Home › Security
Security and data residency, in plain English
Your information stays in your own systems. Anything we host is treated as the most sensitive thing we touch. Here is what we do, and what we do not claim.
What we do
- Hosted in Sydney (AWS via Fly and Supabase). NZ Privacy Act IPP 12 compliant.
- Multi-tenant by design: org_id on every row, RLS on every query, every test.
- Hash-chained audit log per ADR-0004. Append-only, immutable, verifiable.
- Magic-link auth via Supabase; MFA enforced; sessions cookie HttpOnly, Secure and SameSite=Lax.
- All secrets in Fly secrets, never in source. Gitleaks runs on every PR.
- CSP nonce per request, HSTS, X-Frame-Options DENY, strict referrer policy.
- In-process rate limiter on auth and write endpoints.
- Quarterly PITR restore drills. RPO 1h / RTO 4h.
What we do not claim
- No SOC 2 yet. Vanta readiness is in progress.
- No ISO 27001.
- Pen test scoped for the end of P1, not yet conducted.
- No published uptime figure.
- Sydney is in Australia, not New Zealand. We say so because it matters if your client asks.