Information Security & Data Protection Training Programme
SyncMate — WYHEN Pty Ltd (ABN 57 688 078 999) Version 1.0 · Effective 31 August 2026 · Owner: Founder/Technical Operator · Review: annually
1. Purpose and scope
This programme ensures every person with access to SyncMate systems or customer data understands their security and privacy obligations. It applies to all personnel — the Founder, any employee, contractor, or third party granted access — without exception. Completion is a precondition of access.
2. Training components
2.1 Induction module — before any access is granted
Mandatory. Estimated 90 minutes. Covers:
- The nature of the data we hold: accounting firms' clients' financial documents and transactions, and why it is sensitive.
- Our role as Data Processor and the customer's role as Controller.
- Australian Privacy Principles and the Notifiable Data Breaches scheme.
- Client confidentiality: the rule that customer data is accessed only when required to resolve a specific support ticket, and never browsed.
- Credential hygiene: Xero-based authentication with mandatory two-step verification; password manager use; no credential sharing; no credentials in code, chat or email.
- Phishing and social engineering, including pretexting as a customer.
- Incident reporting: what to report, to whom, and the 24-hour customer-notification obligation.
- Acceptable use of devices: full-disk encryption, screen lock, current OS patches, no customer data on personal or removable storage.
2.2 Annual refresher — every 12 months
Mandatory. Estimated 60 minutes. Re-covers the induction content, updated with the past year's incidents, near-misses, threat landscape changes, and any changes to our policies, subprocessors or architecture.
2.3 Quarterly awareness update — every 3 months
Estimated 15–30 minutes. A short written brief on current threats relevant to us: active phishing campaigns targeting accounting and Xero users, credential-stuffing trends, supply-chain and dependency compromises, and any ACSC or OAIC advisory of relevance. Delivered from the threat intelligence process (A7).
2.4 Secure development module — before writing or reviewing code
Mandatory for anyone contributing code. Estimated 2 hours. Covers:
- OWASP Top 10 and the OWASP ASVS controls we hold ourselves to.
- Tenant isolation: how Row-Level Security works here, why every new table needs policies and grants, and why service-role access must never be reachable from the browser.
- Authorisation-before-action: verifying the caller in every server function.
- Input validation and safe handling of uploaded files.
- Secrets handling: managed secret store only, never in source or logs.
- Secure code-review checklist and the promotion gates in A3/A8.
3. Records
For each person and each training event we record: name, role, module, date completed, version of the material, and a signed or electronically acknowledged attestation. Records are retained for the duration of the engagement plus 7 years and are available to customers as evidence on request.
4. Non-completion
Access is not granted until induction is complete. Failure to complete an annual refresher within 30 days of its due date results in suspension of administrative access until completed.
5. Effectiveness review
Annually the Founder reviews: completion rates, incidents or near-misses attributable to a knowledge gap, and whether the material still reflects the architecture and threat landscape. Material is updated accordingly.
6. Current status
As at the effective date, WYHEN is operated by a single principal, who has completed the induction and secure-development modules and is subject to the annual refresher and quarterly update cycle on the same terms as any future employee or contractor.