Security Overview - Central AI Platform
Version 2.2 · Last updated July 2026
1. Infrastructure
- Hosting on managed cloud infrastructure with security controls aligned with the ASD Essential Eight framework
- TLS 1.2+ for all data in transit
- Encryption at rest for stored data where applicable
2. Authentication & Access
- Authentication via Supabase Auth (email/password, OAuth)
- API keys and scoped credentials for programmatic and integration access
- Role-based access control (client, developer, customiser, admin) with administrative functions restricted to authorised personnel. We continue to strengthen authentication controls as the platform evolves
- Session management with secure cookies
3. Data Protection
- Personal data processed as per our Data Processing Agreement (DPA)
- Data minimisation where reasonably practicable; usage logs for billing, abuse prevention, and incident response
- Use of third-party AI model providers for platform and agent operations as described in our Terms and Privacy Policy
4. Compliance
- Privacy Act and Australian Privacy Principle aligned controls where applicable
- GDPR and UK GDPR aligned handling where applicable
- DPA available for business and enterprise customers
- Audit logs for administrative actions
5. Incident Response
- Monitoring for anomalies and abuse
- Incident response processes appropriate to the size and scale of our operations
- Notification to affected parties and the OAIC in accordance with the Notifiable Data Breaches (NDB) scheme, where required by law
6. Enterprise Procurement
- Invoices and tax documentation
- DPA and security documentation
- Custom contracts upon request