Trust

Security overview

For procurement and security review. It says what is in place today, and is explicit about what is still to come. Last reviewed September 2026.

Where your data lives

Customer isolation

Access control

Handling of uploads and models

Application and server hardening

Backups

Nightly encrypted backups of the database and stored files, with a retention schedule and a tested restore procedure.

Status

ControlStatus
Hosting in Australia, per-customer isolation, two-step sign-in, audit logIn place
Sandboxed model runs (separate process, no database access, resource limits)In place
Offsite encrypted backup copies in Australian cloud storageBeing set up before customer go-live
Disk encryption at rest on the production hostPlanned with the production host
Independent penetration testPlanned before the first paying customer
Single sign-on (Microsoft Entra ID) and API accessPlanned
Model runs in isolated containers with no networkPlanned
Formal certificationControls are being aligned to the ASD Essential Eight and ISO 27001 Annex A; no certification is claimed

Your data and exit

Your data remains yours. On termination or request it is deleted from live systems on a documented schedule and from backups as they expire. We will provide this in writing.

Reporting a problem

To report a security concern or vulnerability, email [email protected]. We will acknowledge it promptly and keep you informed.

Procurement teams: for the full document set (incident response, data processing terms, control mapping), contact us.