Trust Centre and Sub-processor List. Last updated 12 October 2026.
Trust Centre and Sub-processor List
Information security
ISO/IEC 27001:2022 certified
86 security controls across 15 categories, mapped to ISO/IEC 27001:2022 Annex A under our Statement of Applicability.
- ISO/IEC 27001:2022
- 86 controls
- Statement of Applicability
Security Controls
Inspra has implemented 86 security controls across 15 categories, mapped to ISO/IEC 27001:2022 Annex A.
Asset management
Information assets are inventoried, owned and handled under clear rules from acquisition through to disposal.
Asset inventory
A.5.9An inventory of information and associated assets is maintained, and each asset has a designated owner responsible for protecting it.
Acceptable use of assets
A.5.10Acceptable use rules set out user responsibilities and handling requirements for systems and information, based on classification.
Return of assets
A.5.11Employees and third parties return all company assets when their employment or contract ends, tracked through offboarding checklists.
Storage media handling
A.7.10Removable media is handled according to its classification, authorised and logged when taken off-site, and securely destroyed when no longer needed.
Secure disposal and re-use of equipment
A.7.14Data and licensed software are securely wiped from equipment before it is disposed of or re-used, and disposal records are kept.
Business continuity and resilience
Redundancy, tested backups and continuity planning keep services available and data recoverable during disruption.
Security during disruption
A.5.29Continuity plans are integrated with business continuity arrangements so security controls stay in place during a crisis.
ICT readiness for business continuity
A.5.30Systems and infrastructure are designed with redundancy and backup plans so information stays available during disruption.
Capacity management
A.8.6System usage and performance are monitored to forecast capacity needs and maintain uptime.
Information backup
A.8.13Backups follow defined procedures and are tested regularly, and recovery test results are retained.
Redundant processing facilities
A.8.14Critical systems have redundant processing capacity to meet availability objectives.
Compliance and assurance
Legal, regulatory and contractual obligations are tracked, and the security program is reviewed independently.
Industry and professional engagement
A.5.6Inspra takes part in industry groups and professional associations to stay current on emerging threats, regulation and good practice.
Legal and regulatory requirements
A.5.31Legal, statutory, regulatory and contractual requirements, including those that apply to cryptography, are identified, documented and reviewed regularly.
Intellectual property rights
A.5.32Use of licensed software and proprietary information is governed by policy and checked through periodic reviews.
Protection of records
A.5.33Records are protected against loss, unauthorised access and destruction in line with regulatory and business requirements.
Independent security review
A.5.35The information security program is independently reviewed at planned intervals and whenever significant changes occur.
Policy compliance reviews
A.5.36Managers regularly check that day-to-day operations comply with internal security policies and applicable standards.
Protecting systems during audits
A.8.34Audit testing is planned in advance so it does not disrupt operations or put data integrity at risk.
Configuration and vulnerability management
Systems are built to secure baselines, changed under control, and patched against known vulnerabilities.
Technical vulnerability management
A.8.8Vulnerabilities are tracked through vendor advisories and security testing, and patches are applied and reviewed regularly.
Configuration management
A.8.9Systems follow secure baseline configurations that are tracked, verified and updated through formal change control.
Software installation controls
A.8.19Software installation on operational systems is controlled, and only approved software is permitted.
Data protection and privacy
Information is classified by sensitivity and protected accordingly when stored, shared and deleted.
Information classification
A.5.12A classification scheme assigns sensitivity levels to information based on its legal, regulatory and business impact.
Information labelling
A.5.13Information is labelled according to its classification so people know how to handle it.
Secure information transfer
A.5.14Information sent by email, in backups or to suppliers follows formal transfer procedures and is protected with encryption and access controls.
Privacy and protection of personal information
A.5.34Personal information is protected in line with applicable privacy law through encryption, access control and privacy policies.
Information deletion
A.8.10Information is securely deleted when it is no longer required, and defined retention periods are enforced.
Data masking
A.8.11Sensitive data is masked where appropriate to limit how much of it is exposed.
Data leakage prevention
A.8.12Technical and administrative controls detect and prevent unauthorised transfer of information out of the organisation.
Endpoint and remote work security
Laptops and other endpoints are protected wherever staff work, in the office or at home.
Remote working
A.6.7Remote access policies and controls protect information that is accessed or processed outside the office.
Security of off-site assets
A.7.9Staff working from home use company-issued laptops managed under the same endpoint security requirements.
User endpoint devices
A.8.1Endpoint and mobile device policies require users to lock or secure unattended devices and meet endpoint security requirements.
Malware protection
A.8.7Anti-malware tools with automatic updates and scanning are deployed, backed by user awareness training.
Identity and access management
Access is granted by role, protected by strong authentication, and reviewed regularly.
Access control policy
A.5.15A dedicated access control policy restricts access according to business role and security requirements, and requires regular reviews of access rights.
Identity management
A.5.16Formal onboarding and offboarding processes register new users and remove departing users promptly.
Authentication information
A.5.17Passwords and other authentication secrets are issued, stored and managed securely under strong password rules.
Access rights reviews
A.5.18Access is provisioned and revoked through formal approval, reviewed periodically, and removed systematically when people leave.
Privileged access
A.8.2Privileged access is limited to authorised personnel through role-based access and separate administrative accounts.
Least-privilege access
A.8.3Access to systems, functions and data is restricted to what each role needs.
Secure authentication
A.8.5Sign-in to systems uses secure authentication, including strong password requirements and session management.
Privileged utility programs
A.8.18Tools that can override system or application controls are restricted and used only with documented approval.
Incident response
Documented procedures and clear reporting channels support fast detection, containment and learning from security events.
Contact with authorities
A.5.5Procedures define who contacts regulators and other authorities when a breach or regulatory incident occurs.
Incident response planning
A.5.24Incident response roles, responsibilities and procedures are formally documented and ready to use across all systems.
Security event assessment
A.5.25Security events are assessed to decide whether they are incidents that need escalation, logging or reporting.
Incident handling
A.5.26Incidents are handled through defined steps for detection, reporting, analysis and mitigation.
Learning from incidents
A.5.27Post-incident reviews identify root causes, and corrective actions are implemented to prevent recurrence.
Evidence collection
A.5.28Digital evidence related to security events is identified, collected and preserved in a way that protects its integrity.
Security event reporting
A.6.8All staff must report observed or suspected security events through designated channels.
Logging and monitoring
Activity across systems is logged, time-synchronised and watched for signs of compromise.
Threat intelligence
A.5.7Findings from vulnerability assessments, penetration tests, system logs and vendor partners inform how threats are mitigated.
Logging
A.8.15System events, user activity and administrator actions are logged and reviewed to detect anomalies.
Security monitoring
A.8.16Systems are monitored for suspicious behaviour using logs, alerts and vulnerability reports.
Clock synchronisation
A.8.17System clocks are synchronised to an Australian NTP time source so log timestamps line up across systems.
Network security
Segmented networks, firewalls and filtering control which traffic can reach Inspra systems.
Network security controls
A.8.20Network access and traffic are controlled with firewalls, network segmentation, network access control and enforced VPN use.
Security of network services
A.8.21Internal and outsourced network services have defined security controls and service levels.
Network segregation
A.8.22Networks are segmented by function, with access rules controlling traffic between segments.
Web filtering
A.8.23Web access is filtered to block malicious sites and unauthorised content.
People security
Staff are screened, trained and bound by clear security obligations from hiring through to departure.
Background screening
A.6.1Background checks are completed for new hires in line with legal requirements and in proportion to the risk of the role.
Terms of employment
A.6.2Employment contracts set out the information security responsibilities of both staff and the company.
Security awareness and training
A.6.3All staff receive security training and periodic awareness refreshers relevant to their roles.
Disciplinary process
A.6.4A defined disciplinary process addresses breaches of security policy and is communicated to all staff.
Post-employment responsibilities
A.6.5Security obligations that continue after employment ends are defined and communicated during offboarding.
Confidentiality agreements
A.6.6Staff sign non-disclosure agreements, which are reviewed regularly against data protection obligations.
Physical and environmental security
Offices and equipment rooms are protected by defined perimeters, entry controls, monitoring and environmental safeguards.
Physical security perimeters
A.7.1Defined perimeters and security zones protect areas that hold critical information and equipment.
Physical entry controls
A.7.2Access passes and visitor logs restrict entry to secure areas to authorised people.
Securing offices and facilities
A.7.3Offices and server rooms are protected with physical and environmental controls that prevent unauthorised access.
Physical security monitoring
A.7.4Surveillance, alarms and access logs detect unauthorised attempts to enter secure areas.
Environmental threat protection
A.7.5Fire protection, surge protection and secure storage guard against environmental hazards and physical attack.
Working in secure areas
A.7.6Formal procedures govern authorised access, visitor escorts and conduct within secure areas.
Clear desk and clear screen
A.7.7Clear desk and clear screen rules reduce the risk of sensitive information being seen or removed.
Equipment siting and protection
A.7.8Equipment is located and protected to prevent theft, environmental damage and unauthorised access.
Supporting utilities
A.7.11Power, UPS and HVAC systems are in place to prevent service interruptions caused by utility failures.
Cabling security
A.7.12Power and network cabling is routed and secured to prevent damage, interference or tapping.
Equipment maintenance
A.7.13Equipment is maintained on a regular, tracked schedule to keep systems available and reliable.
Secure architecture and cryptography
Systems are designed with security built in, and sensitive data is protected with strong encryption.
Use of cryptography
A.8.24Cryptography protects sensitive information, and encryption keys are managed securely.
Application security requirements
A.8.26Applications that exchange data over public networks use HTTPS/TLS, input validation and secure session handling.
Secure architecture principles
A.8.27System design and integration follow least privilege, defence in depth, secure defaults and modular design.
Security governance
Leadership sets the direction for information security, assigns clear ownership, and keeps policies current.
Information security policies
A.5.1An information security policy and supporting topic-specific policies are approved by management, communicated to staff, and reviewed at planned intervals or after significant change.
Security roles and responsibilities
A.5.2Security responsibilities are defined and assigned across leadership, IT, HR and operational staff, so every control has an accountable owner.
Segregation of duties
A.5.3Conflicting duties are separated across management, IT, HR and security roles to reduce the risk of unauthorised or accidental changes.
Management commitment
A.5.4Management requires all employees and contractors to follow security policies and provides the resources needed to do so.
Security in project management
A.5.8Security risks and responsibilities are identified during project planning and addressed throughout the project lifecycle.
Documented operating procedures
A.5.37Procedures for key IT and security operations are documented, shared with the people who use them, and reviewed regularly.
Third-party management
Suppliers and cloud providers with access to Inspra information are assessed, bound to security requirements by contract, and monitored.
Supplier security
A.5.19Supplier access to information is risk-assessed, and suppliers that handle sensitive data are covered by security agreements and monitoring.
Security in supplier agreements
A.5.20Supplier agreements include security clauses covering how information is processed, transmitted and stored.
ICT supply chain security
A.5.21Risks from ICT products and services are addressed in risk assessments and contractual obligations.
Supplier monitoring and change
A.5.22Supplier services are monitored and reviewed regularly, and security risks are reassessed whenever service delivery changes.
Cloud services security
A.5.23Cloud service providers are assessed and bound by a data processing agreement or their published data processing terms, which we review before use. We use Australian regions or location pinning wherever available.
Outsourced development
A.8.30Contracts for outsourced development define security requirements and how the vendor's work is monitored.
Controls shown are those that apply under the Genius365 Pty Ltd (Inspra) Statement of Applicability for ISO/IEC 27001:2022. Last updated October 2026.
Sub-processors
Inspra uses the 24 third-party sub-processors below to deliver its services. Each is bound by a data processing agreement or by the provider's published data processing terms, which we review before we use the provider.
We make every effort to keep customer data in Australia. The platform is hosted in Australian regions, and with overseas providers we use Australian regions or location pinning wherever they are available. Some processing, such as AI model and speech services, may take place in the USA. The Location column shows where each sub-processor may process data.
Core sub-processors 12
Used to host the platform and handle calls.
| Sub-processor | Category | Purpose | Location |
|---|---|---|---|
| Amazon Web Services | Infrastructure | Primary application hosting; storage of call recordings and session reports | Australia (Sydney) |
| Northflank | Infrastructure | Redundant application hosting | Australia |
| Google Cloud Platform | Infrastructure | Legacy platform hosting | Australia (Sydney) |
| LiveKit | Voice infrastructure | Real-time call audio and SIP | Australia (Sydney)USA |
| Retell AI | AI services | Voice agent orchestration | USA |
| Vapi | AI services | Voice agent orchestration | USA |
| Vercel | Infrastructure | Platform web hosting and performance measurement | Australia (Sydney)USA |
| Deepgram | AI services | Speech recognition | Australia (Sydney)USA |
| ElevenLabs | AI services | Voice synthesis | Australia (Sydney)USA |
| OpenRouter | AI services | AI language model routing | Australia (Sydney)USA |
| OpenAI | AI services | AI language model processing (via OpenRouter) | Australia (Sydney)USA |
| Logfire (Pydantic) | Infrastructure | Application logging and monitoring | Australia (Sydney)USA |
Feature-based sub-processors 7
Used only when a customer enables or configures the related feature or agent.
| Sub-processor | Category | Purpose | Location |
|---|---|---|---|
| AssemblyAI | AI services | Speech recognition | Australia (Sydney)USA |
| DeepInfra | AI services | Speech recognition and language model processing | Australia (Sydney)USA |
| NVIDIA | AI services | Speech recognition | Australia (Sydney)USA |
| Cartesia | AI services | Voice synthesis | Australia (Sydney)USA |
| Google (Gemini) | AI services | Voice synthesis | Australia (Sydney)USA |
| Anthropic | AI services | Language model processing | Australia (Sydney)USA |
| Twilio | Telecommunications | SMS for the take-a-message feature | Australia (Sydney)USA |
Business operations 5
| Sub-processor | Category | Purpose | Location |
|---|---|---|---|
| Mailgun | Communications | Transactional email | Australia (Sydney)USA |
| Google Workspace | Business operations | Email and document collaboration | Australia (Sydney)USA |
| HighLevel (GoHighLevel and LeadConnector) | Business operations | CRM, demo bookings and marketing email | USA |
| Stripe | Business operations | Payments and fraud prevention | USA |
| Cloudflare | Business operations | Website security, bot checks and web analytics | USA |
Customer-connected services: Google Calendar, Microsoft Graph and Calendly work through the customer's own account. They are third-party services under clause 8A of our Customer Terms, not our sub-processors.
Phone numbers: customers either bring their own carrier or take numbers directly from our carrier partners, Atom Telecom (Services Agreement, Voice Services schedule, legal terms) and VoIPcloud (terms). The customer accepts the carrier's terms and the carrier supplies and bills the customer directly, so carriers are not our sub-processors.
We update this list before adding or replacing a sub-processor. We give customers at least 30 days' notice by email or in the platform before a new sub-processor handles customer personal information, except for urgent changes needed for security or to keep the service running, which we tell customers about as soon as practicable. Clause 4 of Schedule 3 to our Customer Terms explains customers' right to object. For questions or to request our data processing agreement, contact compliance-officer@inspra.ai or hello@inspra.ai.
Last updated 12 October 2026.