We’re ISO/IEC 27001:2022 Certified
OMNIMax maintains an Information Security Management System (ISMS) certified by INTERCERT to ISO/IEC 27001:2022.
This means our information security practices are independently audited against an internationally recognised standard.
This framework ensures:
You can find out more about ISO/IEC 27001:2022 here and view our certificate here.
What This Means for Advisers
When adviser businesses store client information in software, they need confidence that the provider takes security seriously.
Data is managed within a secure, independently audited environment
Information is protected through multiple layers of security controls
Security risks are actively monitored and managed
Systems are designed for the needs of financial advice businesses
Data is handled in line with documented security and privacy practices
Security information is available to support due diligence requirements
Our Data Security Controls
Multiple layers of control help protect your data and your clients’ data
01
Protect Data
Access control and authentication
Access to systems and client data is restricted according to a user’s role and responsibilities.
We use role-based permissions, password management tools, strong password standards, multi-factor authentication, and controlled onboarding and offboarding processes to help prevent unauthorised access.
Encryption and data protection
Data security is supported through the use of encryption technologies and secure infrastructure practices.
We use:
- HTTPS encryption for data transmitted online
- Encryption at rest where appropriate
- Server-side encryption within our cloud environment
- Secure cloud-based storage rather than local file storage
Data segregation
Client data is logically separated within our systems.
Controls are in place to ensure adviser businesses can only access their own information, and that customer data remains appropriately isolated.
Data retention
We understand the record-keeping obligations that apply to Financial Advice Providers.
Client and adviser records are retained for a minimum of seven years. Information is stored securely throughout the retention period in line with our retention policies and operational requirements.
Staff security and governance
Information security is supported by documented policies, ongoing staff awareness, and formal governance processes.
Employees and contractors are subject to confidentiality obligations, and security practices are reviewed regularly as part of our ISO/IEC 27001:2022 management framework.
02
Secure Systems
Secure software development
Security is built into how we design and release software.
Code changes are reviewed before release, development and production environments are separated, and system changes are managed through controlled release processes.
Vulnerability management and threat protection
We regularly assess our systems for vulnerabilities, apply security updates, monitor infrastructure, and use technologies designed to help protect against malware, malicious traffic, and common web-based attacks.
This includes:
- Vulnerability assessments
- Security patch management
- Anti-malware protection
- Infrastructure monitoring
- Firewall and web application protection technologies
Microsoft Azure infrastructure
OMNIMax solutions are hosted on Microsoft Azure, Microsoft’s enterprise cloud platform.
Azure provides enterprise-grade security, resilience, and compliance capabilities, including secure infrastructure, encryption, and robust security controls.
This helps support security, monitoring, backup, disaster recovery, and business continuity across our services.
03
Respond & Recover
Backup and recovery
Regular backups are maintained to support business continuity and data recovery.
Recovery processes are in place to help restore critical information and services if required.
Incident management
We maintain documented procedures for managing security incidents.
Incidents are assessed, investigated, and responded to through defined escalation and response processes. Where necessary, lessons learned are used to strengthen controls and reduce future risk.
Continuous improvement
As part of our ISO/IEC 27001:2022 programme, we regularly review and improve our ISMS. This includes our security practices, complete internal and external audits, ongoing staff training, and policy and control updates as new risks emerge
Further Information
We recognise that security is an important part of the due diligence process for financial advice businesses.
If you require additional information about our information security practices, please contact us at contact@omnimax.co.nz.











