption โ System outage, infrastructure failure, or loss of access to critical platforms disrupting service delivery
3 (Possible)
3 (Moderate)
Medium (9)
Cloud-based operations (no on-premises dependencies); automated backups managed by Destiny IT; business continuity and disaster recovery plan; alternative communication channels documented; mobile device access capability
2 (Unlikely)
2 (Minor)
Low (4)
Out Sauce Operations
March 2026
March 2027
Active
RSK-009
AI & Technology
AI Secondary Use / Re-identification โ Use of client data beyond service delivery (APP 6), re-identification of de-identified aggregates, or the internal knowledge base (OS-KB-001) / any stage-2 AI model acting as a new exfiltration surface
3 (Possible)
4 (Major)
High (12)
De-identification before pooling for the cross-firm global layer (OS-DHP-001 ยง8.1, data class 3.4; pipeline design committed, controls being implemented progressively), with "no individual, client, or firm reconstructable" holding for that layer; for the firm-attributed Out Sauce Know-How layer (class 3.5, added July 2026), which is identifiable to its firm by design, the replacement control is the per-slice re-identification test โ end-customer de-identification is verified within every firm/adviser slice, and a pattern that passes globally but fails attributed is kept in class 3.4 only โ plus internal-only handling and permanent AU-only processing (OS-DHP-001 ยง3.5, OS-VMP-001 ยง5.1); purpose limitation supporting the firm's APP 6 obligation (OS-PDP-001); Sensitive never ingested; human oversight, no automated decision-making (OS-AIT-001); any stage-2 model assessed and registered as a Tier 1 sub-processor before use (OS-VMP-001 ยง4.1 / ยง5.1), noting stage-2 never applies to class 3.5; residual rating contingent on the pipeline meeting the class 3.4 standard globally and the per-slice standard for class 3.5 at delivery
1 (Rare)
3 (Moderate)
Low (3)
Out Sauce Operations
July 2026
March 2027
Active
RSK-010
AI & Technology
Query-Time Model Access to Live Operational Data โ the internal software (OS-OPS-001, OS-DHP-001 ยง8.1.2) runs a query-time model over live, identifiable operational records rather than over a pooled or de-identified corpus, presenting four distinct exposures: prompt injection or exfiltration through the query surface; decision harm from a wrong aggregate being acted on as fact; profiling of an individual contractor from their operational record; and scope creep beyond the sanctioned read model
3 (Possible)
4 (Major)
High (12)
Because this software is assessed at the design stage and is neither approved nor in use, its controls are described as designed, to be verified before it could run; none is claimed as proven today. Four exposures are addressed by design. First, injection or exfiltration through the query surface is reduced by excluding free-text document bodies from what the model can read, so no narrative content reaches the model or returns through it. Second, the risk of a wrong result being acted on as fact is met by requiring a human decision on every output, with the portal remaining the single source of truth and any output usable only as an input to a person's decision, never an automated one. Third, profiling of an individual contractor is met by that same human-decision rule together with Out Sauce's monitoring position (Contractors Agreement cl 8.5 and Schedule A ยง5), so no assessment of a contractor is made or acted on automatically. Fourth, scope creep is constrained by an allowlist model that reads only named fields, with any extension governed by this register rather than by convenience. Three further safeguards are designed and would be tested before any live use: processing kept within Australia and enforced at the connection; exclusion of any firm that has opted out of the knowledge base; and logging that records no query content, so nothing sensitive is held. Status: In development. Until the Approved AI Tools Register (OS-AIT-001) records this software as Approved, the register's default position applies to it: no use with any Out Sauce data. This risk was assessed before the software was built; the residual rating is provisional and will be confirmed against the chosen hosting and vendor before any operational use
1 (Rare), provisional
3 (Moderate), provisional
Low (3), provisional
Out Sauce Operations
July 2026
March 2027
Active
4. Assessment Schedule
4.1 Annual Comprehensive Assessment
A full risk assessment is conducted annually, aligned with the policy review cycle
All existing risks are reassessed for changes in likelihood, impact, or control effectiveness
New risks are identified through environmental scanning, incident review, and stakeholder consultation
Results are recorded against each risk in the register above
4.2 On-Change Assessment
A targeted risk assessment is conducted when any of the following occur:
New technology, platform, or tool introduced into the Out Sauce environment
New licensee onboarded or significant change to licensee arrangements
New vendor engaged or existing vendor scope materially changed
Significant change to Out Sauce staffing model or operational processes
Regulatory change affecting Out Sauce security obligations
4.3 Post-Incident Assessment
Following any security incident (actual or near-miss), the relevant risk(s) are reassessed
Control effectiveness is evaluated in light of the incident
New risks identified during incident investigation are added to the register
Assessment is completed within 10 business days of incident closure
APPROVAL
Approved by:
Clinton Weekes
Position:
Director โ Weekes Financial Pty Ltd
Date:
July 2026
Next review:
March 2027
This document is classified as Internal and is maintained by Out Sauce Operations. It is available to licensees upon request as part of the Out Sauce due diligence pack.
This document defines the Out Sauce security awareness training program, including the annual training schedule, module descriptions, onboarding requirements, and effectiveness measurement criteria. It ensures all Out Sauce personnel โ including all operations staff, and contract paraplanners โ receive consistent, relevant, and timely security training aligned with Out Sauce policy obligations and licensee expectations.
This program is maintained by Out Sauce Operations and delivered in partnership with Destiny IT.
2. Training Requirements Summary
Requirement
Detail
Minimum annual training hours
2 hours per person per year
Applicability
All Out Sauce personnel โ operations staff, and all contract paraplanners
Phishing simulations
Monthly or bi-monthly (ongoing)
Policy acknowledgment
Annual, plus on any material policy update
New starter training
Must be completed within 30 days of receiving the managed device
Non-compliance consequence
Access restrictions until training completed (see Section 6.3)
3. Annual Training Schedule
Quarter
Activity
Description
Duration
Delivery Method
Provider
Audience
Q1
Security Awareness Training
Comprehensive annual security awareness training covering current threats, safe practices, and Out Sauce-specific requirements
1.5 hours
Online (self-paced)
Destiny IT
All personnel
Q1
Out Sauce Policy Acknowledgment
Review and formal acknowledgment of the Out Sauce policy suite, including any changes since previous acknowledgment
30 minutes
Self-paced document review
Out Sauce Operations
All personnel
Q2
Phishing Simulation #1
Simulated phishing email exercise to test recognition and reporting behaviour
N/A
Simulated email
Destiny IT
All personnel
Q3
Phishing Simulation #2
Second simulated phishing exercise. Personnel who clicked in Q2 receive targeted refresher training
N/A
Simulated email + refresher module
Destiny IT
All personnel
Q4
Phishing Simulation #3 + Annual Review
Third simulated phishing exercise. Annual review of training effectiveness and planning for next cycle
N/A
Simulated email + review
Destiny IT
All personnel
Ongoing
Incident Debriefs
Training sessions triggered by actual security incidents or near-misses, covering lessons learned and updated procedures
As needed
Briefing (virtual or in-person)
Out Sauce Operations
Affected personnel
4. Training Modules
Module ID
Module Name
Description
Duration
Frequency
Provider
Data Classifications Covered
MOD-001
Security Awareness Fundamentals
Recognising cyber threats including phishing, social engineering, and business email compromise. Password hygiene, device security, safe browsing, and physical security practices. Reporting suspicious activity.
1.5 hours
Annual
Destiny IT
All (General, Personal, Sensitive)
MOD-002
Out Sauce Data Classification & Handling
The Out Sauce data classification system: the three collected classes (General, Personal, Sensitive) plus the two derived classes (3.4 De-Identified and Aggregated Intelligence, 3.5 Out Sauce Know-How). Approved methods for storing, transferring, and disposing of each classification. Prohibited practices and common mistakes.
30 minutes
Annual
Out Sauce Operations
All (General, Personal, Sensitive)
MOD-003
AI Governance & Approved Tools
The Out Sauce approved AI tools list and usage restrictions. What data can and cannot be entered into AI tools. Human review requirements for all AI-generated outputs. Prohibited AI practices.
20 minutes
Annual (and on approved tools list update)
Out Sauce Operations
All (General, Personal, Sensitive)
MOD-004
Incident Reporting
What constitutes a reportable security incident or near-miss. Timeframes for reporting (immediate for confirmed incidents, within 4 hours for suspected). Reporting channels and who to contact. What information to include. Preservation of evidence.
15 minutes
Annual
Out Sauce Operations
All (General, Personal, Sensitive)
MOD-005
Out Sauce Policy Suite Overview
Onboarding orientation covering all Out Sauce policies: Information Security, Acceptable Use, Data Handling, Access Management, Incident Response, Business Continuity, Privacy, Vendor Management, and AI Governance. Key obligations and where to find each policy.
45 minutes
On engagement (and on major policy updates)
Out Sauce Operations
All (General, Personal, Sensitive)
MOD-006
Phishing Simulation
Monthly or bi-monthly simulated phishing exercises delivered via email. Tests ability to recognise and report phishing attempts. Results tracked and personnel who fail receive additional targeted training.
N/A
Monthly or bi-monthly (ongoing)
Destiny IT
N/A
5. New Contractor Onboarding Checklist
All new contractors must complete the following steps within 30 days of receiving their managed device. Access to client data and financial planning software is not granted until all mandatory items are completed.
Step
Activity
Timing
Responsible
Completed
1
Receive managed device from Destiny IT
Day 1
Destiny IT / Out Sauce Operations
[ ]
2
Complete MOD-005: Out Sauce Policy Suite Overview
Day 1-2
Out Sauce Operations
[ ]
3
Complete MOD-001: Security Awareness Fundamentals
Day 1-3
Destiny IT
[ ]
4
Acknowledge all Out Sauce policies (signed acknowledgment form)
Day 1-3
Out Sauce Operations
[ ]
5
Configure MFA on all assigned accounts
Day 1-2
Destiny IT / Contractor
[ ]
6
Complete MOD-002: Out Sauce Data Classification & Handling
Day 3-5
Out Sauce Operations
[ ]
7
Complete MOD-003: AI Governance & Approved Tools
Day 3-5
Out Sauce Operations
[ ]
Sign-off:
Name
Date
Signature
Contractor
Out Sauce Operations
6. Completion Requirements
6.1 Passing Criteria
MOD-001 (Security Awareness Fundamentals): Must achieve minimum 80% score on assessment
MOD-002 to MOD-005: Must complete all content and provide written acknowledgment
MOD-006 (Phishing Simulations): No pass/fail โ results tracked for trend analysis and targeted remediation
6.2 Timeframes
Annual training (MOD-001 to MOD-004): Must be completed within Q1 each year
Policy acknowledgment: Within 10 business days of notification
New contractor onboarding: Within 30 days of receiving the managed device
6.3 Non-Compliance Consequences
Personnel who fail to complete mandatory training within the required timeframe will have their access to Out Sauce systems restricted until training is completed
Personnel who fail a phishing simulation will receive targeted refresher training within 5 business days
Personnel who fail two consecutive phishing simulations will complete the full MOD-001 module again
Repeated non-compliance will be escalated to Out Sauce Operations for review and may result in termination of contractor engagement
7. Effectiveness Measurement
Out Sauce Operations tracks the following metrics to assess training program effectiveness:
Metric
Target
Measurement Frequency
Source
Training completion rate
100% of personnel within required timeframes
Quarterly
Training register (OS-TR-001)
Phishing simulation click rate
<10% (declining trend year-on-year)
Quarterly
Destiny IT simulation reports
Phishing reporting rate
>80% of simulated emails reported to IT
Quarterly
Destiny IT simulation reports
Credential entry rate
0% of personnel entering credentials on simulated phishing pages
Quarterly
Destiny IT simulation reports
Incident reporting compliance
100% of incidents reported within required timeframes
Ongoing
Incident register
Assessment pass rate
100% achieving minimum 80% on MOD-001
Annual
Training register (OS-TR-001)
Onboarding completion
100% of new contractors completing all onboarding within 5 days
Per engagement
Onboarding checklists
Annual Effectiveness Review
At the end of each training year (Q4), Out Sauce Operations conducts an effectiveness review that considers:
Year-on-year trends in all metrics above
Correlation between training and actual incident rates
Feedback from personnel on training content and delivery
Changes in threat landscape requiring curriculum updates
Recommendations for the following year's training program
Results are documented in the Training Register annual summary (OS-TR-001) and reported to Out Sauce Operations.
APPROVAL
Approved by:
Clinton Weekes
Position:
Director โ Weekes Financial Pty Ltd
Date:
August 2026
Next review:
March 2027
This document is classified as Internal and is maintained by Out Sauce Operations. It is available to licensees upon request as part of the Out Sauce due diligence pack.
Out Sauce Cyber Insurance COC
CFC Cyber Liability, $2M per clause. Cover to 6 September 2026.
Out Sauce Cyber Insurance COC (2026 to 2027 renewal)
CFC Cyber Liability, $2M per clause. Cover 6 September 2026 to 6 September 2027. Issued to Weekes Financial Pty Ltd, trading as Out Sauce Paraplanning.
Out Sauce Professional Indemnity COC (2026 to 2027 renewal)
AIG Professional Indemnity, $1M any one claim and $3M aggregate. Cover 6 September 2026 to 6 September 2027. Issued to Weekes Financial Pty Ltd, trading as Out Sauce Paraplanning.
Chubb PremierTech2 (Technology Professional Liability $1M any one claim / $2M aggregate; Cyber $1M aggregate; Public and Product Liability $20M each). Valid to 1 October 2027.