Trust Centre
Security, compliance and transparency behind RapidP2P
RapidP2P supports critical finance processes and the information that moves through them. Explore how Efficiency Leaders approaches cloud infrastructure, information security, access control, third-party risk, integrations and service support.
Security, Privacy & Compliance
Our Approach to Security & Compliance
Security practices designed to support the standards our customers expect.
Protecting customer information requires more than technology alone. It depends on clear governance, controlled access, secure infrastructure, independent assurance and disciplined operational practices.
Efficiency Leaders applies defined security and compliance controls across the way RapidP2P is hosted, managed and supported. Our approach is designed to protect customer information, reduce security risk and provide finance, IT, security and procurement teams with the assurance they need when assessing RapidP2P.
ISO/IEC 27001
Certified Information Security Management System
Microsoft Azure
Enterprise cloud infrastructure
Australian Hosting
Sydney & Melbourne Azure regions
Independent Security Testing
Third-party penetration testing
Access Controls
SSO & Role-Based Access Control
Explore our Trust Centre
Find the information you need
Explore the areas below to find information relevant to your security, technology or procurement review.
Infrastructure
Learn how RapidP2P is hosted, where its Azure infrastructure is located, how the platform is deployed and how the environment supports geographic data requirements and scalability.
View Infrastructure FAQs →
Security
Explore security governance, ISO/IEC 27001 certification, access safeguards, independent testing, logging, platform maintenance and information protection practices.
View Security FAQs →
Third-Party Risk Management
Understand how Efficiency Leaders assesses and manages suppliers and service providers and how relevant security and privacy requirements are addressed.
View Third-Party FAQs →
Access
Learn how RapidP2P supports Single Sign-On, user administration and Role-Based Access Control.
View Access FAQs →
Integration
Understand how RapidP2P connects with cloud and on-premises ERP environments, APIs and other third-party applications
View Integration FAQs →
Support & Maintenance
Review the support and escalation processes available to RapidP2P customers.
View Support FAQs →
Security & Compliance FAQs
Detailed answers for your due-diligence review
Find detailed answers about RapidP2P’s infrastructure, security practices, third-party risk management, access controls, integration and support.
Infrastructure
How RapidP2P is hosted and delivered
How is RapidP2P hosted?
RapidP2P is hosted on Azure cloud infrastructure.
Where is RapidP2P hosted?
RapidP2P is hosted on the Azure Availability Zones of Australia East (Sydney) and Australia Southeast (Melbourne).
What service model does RapidP2P utilise?
RapidP2P is deployed under an Enterprise SaaS model; it is deployed on Microsoft Azure and configured to customer needs. The ability to integrate with and export from RapidP2P gives our customers reassurance against vendor lock-in.
Can EL prevent data flow outside of agreed geographic boundaries?
RapidP2P is fully hosted on the Microsoft Azure platform. Data at-rest and in-transit is fully contained within Microsoft’s Australian data centres. At the customer’s request, EL can implement geo-blocking.
What are RapidP2P’s capabilities in relation to scaling?
The Azure cloud infrastructure has automated capacity monitoring and alerts to notify RapidP2P’s system administrators when the capacity threshold markers have been triggered. RapidP2P can scale-up or scale-out where necessary.
Are operating systems hardened to provide only the necessary ports, protocols, and services?
RapidP2P is deployed on Microsoft Azure’s serverless architecture, where Microsoft actively secures and hardens the underlying operating system. In addition, Efficiency Leaders’ security team uses Microsoft Defender for Cloud to continuously monitor and improve the platform’s security posture.
Security
Information security governance and controls
Does EL conduct formal third-party penetration testing?
Yes. In addition to ongoing automated vulnerability scanning, EL commissions formal third-party web application penetration tests. A summary penetration test report for RapidP2P is available upon request.
How does EL manage patching and security?
RapidP2P is deployed on serverless architecture on the Microsoft Azure cloud platform. All patching and security are handled automatically by Microsoft. In the event of a RapidP2P patch, EL’s support team manages and schedules this in consultation with the client.
Does EL have anti-virus and anti-malware software installed on all RapidP2P systems?
RapidP2P is deployed on serverless architecture on the Microsoft Azure cloud platform. Security is handled on this platform automatically by Microsoft. EL has up-to-date virus protection on all staff and system machines used in software development and day-to-day operations.
Is EL certified for security compliance?
Yes. EL holds ISO/IEC 27001:2022 certification for its Information Security Management System (ISMS). The certificate is available upon request.
Does RapidP2P have audit logging in place to capture events and actions?
RapidP2P is deployed on serverless Azure infrastructure. Each resource has native Azure logging and diagnostics enabled. RapidP2P also has its own in-built logging and data capture to enable offline diagnostics and scenario recreation.
Does EL have controls in place to ensure that log files are viewable only to administrators with the appropriate permissions?
Access to Azure (where the log files reside) is managed on a principle of least privilege. MFA is enforced for all EL staff that requires access. Encryption at rest and encryption in transit policies are standard for every deployment.
Does EL report observed or suspected information security weaknesses or breaches?
Yes, EL is very proactive and open with customers. If weaknesses are identified, we work with the customer to a satisfactory conclusion. Our incident response policy includes notifying the customer and any other third party where legally obliged to do so.
Does EL have a Data Loss Prevention (DLP) programme in place?
EL has documented information handling, access control, and incident management processes designed to reduce the risk of unauthorised disclosure or loss of information.
Does EL have a formal information security governance structure with a designated security owner?
Yes. EL has a documented information security governance framework with defined roles, responsibilities, and management oversight for the Information Security Management System (ISMS).
Third-Party Risk Management
Extending security expectations to the organisations we work with
Does EL have a formal third-party risk management programme?
Yes. EL maintains a documented Third-Party Management Policy governing the selection, onboarding, assessment, and ongoing management of suppliers and service providers. Third parties are assessed based on the nature of the services they provide and the associated business, security, privacy, and operational risks. Security and confidentiality obligations are incorporated into supplier agreements where appropriate, and suppliers are reviewed periodically throughout the relationship.
Do third-party contracts include the same security and privacy obligations as EL’s own programme?
EL incorporates appropriate security, confidentiality, privacy, and data protection requirements into supplier agreements based on the services provided and the associated risk profile. Supplier relationships are periodically reviewed to ensure they continue to meet EL’s security and compliance expectations.
Access
Controlling who can access RapidP2P and what they can do.
Does EL have a formal third-party risk management programme?
Yes. EL maintains a documented Third-Party Management Policy governing the selection, onboarding, assessment, and ongoing management of suppliers and service providers. Third parties are assessed based on the nature of the services they provide and the associated business, security, privacy, and operational risks. Security and confidentiality obligations are incorporated into supplier agreements where appropriate, and suppliers are reviewed periodically throughout the relationship.
Do third-party contracts include the same security and privacy obligations as EL’s own programme?
EL incorporates appropriate security, confidentiality, privacy, and data protection requirements into supplier agreements based on the services provided and the associated risk profile. Supplier relationships are periodically reviewed to ensure they continue to meet EL’s security and compliance expectations.
Access
Controlling who can access RapidP2P and what they can do.