SolutionsCalls and voice notesSecure meeting recordingCustomer records that stay currentWeb apps built for your businessMobile apps for the team on the roadProjects that report themselvesConsulting and trainingView all solutions
AboutPricing
ResourcesWhat is AI?TrainingFAQsBlog
Contact
Sign inClient portalStaff portal
Book a call
HomeSecurity

Security and data residency, in plain English

Your information stays in your own systems. Anything we host is treated as the most sensitive thing we touch. Here is what we do, and what we do not claim.

What we do

  • Hosted in Sydney (AWS via Fly and Supabase). NZ Privacy Act IPP 12 compliant.
  • Multi-tenant by design: org_id on every row, RLS on every query, every test.
  • Hash-chained audit log per ADR-0004. Append-only, immutable, verifiable.
  • Magic-link auth via Supabase; MFA enforced; sessions cookie HttpOnly, Secure and SameSite=Lax.
  • All secrets in Fly secrets, never in source. Gitleaks runs on every PR.
  • CSP nonce per request, HSTS, X-Frame-Options DENY, strict referrer policy.
  • In-process rate limiter on auth and write endpoints.
  • Quarterly PITR restore drills. RPO 1h / RTO 4h.

What we do not claim

  • No SOC 2 yet. Vanta readiness is in progress.
  • No ISO 27001.
  • Pen test scoped for the end of P1, not yet conducted.
  • No published uptime figure.
  • Sydney is in Australia, not New Zealand. We say so because it matters if your client asks.