
GIS-pax develops and licenses specialist geoscience and petroleum evaluation software used by energy companies, government agencies and research organisations worldwide.
We maintain documented security policies, manage risk through a defined process, and review our practices regularly to protect the confidentiality, integrity and availability to keep our customers safe.

How we protect your information

We apply practical & appropriate layered controls, including:
- Role-based access controls and the principle of least privilege;
- Multi-factor authentication, where supported by the relevant system;
- Encryption of information in transit, and secure, reputable cloud-hosted services where applicable;
- Regular software updates and risk-prioritised patching;
- Backup and recovery procedures for key systems and data;
- Business continuity arrangements proportionate to our operations;
- Ongoing staff security awareness, covering phishing, secure data handling and incident reporting; and
- A defined incident management process for responding to suspected security events.
Reporting a security concern or vulnerability
We welcome reports from customers, researchers and members of the public. If you believe you have found a security vulnerability, or wish to raise a security concern, please contact us with enough detail for us to reproduce and assess the issue. We ask that you give us a reasonable opportunity to investigate before any public disclosure.
GIS-pax is committed to acting with integrity in all our business dealings. Our Anti-Bribery & Corruption Policy outlines our approach. To report a concern, contact us.
See below for a link to the ABC policy (public):
ABC Policy