Effective 1 October 2026. This page summarises current practice and will be updated as controls mature.
Hosting and residency
Regional cells on managed cloud infrastructure in Sydney, Singapore, London, Frankfurt and US East. Your data, backups, logs and AI processing stay in the cell you choose.
Access control
Role and scope-based permissions enforced in the application and again by row-level security in the database. Multi-factor authentication for all internal roles; single sign-on (SAML / OIDC) on Enterprise. Tenant, franchisee, owner and adviser portals use short-lived scoped tokens. Every change is written to an immutable audit log.
Encryption
TLS 1.2 or higher in transit; AES-256 at rest for databases, storage and backups. Secrets are held in a managed vault and rotated.
Availability and backups
Point-in-time recovery with a 15-minute recovery point objective and a 4-hour recovery time objective; daily encrypted backups retained for 35 days; status page with incident history.
Development
Code review on every change, automated tests, dependency scanning, infrastructure as code, separate development, staging and production environments with no shared data.
Vendors
Sub-processors are assessed before onboarding and listed on our Sub-processors page. AI providers are contractually prohibited from training on customer documents.
Incident response
Documented incident response plan; customers notified without undue delay and within statutory timeframes for eligible data breaches.
Responsible disclosure
Report vulnerabilities through our contact form, starting your message with "Security". We will acknowledge within two business days and not pursue good-faith researchers who respect this policy.
Certifications
[Planned: ISO 27001 alignment in year one; SOC 2 Type II to follow. Update this section as attestations are obtained.]