green line

Trust Centre

Security, compliance and transparency behind RapidP2P

RapidP2P supports critical finance processes and the information that moves through them. Explore how Efficiency Leaders approaches cloud infrastructure, information security, access control, third-party risk, integrations and service support.

RapidP2P hero3

Security, Privacy & Compliance

Our Approach to Security & Compliance

Security practices designed to support the standards our customers expect.

Protecting customer information requires more than technology alone. It depends on clear governance, controlled access, secure infrastructure, independent assurance and disciplined operational practices.

Efficiency Leaders applies defined security and compliance controls across the way RapidP2P is hosted, managed and supported. Our approach is designed to protect customer information, reduce security risk and provide finance, IT, security and procurement teams with the assurance they need when assessing RapidP2P.

icon 264
ISO/IEC 27001
Certified Information Security Management System
icon 264
Microsoft Azure
Enterprise cloud infrastructure
icon 264
Australian Hosting
Sydney & Melbourne Azure regions
icon 264
Independent Security Testing
Third-party penetration testing
icon 264
Access Controls
SSO & Role-Based Access Control

Explore our Trust Centre

Find the information you need

Explore the areas below to find information relevant to your security, technology or procurement review.
infrastructure icon
Infrastructure
Learn how RapidP2P is hosted, where its Azure infrastructure is located, how the platform is deployed and how the environment supports geographic data requirements and scalability.
View Infrastructure FAQs →
security icon 1
Security
Explore security governance, ISO/IEC 27001 certification, access safeguards, independent testing, logging, platform maintenance and information protection practices.
View Security FAQs →
third party icon icon

Third-Party Risk Management

Understand how Efficiency Leaders assesses and manages suppliers and service providers and how relevant security and privacy requirements are addressed.
View Third-Party FAQs →
access icon
Access
Learn how RapidP2P supports Single Sign-On, user administration and Role-Based Access Control.
View Access FAQs →
integration icon
Integration
Understand how RapidP2P connects with cloud and on-premises ERP environments, APIs and other third-party applications
View Integration FAQs →
support icon
Support & Maintenance

Review the support and escalation processes available to RapidP2P customers.

View Support FAQs →

Security & Compliance FAQs

Detailed answers for your due-diligence review

Find detailed answers about RapidP2P’s infrastructure, security practices, third-party risk management, access controls, integration and support.
infrastructure icon grey

Infrastructure

How RapidP2P is hosted and delivered
RapidP2P is hosted on Azure cloud infrastructure.
RapidP2P is hosted on the Azure Availability Zones of Australia East (Sydney) and Australia Southeast (Melbourne).
RapidP2P is deployed under an Enterprise SaaS model; it is deployed on Microsoft Azure and configured to customer needs. The ability to integrate with and export from RapidP2P gives our customers reassurance against vendor lock-in.
RapidP2P is fully hosted on the Microsoft Azure platform. Data at-rest and in-transit is fully contained within Microsoft’s Australian data centres. At the customer’s request, EL can implement geo-blocking.
The Azure cloud infrastructure has automated capacity monitoring and alerts to notify RapidP2P’s system administrators when the capacity threshold markers have been triggered. RapidP2P can scale-up or scale-out where necessary.
RapidP2P is deployed on Microsoft Azure’s serverless architecture, where Microsoft actively secures and hardens the underlying operating system. In addition, Efficiency Leaders’ security team uses Microsoft Defender for Cloud to continuously monitor and improve the platform’s security posture.
security icon grey

Security

Information security governance and controls
Yes. In addition to ongoing automated vulnerability scanning, EL commissions formal third-party web application penetration tests. A summary penetration test report for RapidP2P is available upon request.
RapidP2P is deployed on serverless architecture on the Microsoft Azure cloud platform. All patching and security are handled automatically by Microsoft. In the event of a RapidP2P patch, EL’s support team manages and schedules this in consultation with the client.
RapidP2P is deployed on serverless architecture on the Microsoft Azure cloud platform. Security is handled on this platform automatically by Microsoft. EL has up-to-date virus protection on all staff and system machines used in software development and day-to-day operations.
Yes. EL holds ISO/IEC 27001:2022 certification for its Information Security Management System (ISMS). The certificate is available upon request.
RapidP2P is deployed on serverless Azure infrastructure. Each resource has native Azure logging and diagnostics enabled. RapidP2P also has its own in-built logging and data capture to enable offline diagnostics and scenario recreation.
Access to Azure (where the log files reside) is managed on a principle of least privilege. MFA is enforced for all EL staff that requires access. Encryption at rest and encryption in transit policies are standard for every deployment.
Yes, EL is very proactive and open with customers. If weaknesses are identified, we work with the customer to a satisfactory conclusion. Our incident response policy includes notifying the customer and any other third party where legally obliged to do so.
EL has documented information handling, access control, and incident management processes designed to reduce the risk of unauthorised disclosure or loss of information.
Yes. EL has a documented information security governance framework with defined roles, responsibilities, and management oversight for the Information Security Management System (ISMS).
third party icon grey

Third-Party Risk Management

Extending security expectations to the organisations we work with
Yes. EL maintains a documented Third-Party Management Policy governing the selection, onboarding, assessment, and ongoing management of suppliers and service providers. Third parties are assessed based on the nature of the services they provide and the associated business, security, privacy, and operational risks. Security and confidentiality obligations are incorporated into supplier agreements where appropriate, and suppliers are reviewed periodically throughout the relationship.
EL incorporates appropriate security, confidentiality, privacy, and data protection requirements into supplier agreements based on the services provided and the associated risk profile. Supplier relationships are periodically reviewed to ensure they continue to meet EL’s security and compliance expectations.
third party icon grey

Access

Controlling who can access RapidP2P and what they can do.
Yes. EL maintains a documented Third-Party Management Policy governing the selection, onboarding, assessment, and ongoing management of suppliers and service providers. Third parties are assessed based on the nature of the services they provide and the associated business, security, privacy, and operational risks. Security and confidentiality obligations are incorporated into supplier agreements where appropriate, and suppliers are reviewed periodically throughout the relationship.
EL incorporates appropriate security, confidentiality, privacy, and data protection requirements into supplier agreements based on the services provided and the associated risk profile. Supplier relationships are periodically reviewed to ensure they continue to meet EL’s security and compliance expectations.
third party icon grey

Access

Controlling who can access RapidP2P and what they can do.