# Information Security & Data Protection Training Programme

**SyncMate — WYHEN Pty Ltd (ABN 57 688 078 999)**
Version 1.0 · Effective 31 August 2026 · Owner: Founder/Technical Operator · Review: annually

## 1. Purpose and scope

This programme ensures every person with access to SyncMate systems or customer data understands their security and privacy obligations. It applies to **all personnel** — the Founder, any employee, contractor, or third party granted access — without exception. Completion is a precondition of access.

## 2. Training components

### 2.1 Induction module — before any access is granted
Mandatory. Estimated 90 minutes. Covers:
- The nature of the data we hold: accounting firms' clients' financial documents and transactions, and why it is sensitive.
- Our role as Data Processor and the customer's role as Controller.
- Australian Privacy Principles and the Notifiable Data Breaches scheme.
- Client confidentiality: the rule that customer data is accessed only when required to resolve a specific support ticket, and never browsed.
- Credential hygiene: Xero-based authentication with mandatory two-step verification; password manager use; no credential sharing; no credentials in code, chat or email.
- Phishing and social engineering, including pretexting as a customer.
- Incident reporting: what to report, to whom, and the 24-hour customer-notification obligation.
- Acceptable use of devices: full-disk encryption, screen lock, current OS patches, no customer data on personal or removable storage.

### 2.2 Annual refresher — every 12 months
Mandatory. Estimated 60 minutes. Re-covers the induction content, updated with the past year's incidents, near-misses, threat landscape changes, and any changes to our policies, subprocessors or architecture.

### 2.3 Quarterly awareness update — every 3 months
Estimated 15–30 minutes. A short written brief on current threats relevant to us: active phishing campaigns targeting accounting and Xero users, credential-stuffing trends, supply-chain and dependency compromises, and any ACSC or OAIC advisory of relevance. Delivered from the threat intelligence process (A7).

### 2.4 Secure development module — before writing or reviewing code
Mandatory for anyone contributing code. Estimated 2 hours. Covers:
- OWASP Top 10 and the OWASP ASVS controls we hold ourselves to.
- Tenant isolation: how Row-Level Security works here, why every new table needs policies and grants, and why service-role access must never be reachable from the browser.
- Authorisation-before-action: verifying the caller in every server function.
- Input validation and safe handling of uploaded files.
- Secrets handling: managed secret store only, never in source or logs.
- Secure code-review checklist and the promotion gates in A3/A8.

## 3. Records

For each person and each training event we record: name, role, module, date completed, version of the material, and a signed or electronically acknowledged attestation. Records are retained for the duration of the engagement plus 7 years and are available to customers as evidence on request.

## 4. Non-completion

Access is not granted until induction is complete. Failure to complete an annual refresher within 30 days of its due date results in suspension of administrative access until completed.

## 5. Effectiveness review

Annually the Founder reviews: completion rates, incidents or near-misses attributable to a knowledge gap, and whether the material still reflects the architecture and threat landscape. Material is updated accordingly.

## 6. Current status

As at the effective date, WYHEN is operated by a single principal, who has completed the induction and secure-development modules and is subject to the annual refresher and quarterly update cycle on the same terms as any future employee or contractor.
