Agend Pro — Security Framework
This page covers the Agend Pro (WordPress)-specific implementation of our security controls. For the company-wide security principles that apply across all Agend products, see Trust & Compliance — Security Framework.
Hosting Environment Security (Kinsta)
- SOC 2 Type 2 Compliance: our hosting provider Kinsta maintains SOC 2 Type 2 certification, demonstrating their commitment to security, availability, processing integrity, confidentiality, and privacy.
- Cloud Infrastructure: leveraging Google Cloud Platform's secure infrastructure with built-in protection against DDoS attacks, intrusion detection, and hardware security.
- Isolated Container Technology: each WordPress site runs in its own isolated container with dedicated resources, limiting the impact of potential security breaches.
- Automatic Scaling: resources automatically adjust to handle traffic spikes, preventing downtime during high-traffic periods.
- Data Sovereignty: data is stored within Australia (see Data Hosting & Sovereignty).
WordPress Core Security
- Monthly Updates: monthly release schedule for updates to the code base. Critical security updates are applied intra-monthly where appropriate to minimise vulnerability windows — see Updates & Maintenance for the full schedule.
- Plugin and Theme Vetting: strict policy for using only reputable, regularly updated, and security-audited plugins.
- Plugin Minimisation: using only essential plugins to reduce the potential attack surface.
- Regular Security Scans: automated and manual scans for malware, vulnerabilities, and suspicious activities.
Firewalls & Password Security
Agend Pro's application-layer firewall and password security implementation are covered in their own pages:
- Firewalls — Cloudflare WAF + Wordfence
- Password Security — WordPress password hashing, 2FA, and login protection