Skip to main content
Security & Trust

Member data deserves serious treatment.

Volunteer-run committees still hold sensitive information about kids, parents and members. Here's how we keep it safe — in plain English.

How we protect your data

Six pillars, every one of them measurable rather than aspirational.

Organisation isolation

Every club, region and federation is a separate organisation. Postgres row-level security enforces the boundary on every query.

Encryption

TLS 1.2+ in transit, AES-256 at rest. Backups are encrypted and stored in the same region as your primary data.

Least-privilege access

Production access is restricted to a small named team and gated behind SSO + hardware MFA. Every access event is logged.

Audit log

Admin actions, role changes and configuration tweaks are recorded per organisation and exportable as CSV.

Backups & recovery

Daily encrypted backups retained for 30 days, with point-in-time recovery on Pro and Enterprise plans.

Australian-hosted

Primary infrastructure runs in Australia, aligned with the Privacy Act and the Australian Privacy Principles.

Compliance posture

Where we are, what's in flight, and what we won't claim until it's audited.

SOC2-aligned controls

Our internal controls are mapped to the SOC2 Trust Services Criteria. A formal Type 1 audit is on the roadmap.

GDPR-aligned data handling

Data minimisation, lawful basis tracking, and deletion-on-request are built into our admin tooling.

Australian Privacy Act

Default hosting in Australia, with notifiable-breach handling and APP-aligned data practices.

Sub-processors

The vendors that touch your data. The full list lives in our sub-processors register.

VendorPurpose
SupabasePostgres database, auth, storage
VercelWeb hosting and edge runtime
CloudflareDNS, WAF and edge caching
Cloudflare R2Object storage for media uploads
StripeSubscription billing and payments
ResendTransactional and broadcast email
InngestBackground jobs and scheduled tasks
SentryError monitoring
AxiomApplication logging and analytics
Better StackUptime and incident alerting

When something goes wrong

Reliability is a trust promise too. Bugs happen in every product — what matters is whether they get noticed, reported and fixed, or quietly ignored.

Monitored, not assumed

Every page reports crashes automatically — and also the failures that never throw an error, like a button that does nothing when clicked or a request that fails behind the scenes.

One-click bug reports

Every signed-in user can report a bug in one click — throughout the admin, from their account page, and on any error screen. The report carries the page and recent errors, and from an error screen it files onto the same tracked issue as the crash itself — so it reaches the engineer with the evidence attached.

Privacy-safe diagnostics

Screen recordings are captured only when an error occurs, and text, inputs and media are masked by default — member rosters, waivers and payment fields never appear in recordings.

Watched around the clock

Synthetic checks exercise the platform continuously, background jobs report their failures like any other error, and the live service status is public on our status page.

Want to see the product before trusting it with a season? The live demo is open to anyone — no sales call, no sign-up wall. Current platform health is always visible on the service status page.

Found a vulnerability?

We take security reports seriously. Email security@clubhelix.com with details and the team will review your report.

Security & Trust — Australian-Hosted Club Software — ClubHelix