Security
Last updated 20 August 2026
Compliantly is built for businesses that take quality and compliance seriously, so security must be in the same league. Here's a plain- English summary of how we protect your data.
Encryption
- In transit: all traffic is TLS 1.2+ via Vercel edge. We do not serve or accept HTTP.
- At rest: the Supabase Postgres database and object storage encrypt every record with AES-256.
- Backups: daily encrypted backups managed by our database provider, retained for 30 days.
Access control
- Row-level security (RLS): every database row is gated by Supabase RLS policies. A user can only read or write rows that belong to a company they're an active member of.
- Role-based permissions: within a workspace, six distinct roles (Owner, QMS Admin, Editor, Contributor, Viewer, Self-service) determine what each user can do.
- Two-factor authentication: available on all plans (TOTP authenticator apps). Enforced 2FA for paid plans is on the roadmap.
- Sub-processor access: our staff don't access your workspace data except where strictly necessary to resolve a support issue you've raised, with your consent.
Application security
- Server-side authorisation: RLS is the second line; the application enforces fine-grained per-action authorisation in server-side code.
- Audit log: every write to a register is recorded in
activity_eventswith the actor, timestamp, and subject. Retained alongside your workspace data. - Dependency hygiene: automated security scanning (npm audit + Renovate) on every commit. Critical CVEs patched within 72 hours.
- Input validation: all user input is validated server-side; AI suggestions go through a tool-use schema and are never trusted blindly.
Sub-processors
Compliantly relies on these vetted sub-processors. Each is bound by contractual data-processing terms compliant with Australian Privacy Principles and (where applicable) GDPR Standard Contractual Clauses.
- Supabase (database, auth, storage) — AWS-hosted.
- Vercel (application hosting + edge network).
- Anthropic (AI inference for suggestions). Prompts are not used for training and are not retained beyond the inference window.
- Resend (transactional email delivery).
- Stripe (billing, when paid plans launch).
Incident response
If we discover a security incident affecting your data, we will notify you as soon as practicable — targeting within 72 hours of becoming aware — consistent with the Notifiable Data Breaches scheme under the Privacy Act. The notice will include what happened, what data was affected, what we're doing about it, and what you should do.
Responsible disclosure
Found something concerning? Please email security@compliantly.com.au (placeholder). We commit to:
- Acknowledging your report within 1 business day.
- Investigating in good faith.
- Not pursuing legal action against researchers acting in good faith and following responsible-disclosure principles.
Compliance roadmap
We're committed to formal certification as the product matures. Targets:
- SOC 2 Type II — within 18 months of paid launch.
- ISO 27001 — within 24 months.
- Australian Information Security Registered Assessors Program (IRAP) PROTECTED — when government / public-sector customers require it.