Security at Foodworks
Foodworks handles sensitive data: client dietary records, proprietary recipes, product formulations. We know what that data means to your organisation, and we build accordingly. This page outlines how we protect customer data across hosting, encryption, access controls, development practices, and independent testing. If your procurement or IT security team needs more detail, we're happy to talk.
Australian hosting
AWS Sydney region. All data stays in Australia.Foodworks is operated by Xyris Pty Ltd, an Australian company based in Brisbane, Queensland.
All customer data is hosted in Amazon Web Services (AWS) in the Sydney region (ap-southeast-2). Data storage, processing, and backups are restricted to Australian data centres. Your data doesn’t leave the country.
If your organisation has data sovereignty requirements, the short version is: your data stays in Australia, managed by an Australian company on Australian infrastructure.
Data ownership
You retain full ownership. We treat it as confidential.Customers retain full ownership of their data. Xyris does not obtain any intellectual property rights over data entered into Foodworks.
Customer data is accessible only to the customer and their authorised users through their Foodworks instance. We treat all customer data as confidential information and maintain technical and organisational controls to protect it against misuse, loss, interference, unauthorised access, modification and disclosure.
If we ever become aware of a suspected or actual data incident affecting your account, we will notify you.
Encryption
AES-256 at rest, SSL/TLS in transit, encrypted backups.Data is encrypted in transit using SSL/TLS and encrypted at rest using AES-256, the same standard used by financial institutions and government agencies.
Encryption keys are managed through AWS Key Management Service (KMS), which handles key protection, management, and rotation. Backups are fully encrypted using the same methodology as production databases.
User passwords are salted and hashed. They are never stored in plain text and cannot be retrieved by Xyris staff.
Access controls
Microsoft Entra ID SSO, 2FA, role-based access.Foodworks supports role-based access controls following the principle of least privilege. Organisations manage their own users, including granting and revoking access.
Single sign-on. Foodworks supports Microsoft Entra ID (formerly Azure AD) single sign-on. Organisation owners can make SSO mandatory for their account.
Two-factor authentication. 2FA is available for all user accounts and can be made mandatory by the organisational owner.
Internal access. Xyris staff require multi-factor authentication for sensitive system access. Account lockout controls are in place after repeated failed login attempts.
Infrastructure
Private subnets, WAF, ports closed by default.Foodworks runs on AWS with network-level and application-level access controls working together.
The environment uses public and private subnet separation. Application services and databases sit in private subnets and are not directly exposed to the public internet. Access to databases is restricted to the relevant application services.
Additional controls include AWS web application firewall (WAF), security groups, IAM roles, private network segmentation. All ports are disabled by default and only enabled where required for application operation. Directory viewing is disabled on web servers, and request filtering is in place.
Production and non-production environments are logically separated.
Backups & recovery
Nightly backups, 7-day point-in-time restore.Customer data is backed up nightly with automated backup recovery testing through AWS. Point-in-time recovery allows us to restore database state to any moment within the previous seven days.
Backups are stored in the AWS Sydney region, with cross-region backups within Australia, providing additional resilience for disaster recovery.
Foodworks is cloud-hosted, and the Xyris team operates with full remote capability. A disruption to the physical office location would not affect service delivery or customer support.
Secure development
Internal team, peer review, separated environments.Foodworks is developed internally by the Xyris engineering team. There is no offshore or outsourced development.
All code changes go through peer review and testing before production release. Development, staging, and production environments are separated, and changes must pass through the full testing pipeline before deployment.
Changes that could affect the security posture of the application are subject to third-party penetration testing before release.
Security testing is aligned with recognised frameworks including OWASP Top 10, SANS Top 25, WASC Threat Classification, and NIST SP 800-115.
Patch management follows the same controlled process as other code changes, including testing, peer review, and CI/CD deployment controls.
Penetration testing
Independent testing by TrustedImpact. No critical or high issues.Foodworks undergoes regular independent security testing by TrustedImpact, a specialist security testing firm.
Monitoring
CloudWatch, CloudTrail, post-incident review process.We use AWS CloudWatch and CloudTrail to monitor system activity, application logs, and account-level events. User file uploads are scanned for malware.
Security incidents/incidents are escalated internally to the CEO, technical manager, product manager, and development team. Incidents are recorded, investigated, remediated, and reviewed through a post-incident process.
Customers affected by a security incident are notified as soon as practicable.
Privacy
Australian privacy law. De-identified where possible.Xyris complies with applicable Australian privacy laws in relation to customer and user data.
Personal information is stored on secure servers protected from unauthorised access, modification or disclosure. Information transferred across public networks is encrypted using SSL, TLS, and access to systems requires two-factor authentication where possible.
We do not disclose personal information except in accordance with our privacy policy or with consent. Where we use de-identified data, it will not include information that could reasonably identify a person.
We take reasonable steps to destroy or de-identify personal information that is no longer needed unless required to retain it by law.
Questions about security?
If your organisation has specific security or compliance requirements, or if your procurement team needs to run through a security questionnaire, we're happy to help.
