Security and data
Readiness records are safety evidence. They must be accurate, available when a regulator asks, and invisible to everyone else.
Controls
- Data location
- Every record and photo stored in Sydney (ap-southeast-2). The dashboard runs in Sydney.
- Separation
- Enforced in the database, not the app. One organisation cannot reach another, by any route.
- Proof
- 161 automated tests run on every change, including 29 deliberate attacks. All are refused.
- Roles
- Crew, officer, fleet manager, org admin. Officers see alerts for their own station.
- Audit log
- Append only. Cannot be edited or deleted by anyone, including us.
- Records
- Submitted checks and published templates cannot be altered after the fact.
- Photos
- Private storage, served through short lived links to that organisation only.
- Sign in
- Email and password, with Microsoft single sign-on available. Passwords never stored by us.
- Transport
- HTTPS everywhere, strict content security policy, no framing.
- Independent review
- External security review and penetration test before the first customer fleet goes live.
Straight answers
- Can you see our data?
- Only with your permission, for support. Access is logged.
- What if we leave?
- Export everything as spreadsheets. It is your record.
- Do you sell or train on our data?
- No.
- Who hosts it?
- Supabase and Vercel, both in Sydney.
We are happy to walk your IT or WHS people through the detail, including the tests, before you commit.
Bring your IT questions
We will answer them plainly, and show you the tests rather than a certificate wall.