Skip to main content

Wolf IQ Trust Centre

Start your security review.

Review how we protect client websites and data, understand our infrastructure, and request access to security documentation.

Typical response to an access request: two business days.

Search our security controls

These controls come from our documented Information Security Policy. Search by control or category name.

Governance and People Who owns security, how it is documented, and what every person working on your site is held to.
Documented Information Security Policy

Wolf IQ maintains a written Information Security Policy covering governance, access, data handling, change management, resilience and incident response. It is aligned with our Terms and Conditions, Privacy Policy and the commitments we make in vendor risk assessments. The current approved version is available on request.

Annual policy review

The policy is reviewed and endorsed annually, and again after any material change to our technical environment or business operations. Version and effective date are recorded on the document itself.

Defined security responsibilities

Information security is managed internally by our technical team. Each client environment has a named internal owner responsible for access management and service delivery, and infrastructure-level security and monitoring sits with our hosting provider.

Security awareness training

All employees and contractors complete information security and data privacy awareness training during onboarding and on an ongoing basis. Acceptable use requirements and data handling protocols are set as a condition of engagement.

Confidentiality obligations

Every employee and contractor is bound by confidentiality and acceptable use agreements before they are given access to any client environment.

Personnel vetting

All personnel undergo identity verification and professional due diligence prior to engagement. Formal background checks are mandatory for anyone granted privileged administrative access to production environments or sensitive data.

Access Control Who can reach your environment, what they can do there, and how quickly that access is removed.
Unique accounts and role-based access

Access to client environments, hosting dashboards and sensitive data is granted through individually attributable accounts. Role-based access controls determine what each person can do in each system.

Least privilege

Access is granted strictly on a need-to-know basis and limited to what the role requires. Elevated permissions are the exception, not the default.

Mandatory multi-factor authentication

MFA is required for all Wolf IQ personnel accessing critical infrastructure, password managers and client production environments. Strong password policies are enforced on privileged and non-privileged accounts alike.

Periodic access review

Access rights are reviewed on a recurring basis to confirm that every account still needs the permissions it holds. Anything no longer required is removed at the point of review.

Immediate access revocation

On role change, offboarding or contract termination, all system access is revoked immediately. A formal review follows to confirm the ongoing integrity of every affected environment.

Encrypted remote access

All remote access to client systems runs over encrypted connections using HTTPS with TLS 1.2 or 1.3. There is no unencrypted administrative access path.

Approved access locations

Access is restricted to authorised personnel located in Australia and the Philippines, unless a client approves an additional location in writing.

Static IP allowlisting on request

Where a client requires it, access can be restricted to pre-approved static IP addresses to support their own allowlisting controls.

Data Protection and Privacy How client data is classified, encrypted, retained and destroyed.
Asset identification and classification

Information assets are identified during onboarding and are generally limited to website data, CMS databases and associated media. Assets are classified as public or sensitive, and where a client supplies their own classification we apply controls to match it.

Encryption in transit

All data in transit is encrypted using TLS 1.2 or 1.3 over HTTPS, across both client-facing traffic and administrative access.

Encryption at rest

Encryption at rest is managed by our hosting provider on Google Cloud Platform using cloud provider-managed encryption standards. Key management sits with the hosting provider.

Retention and secure deletion

Client data is retained only for as long as required to deliver contracted services and meet legal obligations. On termination, associated client data including backups is securely destroyed. Automated daily backups are retained for up to 90 days.

Restricted log access

Application logs are reviewed during incidents and troubleshooting. Infrastructure and security event logs are retained for a minimum of 90 days by our hosting provider, and access to audit and event logs is limited to authorised personnel.

No payment card data in WordPress

Payment card information is never stored in the WordPress environments we manage. Payment processing runs exclusively through third-party gateways, so sensitive financial data is not held at the application layer.

Australian privacy alignment

Our internal workflows are aligned with the Australian Privacy Act and the Notifiable Data Breaches scheme. Mandatory regulatory notification obligations remain with the client as the data holder.

Application and Change Security How changes reach your live site, and what stops a bad one getting there.
Separate staging and production

Every managed client website runs separate development, staging and production environments. Nothing is edited directly against production as a matter of course.

Documented change workflow

All WordPress updates, fixes and enhancements follow a structured change process. Changes are tracked in our internal task management system and reviewed and approved internally before implementation.

Testing before production

Changes are tested in a staging environment before deployment. Non-critical updates are batched into scheduled maintenance windows rather than pushed ad hoc.

Version control and rollback

Rollback capability is maintained through version control and backup restoration, so a change that causes a problem can be reversed rather than patched under pressure.

Licensed software only

All software in use, including WordPress core, premium plugins and development tools, is legally licensed and maintained under an automated update policy.

Continuous vulnerability monitoring

Application-level vulnerabilities are monitored continuously through automated scanning. Infrastructure-level scanning is handled by our hosting provider.

Immediate critical patching

Critical vulnerabilities are patched immediately on identification rather than held for the next maintenance window.

Periodic application security review

Wolf IQ conducts periodic application security reviews as part of WordPress maintenance. Our hosting provider runs regular infrastructure penetration testing, and we can support formal third-party penetration testing arranged by a client on request.

Infrastructure and Resilience Where your site lives, how it is defended, and how quickly it comes back.
Enterprise hosting on Google Cloud

Managed sites run on Kinsta, which operates on Google Cloud Platform. Kinsta holds independent SOC 2 Type II and ISO 27001 certification covering that infrastructure.

Isolated client environments

Client data is logically segregated using isolated container-based hosting environments, so an incident affecting one client environment does not spread to others.

WAF and DDoS mitigation

Infrastructure-level controls include web application firewalls and DDoS mitigation, applied across all managed environments.

Cloudflare as an additional layer

Where applicable, Cloudflare is deployed for DNS-level protection, DDoS mitigation and traffic filtering on top of the hosting layer.

Continuous provider monitoring

Network traffic is monitored continuously at the infrastructure layer by our hosting provider, with alerting into their security operations.

Daily automated backups

Automated daily backups of all managed websites run through both BlogVault and Kinsta. Backup jobs are actively monitored and failures are investigated and resolved.

Off-site storage and 90-day retention

Backups are stored off-site on Google Cloud and retained for up to 90 days, giving a recovery window well beyond a single bad deployment.

Restoration testing

Periodic restoration testing is carried out to confirm that backups restore cleanly, rather than assuming a successful backup job means a usable backup.

Recovery objectives

Recovery Time Objective is 2 to 4 business hours during standard operating hours. Recovery Point Objective is 24 hours, based on the daily backup cycle. Both are supported by infrastructure-level redundancy and high availability.

Incident and Supplier Management What happens when something goes wrong, and how we choose who we depend on.
Incident response lifecycle

On detection of a critical incident we lock down and contain the affected system, investigate root cause and scope, remove malicious code, remediate the vulnerability, and restore the site to its most recent clean state.

Breach notification within 48 hours

We notify the affected client of a confirmed material security breach no later than 48 hours after becoming aware of it, including the nature of the breach and the mitigation steps taken.

Post-incident reporting

Every critical incident closes with a written post-incident summary to the affected client, covering what happened and what changed as a result.

Third-party incident escalation

If an incident at a third-party provider affects services we deliver, we notify the affected client as soon as reasonably possible based on the information available to us.

Service disruption communication

Affected clients are notified of service disruptions and kept updated while we investigate and resolve, in line with agreed service levels.

Supplier selection and oversight

Third-party providers are selected on security posture and operational track record, and are governed by their respective agreements. Where required, clients are informed of providers and approval is obtained during onboarding.

Infrastructure assurance

The certifications below are held by our hosting provider and cover the infrastructure your site runs on. Wolf IQ does not hold SOC 2 Type II or ISO 27001 certification in its own right.

Infrastructure provider

Kinsta hosting

Managed WordPress hosting on isolated container environments, with continuous network monitoring and infrastructure-level vulnerability scanning.

View provider evidence

Infrastructure provider

Google Cloud infrastructure

All managed client sites sit on Google Cloud Platform through Kinsta, including redundancy, high availability and off-site backup storage.

View provider evidence

Infrastructure provider certification

SOC 2 Type II

Held by Kinsta, our hosting provider. Wolf IQ does not hold this certification in its own right.

View provider evidence

Infrastructure provider certification

ISO 27001

Held by Kinsta, our hosting provider. Wolf IQ does not hold this certification in its own right.

View provider evidence

Wolf IQ control

TLS 1.2 / 1.3 encryption

All remote access to client systems and all data in transit is encrypted over HTTPS using TLS 1.2 or 1.3.

Provider-delivered control

WAF and DDoS protection

Web application firewall and DDoS mitigation at the infrastructure layer, with Cloudflare deployed as an additional layer where applicable.

Subprocessors and infrastructure

The third-party providers we use to deliver managed website services, and the role each one plays.

Kinsta Google Cloud Platform

Managed hosting infrastructure, WAF, DDoS mitigation, infrastructure monitoring and backups.

Google Cloud Platform Global, region dependent

Underlying cloud infrastructure, redundancy, high availability and encryption at rest.

Cloudflare Global edge network

DNS, CDN, DDoS mitigation and traffic filtering, where deployed.

BlogVault Off-site backup storage

Daily website backups, staging environments and migrations.

Document library

Public documents open directly. Anything operationally sensitive is released on request, after review, through a time-limited secure link.

Public

Available on request

Restricted

Information Security Policy

The full policy covering governance, access, data handling, change management, resilience and incident response.

Version 1.7, effective 22 September 2025

Restricted

Infrastructure assurance pack

Hosting architecture summary plus the independent assurance evidence held by our hosting provider.

Includes third-party reports

Restricted

Business continuity and disaster recovery summary

Backup approach, recovery objectives, restoration testing and escalation ownership.

RTO 2 to 4 business hours, RPO 24 hours

Restricted

Incident response summary

Our containment, investigation, remediation and reporting lifecycle, and our client notification commitment.

Notification within 48 hours of a confirmed material breach

Restricted

Security questionnaire response pack

Standard responses to the questions most often raised in vendor risk assessments.

Sanitised master pack, never client specific

Still have a security question?

Send us your questionnaire or contact our team for a specific security or privacy request.

Contact security team

Request document access

Requests are reviewed manually. Approved documents are sent through a time-limited secure link, never as a public URL.