Secure by Architecture, and Australian End to End
One shared data model, one permission model, a dedicated container per client, and no path to your data except through the application layer itself. Production, metadata, logs, backups, disaster recovery, support access and AI processing all stay inside Australian AWS regions.
Four Facts That Everything Else Follows From
Stack9 Experience is architected on genuine MACH principles — microservices with their own API surfaces, API-first, cloud-native on AWS, and headless. Because each capability is a discrete service, you keep the option to run a best-of-breed alternative alongside Stack9 for any given workload.
One shared data model
Stack9 Core and Stack9 Experience are two components of one platform connected to the same backend API layer — not two products with an integration between them. New capability extends the model rather than adding a system to integrate, so glue code and sync logic do not accumulate.
Tenant isolation without forking the platform
Each client instance is a dedicated Docker image at its own hostname, built by layering client configuration onto the standard Stack9 Core base image. Per-client isolation and a common upgrade path at the same time.
API-first, no proprietary protocol
100+ REST endpoints described with OpenAPI 3.0, secured with API keys or OpenID Connect. Every entity you define automatically produces standard REST resources. Content and data stay portable regardless of future platform decisions.
Headless, fully decoupled front end
Web App Templates are standard HTML, JavaScript and CSS that any web developer can extend — not a proprietary templating language requiring certified specialists.
Four Layers, Stated Concretely
Encryption
All data encrypted at rest and in transit via AWS RDS native encryption.
Network isolation
The database sits in a secure subnet within a private VPC with no direct internet exposure. Only the application’s running containers can reach it.
Access control with no bypass
Because all data access is mediated through the application interface, User Groups, RBAC and row-level security govern every request to sensitive data. There is no direct database access path that could bypass these controls.
Tenant isolation
A dedicated per-client Docker instance, in ISO 27001-certified cloud environments isolated from other tenants.
What We Hold — and What We Do Not
Being explicit about all three states is the point. A discovered gap costs far more than a declared one.
| Standard | Status |
|---|---|
| ISO 27001 | HeldHeld by April9 for over five years, underpinned by a mature ISMS with segregation of duties, least-privilege access and formal risk management. AWS, our primary infrastructure provider, is itself ISO 27001 certified. |
| IRAP | EngagementThe Comcover engagement was delivered and operates under IRAP certification — a higher bar than ISO 27001 alone, designed for Australian government risk frameworks. IRAP applies to that engagement, not to Stack9 as a product certification. |
| PCI DSS | EngagementThe Surf Life Saving Australia platform is PCI DSS-compliant for payment card handling, with direct integration into banking institutions. Stack9 itself never handles card data — it stays with the provider’s PCI-compliant SDK. |
| OLGR | EngagementSurf Life Saving’s lottery systems are certified by the Queensland Office of Liquor and Gaming Regulation. |
| WCAG | In production“Your Passport to Queensland” (Queensland Department of Education) was specified and approved to WCAG AA and is in production. Note: WCAG AA, not 2.2 AA, and a mobile application rather than a Stack9 portal. Dedicated WCAG 2.2 AA testing and independent third-party auditing are scoped explicitly per engagement rather than included as standard. |
| ISO 9001 | In progressQuality Management System certification targeted for completion by Q1 2027. |
| ISO 42001 | In progressAI management system certification targeted for Q2 2027 — not yet held. AI is governed today under April9’s documented AI Policy within the ISO 27001 ISMS. |
| SOC 2 | Not heldNot certified, and not being pursued at this time. For Australian buyers the more relevant credentials are ISO 27001 held for 5+ years and IRAP delivery experience. |
| GDPR | Not defaultNot a default platform setting. GDPR-aligned data handling — data subject access and erasure processes — can be implemented on web portals where a specific engagement requires it. |
No Data Leaves Australian AWS Regions
Including AI processing — which is where most global DXP vendors have a gap.
- ap-southeast-2 (Sydney) — production, metadata, logs and AI processing.
- ap-southeast-4 (Melbourne) — backups and disaster recovery replication.
- Backups — daily RDS snapshots and monthly full database backups.
- Support — a fully onshore Australian team, with no offshore support tier.
- Privacy — handled under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, with a contractual commitment to notify clients of any data breach within 72 hours of becoming aware of it.
Audit, Identity and Change Control
Record-level audit trail
Every record change is versioned and stored in S3 with the user, timestamp and complete change history. Versions can be compared side by side and a previous version restored directly. Infrastructure changes are captured separately via AWS CloudTrail.
Delegated authentication
Authentication is delegated to your identity provider, so your MFA policy is inherited automatically. Stack9 implements no MFA of its own — that is deliberate, not an omission.
Upgrades you do not run
April9 rebuilds and deploys both the Core base image and each client instance image. You can remain on an LTS version as long as its dependencies still receive security patches, with annual framework uplift recommended and included under the MSA. LTS is bounded by dependency support — it is not indefinite.
Independent validation
The solution architecture has been independently reviewed by a third-party security reviewer and by AWS’s own solution architects. Annual penetration testing with formal security reporting is delivered under a managed service engagement.
Four Models, One Codebase
Stack9 Core ships as a Docker container image, which is what makes multiple deployment models possible without forking the platform. A typical instance runs three environments: DEV, UAT and Production.
- Cloud-native on AWS — recommended. Instances run on ECS in an account you own, operated by April9 on your behalf. Full residency and account ownership without the day-to-day operational burden.
- PaaS. The same managed ECS model, described for procurement frameworks that ask for platform-as-a-service. Not a separate product.
- Hybrid / self-hosted. AWS is the primary and fully optimised environment. Azure is technically supported with some performance trade-offs. Deployment outside AWS or Azure is not recommended without further validation.
- Multi-tenant SaaS. Shares hosting resources to reduce infrastructure cost. Not recommended where you require full infrastructure isolation from other tenants — take the dedicated single-tenant AWS model instead.
The Gaps, Before You Have to Find Them
- Privacy incident investigation tooling does not exist. The audit data is there — versioned records, full change history, CloudTrail — but there is no purpose-built tooling for privacy incident investigation, structured evidentiary reporting or chain-of-custody handling. It could be built against the existing audit logs using AWS services, including AI-assisted analysis, but that is dedicated development.
- Consent-based access is not native. It is supported as a customisation on the existing domain entity model.
- Configurability does not bypass change governance. Changes made via Stack9 Console are still raised, reviewed and deployed through a formal Request for Change process. Low-code improves speed within governance; it does not replace it.
- There is no universal integration reference architecture. Each integration is assessed individually, because the right protocol depends on what the target system actually exposes.
Why we publish this
Evaluators discount vendors who claim everything. Declaring the genuine gaps alongside their mitigations is what makes the other ninety claims credible — and it is cheaper for both of us than finding out in week nine of a delivery.
Reviewed by a Third Party, and by AWS
Rather than relying on internal assessment alone. If you have a security questionnaire, a cyber review or a jurisdiction-specific policy to map against, that mapping is part of discovery.