Wolf IQ Trust Centre
Start your security review.
Review how we protect client websites and data, understand our infrastructure, and request access to security documentation.
Typical response to an access request: two business days.
Search our security controls
These controls come from our documented Information Security Policy. Search by control or category name.
Governance and People Who owns security, how it is documented, and what every person working on your site is held to.
Documented Information Security Policy
Wolf IQ maintains a written Information Security Policy covering governance, access, data handling, change management, resilience and incident response. It is aligned with our Terms and Conditions, Privacy Policy and the commitments we make in vendor risk assessments. The current approved version is available on request.
Annual policy review
The policy is reviewed and endorsed annually, and again after any material change to our technical environment or business operations. Version and effective date are recorded on the document itself.
Defined security responsibilities
Information security is managed internally by our technical team. Each client environment has a named internal owner responsible for access management and service delivery, and infrastructure-level security and monitoring sits with our hosting provider.
Security awareness training
All employees and contractors complete information security and data privacy awareness training during onboarding and on an ongoing basis. Acceptable use requirements and data handling protocols are set as a condition of engagement.
Confidentiality obligations
Every employee and contractor is bound by confidentiality and acceptable use agreements before they are given access to any client environment.
Personnel vetting
All personnel undergo identity verification and professional due diligence prior to engagement. Formal background checks are mandatory for anyone granted privileged administrative access to production environments or sensitive data.
Access Control Who can reach your environment, what they can do there, and how quickly that access is removed.
Unique accounts and role-based access
Access to client environments, hosting dashboards and sensitive data is granted through individually attributable accounts. Role-based access controls determine what each person can do in each system.
Least privilege
Access is granted strictly on a need-to-know basis and limited to what the role requires. Elevated permissions are the exception, not the default.
Mandatory multi-factor authentication
MFA is required for all Wolf IQ personnel accessing critical infrastructure, password managers and client production environments. Strong password policies are enforced on privileged and non-privileged accounts alike.
Periodic access review
Access rights are reviewed on a recurring basis to confirm that every account still needs the permissions it holds. Anything no longer required is removed at the point of review.
Immediate access revocation
On role change, offboarding or contract termination, all system access is revoked immediately. A formal review follows to confirm the ongoing integrity of every affected environment.
Encrypted remote access
All remote access to client systems runs over encrypted connections using HTTPS with TLS 1.2 or 1.3. There is no unencrypted administrative access path.
Approved access locations
Access is restricted to authorised personnel located in Australia and the Philippines, unless a client approves an additional location in writing.
Static IP allowlisting on request
Where a client requires it, access can be restricted to pre-approved static IP addresses to support their own allowlisting controls.
Data Protection and Privacy How client data is classified, encrypted, retained and destroyed.
Asset identification and classification
Information assets are identified during onboarding and are generally limited to website data, CMS databases and associated media. Assets are classified as public or sensitive, and where a client supplies their own classification we apply controls to match it.
Encryption in transit
All data in transit is encrypted using TLS 1.2 or 1.3 over HTTPS, across both client-facing traffic and administrative access.
Encryption at rest
Encryption at rest is managed by our hosting provider on Google Cloud Platform using cloud provider-managed encryption standards. Key management sits with the hosting provider.
Retention and secure deletion
Client data is retained only for as long as required to deliver contracted services and meet legal obligations. On termination, associated client data including backups is securely destroyed. Automated daily backups are retained for up to 90 days.
Restricted log access
Application logs are reviewed during incidents and troubleshooting. Infrastructure and security event logs are retained for a minimum of 90 days by our hosting provider, and access to audit and event logs is limited to authorised personnel.
No payment card data in WordPress
Payment card information is never stored in the WordPress environments we manage. Payment processing runs exclusively through third-party gateways, so sensitive financial data is not held at the application layer.
Australian privacy alignment
Our internal workflows are aligned with the Australian Privacy Act and the Notifiable Data Breaches scheme. Mandatory regulatory notification obligations remain with the client as the data holder.
Application and Change Security How changes reach your live site, and what stops a bad one getting there.
Separate staging and production
Every managed client website runs separate development, staging and production environments. Nothing is edited directly against production as a matter of course.
Documented change workflow
All WordPress updates, fixes and enhancements follow a structured change process. Changes are tracked in our internal task management system and reviewed and approved internally before implementation.
Testing before production
Changes are tested in a staging environment before deployment. Non-critical updates are batched into scheduled maintenance windows rather than pushed ad hoc.
Version control and rollback
Rollback capability is maintained through version control and backup restoration, so a change that causes a problem can be reversed rather than patched under pressure.
Licensed software only
All software in use, including WordPress core, premium plugins and development tools, is legally licensed and maintained under an automated update policy.
Continuous vulnerability monitoring
Application-level vulnerabilities are monitored continuously through automated scanning. Infrastructure-level scanning is handled by our hosting provider.
Immediate critical patching
Critical vulnerabilities are patched immediately on identification rather than held for the next maintenance window.
Periodic application security review
Wolf IQ conducts periodic application security reviews as part of WordPress maintenance. Our hosting provider runs regular infrastructure penetration testing, and we can support formal third-party penetration testing arranged by a client on request.
Infrastructure and Resilience Where your site lives, how it is defended, and how quickly it comes back.
Enterprise hosting on Google Cloud
Managed sites run on Kinsta, which operates on Google Cloud Platform. Kinsta holds independent SOC 2 Type II and ISO 27001 certification covering that infrastructure.
Isolated client environments
Client data is logically segregated using isolated container-based hosting environments, so an incident affecting one client environment does not spread to others.
WAF and DDoS mitigation
Infrastructure-level controls include web application firewalls and DDoS mitigation, applied across all managed environments.
Cloudflare as an additional layer
Where applicable, Cloudflare is deployed for DNS-level protection, DDoS mitigation and traffic filtering on top of the hosting layer.
Continuous provider monitoring
Network traffic is monitored continuously at the infrastructure layer by our hosting provider, with alerting into their security operations.
Daily automated backups
Automated daily backups of all managed websites run through both BlogVault and Kinsta. Backup jobs are actively monitored and failures are investigated and resolved.
Off-site storage and 90-day retention
Backups are stored off-site on Google Cloud and retained for up to 90 days, giving a recovery window well beyond a single bad deployment.
Restoration testing
Periodic restoration testing is carried out to confirm that backups restore cleanly, rather than assuming a successful backup job means a usable backup.
Recovery objectives
Recovery Time Objective is 2 to 4 business hours during standard operating hours. Recovery Point Objective is 24 hours, based on the daily backup cycle. Both are supported by infrastructure-level redundancy and high availability.
Incident and Supplier Management What happens when something goes wrong, and how we choose who we depend on.
Incident response lifecycle
On detection of a critical incident we lock down and contain the affected system, investigate root cause and scope, remove malicious code, remediate the vulnerability, and restore the site to its most recent clean state.
Breach notification within 48 hours
We notify the affected client of a confirmed material security breach no later than 48 hours after becoming aware of it, including the nature of the breach and the mitigation steps taken.
Post-incident reporting
Every critical incident closes with a written post-incident summary to the affected client, covering what happened and what changed as a result.
Third-party incident escalation
If an incident at a third-party provider affects services we deliver, we notify the affected client as soon as reasonably possible based on the information available to us.
Service disruption communication
Affected clients are notified of service disruptions and kept updated while we investigate and resolve, in line with agreed service levels.
Supplier selection and oversight
Third-party providers are selected on security posture and operational track record, and are governed by their respective agreements. Where required, clients are informed of providers and approval is obtained during onboarding.
No controls match that search. Send us your questionnaire and we will answer it directly.
Infrastructure assurance
The certifications below are held by our hosting provider and cover the infrastructure your site runs on. Wolf IQ does not hold SOC 2 Type II or ISO 27001 certification in its own right.
Infrastructure provider
Kinsta hosting
Managed WordPress hosting on isolated container environments, with continuous network monitoring and infrastructure-level vulnerability scanning.
View provider evidenceInfrastructure provider
Google Cloud infrastructure
All managed client sites sit on Google Cloud Platform through Kinsta, including redundancy, high availability and off-site backup storage.
View provider evidenceInfrastructure provider certification
SOC 2 Type II
Held by Kinsta, our hosting provider. Wolf IQ does not hold this certification in its own right.
View provider evidenceInfrastructure provider certification
ISO 27001
Held by Kinsta, our hosting provider. Wolf IQ does not hold this certification in its own right.
View provider evidenceWolf IQ control
TLS 1.2 / 1.3 encryption
All remote access to client systems and all data in transit is encrypted over HTTPS using TLS 1.2 or 1.3.
Provider-delivered control
WAF and DDoS protection
Web application firewall and DDoS mitigation at the infrastructure layer, with Cloudflare deployed as an additional layer where applicable.
Subprocessors and infrastructure
The third-party providers we use to deliver managed website services, and the role each one plays.
Managed hosting infrastructure, WAF, DDoS mitigation, infrastructure monitoring and backups.
Underlying cloud infrastructure, redundancy, high availability and encryption at rest.
DNS, CDN, DDoS mitigation and traffic filtering, where deployed.
Daily website backups, staging environments and migrations.
Document library
Public documents open directly. Anything operationally sensitive is released on request, after review, through a time-limited secure link.
Public
Privacy Policy
How we collect, use, store and disclose personal information.
Published on this site
OpenTerms and Conditions
The commercial and service terms that govern our engagements.
Published on this site
OpenSubprocessor and infrastructure summary
The third-party providers used to deliver our services, and the role each one plays.
Listed on this page
OpenAvailable on request
Information Security Policy
The full policy covering governance, access, data handling, change management, resilience and incident response.
Version 1.7, effective 22 September 2025
Infrastructure assurance pack
Hosting architecture summary plus the independent assurance evidence held by our hosting provider.
Includes third-party reports
Business continuity and disaster recovery summary
Backup approach, recovery objectives, restoration testing and escalation ownership.
RTO 2 to 4 business hours, RPO 24 hours
Incident response summary
Our containment, investigation, remediation and reporting lifecycle, and our client notification commitment.
Notification within 48 hours of a confirmed material breach
Security questionnaire response pack
Standard responses to the questions most often raised in vendor risk assessments.
Sanitised master pack, never client specific
Still have a security question?
Send us your questionnaire or contact our team for a specific security or privacy request.