Security and Compliance

Security and compliance, built in.

Designed to support secure payment handling and council-grade operational controls. FlexiRates addresses the security and compliance requirements of Australian local government.

PCI DSS Compliant Payment Capability
Encrypted Data Transmission
Australian Privacy Principles

Secure payment processing.

Card processing runs in a PCI DSS compliant environment. Neither council staff nor ratepayers handle raw card data — sensitive payment information is kept secure at every step.

Direct debit arrangements capture proper digital authorisation, with records kept for compliance and dispute resolution.

PCI DSS Compliant Environment
Payment processing meets the security standards required for handling card payments.
Card Tokenisation
Card numbers are never stored directly. A secure token is used for all subsequent payments — raw card data is not retained.
Direct Debit Authorisation
Ratepayers provide explicit digital authorisation for each arrangement, and records are maintained for compliance.

Protected data, controlled access.

Data is encrypted in transit and the platform follows data-minimisation principles — collecting only what's needed to operate.

On the council side, role-based access and full audit logging are designed to meet local government governance requirements.

Encryption & Secure Authentication
All traffic is encrypted in transit using industry-standard protocols. Ratepayers and admin users authenticate securely before access.
Role-Based Access & Sessions
Admin roles follow least-privilege principles, and inactive sessions time out to reduce the risk of unauthorised access.
Audit Logs
Significant admin actions are logged with timestamps and user identifiers — supporting governance, compliance, and dispute resolution.

Built for council-grade accountability.

FlexiRates handles personal information consistent with the Australian Privacy Principles under the Privacy Act 1988. The council remains the primary data controller; FlexiRates processes data on its behalf under the agreed service arrangements.

Configuration is council-controlled, with the records and audit trails needed for governance and accountability.

  • Ratepayers can view, update, and manage their own information
  • Council-configurable payment rules and settings
  • Complete authorisation records for direct debit arrangements
  • Failed payment detection and admin notification
  • Payment reports suitable for rates ledger reconciliation

Questions About Our Security Approach

We take security questions seriously and welcome engagement from councils and security researchers.

Get in Touch

If you have questions about our security approach, wish to discuss security requirements for your council, or have identified a potential security concern, please contact us through the form on our contact page. We will respond promptly.

Contact Us About Security

Questions about our security approach?

We are happy to discuss our security design and compliance approach with your council's IT, risk, or procurement teams as part of the evaluation process.