Biza.io Logo

Security Assurance Portal

Start your security review
View & download sensitive information
Ask for information
ControlK

Biza.io is exclusively focused on helping organisations deliver business value via the Consumer Data Right. We are passionate about open data and giving people choice about how their information is share and to whom. Banking is just the beginning and we are expanding into Energy and other industries as they are announced.

Documents

Featured Documents

DOCUMENTSBCP Exercise

Network Security

We protect our corporate network against external & internal threats.

Knowledge Base (FAQ)
  • Does your company have policies and processes in place that specifically address modern slavery issues in your operations and supply chains?
  • Is our customer data stored in Australia
  • Does Biza have controls for APRA CPS234 or APRA CPS230.
  • Does Biza have a financial statement available?
View more

Security Assurance Portal Updates

CVE-2025-55182

Vulnerabilities

We have confirmed that the roll-out of the vendor patches for the recently disclosed React and Next js vulnerability is completed. All affected services have now been updated, tested and verified in production.

As part of our process, we reviewed logs and monitoring across the impacted systems and found no evidence of misuse, attempted exploitation or impact to your services or data. All platforms continue to operate normally.

There is no action required from our customers.

This concludes our response to this event and we will continue routine monitoring as part of our ISMS controls.

We are aware of an industry-wide critical vulnerability in React Server Components, which is used extensively in modern web applications. https://www.cve.org/CVERecord?id=CVE-2025-55182

Our immediate investigation and assessment identified that it affects the Nextjs versions used in PM, VTT/OG, BizaID Admin and BTR Admin.

It does not impact HaaS, DSaaS, and Appliance Admin.

We have mitigated the highest risk by deactivating our internal web interfaces for Biza ID Admin. This has no impact for our HaaS customers.
Authentication services are unaffected.

While we have found no evidence of exploitation and have mitigated the highest risk, the risk rating is high and patching promptly is the recommended path.

We will be patching the impacted versions through an emergency change once all testing has been completed today.

No action is required from our customers and there is no downtime expected as a result.

Built onSafeBase by Drata Logo