Security Overview - Central AI Platform

Version 2.2 · Last updated July 2026

1. Infrastructure

  • Hosting on managed cloud infrastructure with security controls aligned with the ASD Essential Eight framework
  • TLS 1.2+ for all data in transit
  • Encryption at rest for stored data where applicable

2. Authentication & Access

  • Authentication via Supabase Auth (email/password, OAuth)
  • API keys and scoped credentials for programmatic and integration access
  • Role-based access control (client, developer, customiser, admin) with administrative functions restricted to authorised personnel. We continue to strengthen authentication controls as the platform evolves
  • Session management with secure cookies

3. Data Protection

  • Personal data processed as per our Data Processing Agreement (DPA)
  • Data minimisation where reasonably practicable; usage logs for billing, abuse prevention, and incident response
  • Use of third-party AI model providers for platform and agent operations as described in our Terms and Privacy Policy

4. Compliance

  • Privacy Act and Australian Privacy Principle aligned controls where applicable
  • GDPR and UK GDPR aligned handling where applicable
  • DPA available for business and enterprise customers
  • Audit logs for administrative actions

5. Incident Response

  • Monitoring for anomalies and abuse
  • Incident response processes appropriate to the size and scale of our operations
  • Notification to affected parties and the OAIC in accordance with the Notifiable Data Breaches (NDB) scheme, where required by law

6. Enterprise Procurement

  • Invoices and tax documentation
  • DPA and security documentation
  • Custom contracts upon request

Platform Terms · Data Processing Agreement · Privacy Policy