Security Statement

Overview

Western Mailing Limited & Western Mailing Wellington Limited (“Western Mailing”, “We”) maintains a security and compliance program designed to protect the confidentiality, integrity and availability of customer information and the systems used to deliver its services. Controls are independently assessed through a SOC 2 Type II examination and are supported by governance processes, policies, technical safeguards, monitoring activities and security awareness initiatives.

SOC 2 Type II Assurance

Western Mailing has successfully completed a SOC 2 Type II examination demonstrating that our controls were suitably designed and operated effectively over the entire review period. The examination was conducted in accordance with the Trust Services Criteria (Security, Availability, and Privacy) established by the American Institute of Certified Public Accountants (AICPA), and performed by an independent, licensed audit firm.

Security Controls Summary

Authentication and Access Security

We maintain authentication and access controls designed to protect customer data and business systems from unauthorised access. Access is granted according to business need, supported by strong authentication mechanisms, and subject to ongoing management and review.

  • We support multi-factor authentification (MFA) across applicable platforms and services.
  • The use of MFA may depend on the specific service, customer integration requirements, and agreed solution design.
  • For file transfer services, secure authentification mechanisms including SSH public/private key authentification are supported.
  • Privileged and administrative access is protected through enhanced authentification controls and restricted to authorised personnel.

Data Protection

We maintain technical and organisational controls designed to protect customer information throughout its lifecycle. These controls support the confidentiality, integrity, and availability of information and include measures for encryption, access control, data handling, and secure storage.

  • Customer data is encrypted during transmission using industry standard protocols.
  • Industry-standard security controls to protect data within production environments, including access management, monitoring, and encryption mechanism are employed where applicable.
  • Backups containing customer information are protected through encryption and restricted access.

Secure Data Transfer

Secure file transfer capabilities are available, including SFTP with public/private key authentication.

Monitoring and Security Operations

We maintain monitoring and security operation processes designed to support the timely identification, investigation, and response to security-related events. These processes help protect customer information and support the ongoing effectiveness of our information security programme.

  • Security-relevent events are logged and monitored.
  • Vulnerability management processes are maintained to identify and remediate security weaknesses.
  • Documented incident response procedures are maintained.

Control Environment

We maintain information security policies, governance processes, and technical controls designed to protect customer information and support the secure delivery of services.

Availability

We maintain controls to support the availability of our systems and services. These include proactive system monitoring, incident response procedures, and operational processes designed to minimise disruption and support service continuity.

Risk Management and Monitoring

We maintain processes to identify, assess, and manage risks that may impact the confidentiality, integrity, and availability of information and systems.

  • Information security policies and standards
  • Access management and user provisioning processes
  • Security monitoring and logging
  • Vulnerability management activities
  • Incident response procedures
  • Change management and operational controls
  • Security awareness and training programmes for all staff

These controls are subject to ongoing review as part of our broader risk management and compliance framework. 

  • System monitoring and operational alerting
  • Backup and recovery processes
  • Incident response and escalation procedures
  • Change management controls designed to minimase unintended service disruption

Security Due Diligence Requests

We support appropriate customer due diligence and transparency regarding information security practices. However, we generally do not complete bespoke security questionnaires or provide detailed security documentation to organisations that do not have a contractual relationship with us.

  • Security questionnaires frequently request sensitive information regarding internal systems, security architecture and operational controls.
  • Disclosure of detailed security information outside an established commercial and confidentiality framework may increase security risk.
  • Many questionnaires seek information already addressed through our security programme and independently assessed SOC 2 Type II assurance.
  • A consistent disclosure process helps ensure information remains accurate, current and appropriately governed.

Report Use and Distribution

Due to the sensitive nature of SOC 2 reports and supporting security documentation, their distribution is controlled.

  • Full SOC 2 reports are generally only made available to contracted customers and approved business partners.
  • Additional security information may be provided subject to appropriate confidentiality and non-disclosure obligations.
  • Public disclosures regarding security controls are limited to information considered apropriate for external publications.

This approach aligns with industry practice and supports responsible disclosure of security-related information. 

Contact

For security-related inquiries, please contact our customer service team in the first instance: customerservice@wm.co.nz