Trust Centre
Security, privacy, and how we handle your data.
The short version: your data lives in Australia, it is encrypted in transit and at rest, and you can take it with you at any time. The detail is below, and our team will answer anything this page doesn't.
Security posture
- All traffic encrypted in transit (TLS 1.2+); customer data encrypted at rest
- Role-based access control in the platform: Full Users and Field Users see only what their role needs
- SSO available on the Enterprise plan
- Production access restricted to authorised engineers, logged and reviewed
Data residency
Customer data is hosted in Australian-region infrastructure. Data does not leave Australia in the ordinary course of operating the platform.
Backup and recovery
Automated backups run daily with point-in-time recovery on production databases. Formal RPO/RTO targets will be published here once confirmed — ask us for the current numbers in the meantime.
Subprocessors
We use a small number of subprocessors to run SiteSherpa (cloud hosting, scheduling and email). The full, current list with data-handling detail is available on request while we finalise the published register.
Standards alignment
Our security practices align with recognised standards such as ISO 27001 and SOC 2. Interim security documentation is available for procurement reviews today, and no badge theatre: if and when we are certified, you will see the certificate here, not before.
Your data, your exit
You can export your data at any time. If you leave, your records leave with you in standard formats. No lock-in theatrics.
