.
Security at Satellite
Last reviewed: August 2026. This page is owned by Satellite's security team and reviewed at least annually.
Our clients trust us with their brands, their events and their customers' data. We take that seriously. Here's a plain-English look at how we protect the systems we build and the information that flows through them.
If you'd like more detail on any of this, security questionnaires, audit reports, the fine print, get in touch and we'll sort you out.
Where your data lives
Tag, our live experience platform, runs on Amazon Web Services. Every deployment sits inside its own protected network, spread across multiple data centres so a failure in one doesn't take anything down. Traffic comes in through one front door only: encrypted HTTPS connections, screened by AWS's web application firewall before it reaches us.
Personal information gets extra care. We store it in a segregated part of the platform with tighter access restrictions than everything else.
AWS looks after the physical side (the buildings, the guards, the generators) and holds the certifications to prove it, including SOC 2 and ISO 27001. We review their audit reports every year, because trusting a provider isn't the same as checking on them.
How we protect it
Your data is encrypted on the way to us and while it's stored with us, including backups. Backups run on a schedule, they're monitored for completion, and access to them is restricted to a small number of senior technical staff.
We keep data only as long as it's needed. When it's no longer required, or when hardware is retired, data is securely destroyed under our retention and decommissioning policies.
Who can touch what
Access at Satellite works on a simple rule: you get the minimum access your job needs, and nothing more.
- Access to systems is role-based, and requests for anything privileged need approval from our Technical Director.
- Only our operations team can reach the production environment.
- Everyone uses a company password manager, and multi-factor authentication backs up password sign-ins.
- When someone leaves, privileged access is removed as soon as notice is given, and every account is deprovisioned within three days.
- We review all access annually to make sure the minimum-access rule still holds.
How we build
Security is part of how we develop software, not a check at the end.
- Every code change is peer reviewed before it ships.
- Development and testing happen in environments completely separate from production, and changes need documented approval before they go live.
- Automated tooling scans our code and open-source dependencies for known vulnerabilities as part of our build pipeline.
- We test our applications against the OWASP framework — the industry standard for web application security.
Watching, testing, fixing
We assume the threat landscape changes daily, because it does.
- Intrusion detection and monitoring run continuously across our platform, with alerting that tells us about problems fast.
- We run internal vulnerability scans quarterly and external scans annually, with independent security specialists engaged for penetration testing every year.
- Our security team monitors threat intelligence from the National Cyber Security Centre (NCSC NZ), AWS security bulletins and leading security researchers, so emerging threats get assessed against our stack as they surface.
- Every vulnerability we find is ranked by severity and tracked to resolution, with defined timeframes for remediation. Critical issues get worked on immediately.
When something goes wrong
No honest security page says "nothing will ever go wrong." What matters is what happens next. We maintain a documented incident response plan covering identification, containment, and notification so if an incident affects you or your data, you'll hear it from us, promptly and straight.
Found a security issue in something we've built? Tell us. We welcome reports from customers, security partners and researchers, and we'll respond quickly.
Our people
Technology is half the picture. The other half is the ~35 people who work here.
- Background checks are part of our hiring process.
- Everyone completes security training when they join, and agrees to our security policies and Code of Conduct.
- Confidentiality obligations are built into employment terms and survive after someone leaves.
Compliance
We're currently completing SOC 2 attestation with independent auditors, with our security programme continuously monitored through Vanta. We operate under the New Zealand Privacy Act 2020, and our platform runs on AWS infrastructure certified against SOC 2, ISO 27001 and more.
Want our latest audit reports or a security questionnaire filled in? Ask us that's what it's there for.