Data Security

Protecting your data and your clients’ data

Financial advice businesses work with sensitive personal and financial information every day.

Protecting that information is a core part of how we design, develop, and operate our software.

We’re ISO/IEC 27001:2022 Certified

OMNIMax maintains an Information Security Management System (ISMS) certified by INTERCERT to ISO/IEC 27001:2022.

This means our information security practices are independently audited against an internationally recognised standard.

This framework ensures:

  • Security risks are identified, assessed, and managed on an ongoing basis

  • Controls are applied based on risk and reviewed regularly

  • Security processes are documented and consistently enforced

  • Independent audits are conducted to maintain certification

  • Key suppliers and service providers are subject to security and risk assessments

What This Means for Advisers

When adviser businesses store client information in software, they need confidence that the provider takes security seriously.

Data is managed within a secure, independently audited environment

Information is protected through multiple layers of security controls

Security risks are actively monitored and managed

Systems are designed for the needs of financial advice businesses

Data is handled in line with documented security and privacy practices

Security information is available to support due diligence requirements

Our Data Security Controls

Multiple layers of control help protect your data and your clients’ data

01

Protect Data

Access control and authentication

Access to systems and client data is restricted according to a user’s role and responsibilities.

We use role-based permissions, password management tools, strong password standards, multi-factor authentication, and controlled onboarding and offboarding processes to help prevent unauthorised access.

Encryption and data protection

Data security is supported through the use of encryption technologies and secure infrastructure practices.

We use:

  • HTTPS encryption for data transmitted online
  • Encryption at rest where appropriate
  • Server-side encryption within our cloud environment
  • Secure cloud-based storage rather than local file storage

Data segregation

Client data is logically separated within our systems.

Controls are in place to ensure adviser businesses can only access their own information, and that customer data remains appropriately isolated.

Data retention

We understand the record-keeping obligations that apply to Financial Advice Providers.

Client and adviser records are retained for a minimum of seven years. Information is stored securely throughout the retention period in line with our retention policies and operational requirements.

Staff security and governance

Information security is supported by documented policies, ongoing staff awareness, and formal governance processes.

Employees and contractors are subject to confidentiality obligations, and security practices are reviewed regularly as part of our ISO/IEC 27001:2022 management framework.

02

Secure Systems

Secure software development

Security is built into how we design and release software.

Code changes are reviewed before release, development and production environments are separated, and system changes are managed through controlled release processes.

Vulnerability management and threat protection

We regularly assess our systems for vulnerabilities, apply security updates, monitor infrastructure, and use technologies designed to help protect against malware, malicious traffic, and common web-based attacks.

This includes:

  • Vulnerability assessments
  • Security patch management
  • Anti-malware protection
  • Infrastructure monitoring
  • Firewall and web application protection technologies

Microsoft Azure infrastructure

OMNIMax solutions are hosted on Microsoft Azure, Microsoft’s enterprise cloud platform.

Azure provides enterprise-grade security, resilience, and compliance capabilities, including secure infrastructure, encryption, and robust security controls.

This helps support security, monitoring, backup, disaster recovery, and business continuity across our services.

03

Respond & Recover

Backup and recovery

Regular backups are maintained to support business continuity and data recovery.

Recovery processes are in place to help restore critical information and services if required.

Incident management

We maintain documented procedures for managing security incidents.

Incidents are assessed, investigated, and responded to through defined escalation and response processes. Where necessary, lessons learned are used to strengthen controls and reduce future risk.

Continuous improvement

As part of our ISO/IEC 27001:2022 programme, we regularly review and improve our ISMS. This includes our security practices, complete internal and external audits, ongoing staff training, and policy and control updates as new risks emerge

Further Information

We recognise that security is an important part of the due diligence process for financial advice businesses.

If you require additional information about our information security practices, please contact us at contact@omnimax.co.nz.

Why Work With Us

We’ve been fuelling financial advice conversations since 2002

Some of New Zealand’s top financial advice brands trust our solutions.

Go to Fisher Funds website
Go to Wealthpoint website
Go to FoxPlan website
BNZ logo
Go to Total Life website