Skip to main content
Security & Trust

Member data deserves serious treatment.

Volunteer-run committees still hold sensitive information about kids, parents and members. Here's how we keep it safe — in plain English.

How we protect your data

Six pillars, every one of them measurable rather than aspirational.

Organisation isolation

Every club, region and federation is a separate organisation. Postgres row-level security enforces the boundary on every query.

Encryption

TLS 1.2+ in transit, AES-256 at rest. Backups are encrypted and stored in the same region as your primary data.

Least-privilege access

Production access is restricted to a small named team and gated behind SSO + hardware MFA. Every access event is logged.

Audit log

Admin actions, role changes and configuration tweaks are recorded per organisation and exportable as CSV.

Backups & recovery

Daily encrypted backups retained for 30 days, with point-in-time recovery on Pro and Enterprise plans.

Australian-hosted

Primary infrastructure runs in Australia, aligned with the Privacy Act and the Australian Privacy Principles.

Compliance posture

Where we are, what's in flight, and what we won't claim until it's audited.

SOC2-aligned controls

Our internal controls are mapped to the SOC2 Trust Services Criteria. A formal Type 1 audit is on the roadmap.

GDPR-aligned data handling

Data minimisation, lawful basis tracking, and deletion-on-request are built into our admin tooling.

Australian Privacy Act

Default hosting in Australia, with notifiable-breach handling and APP-aligned data practices.

Sub-processors

The vendors that touch your data. The full list lives in our sub-processors register.

VendorPurpose
SupabasePostgres database, auth, storage
VercelWeb hosting and edge runtime
CloudflareDNS, WAF and edge caching
Cloudflare R2Object storage for media uploads
StripeSubscription billing and payments
ResendTransactional and broadcast email
InngestBackground jobs and scheduled tasks
SentryError monitoring
AxiomApplication logging and analytics
Better StackUptime and incident alerting

Found a vulnerability?

We take security reports seriously. Email security@clubhelix.au with details and we'll respond within one business day.