🔒 Security First

How We Protect
Your Data

Scan365.ai is built with security at its core. Your scan data, user profiles and reports are protected by enterprise-grade controls hosted in Australia.

Data Sovereignty

🇦🇺

Your Data Stays in Australia

All Scan365.ai data is stored in a Supabase PostgreSQL database hosted in the Oceania (Sydney) region (ap-southeast-2). Your scan results, user profiles, and reports never leave Australian soil. This supports compliance with the Australian Privacy Act 1988 and data sovereignty requirements for government and regulated industries.

Authentication and Access Control

🔐

Multi-Factor Authentication (MFA)

All Scan365.ai accounts support MFA. Password changes require MFA verification. Admin accounts require MFA to be enabled before any privileged operations such as password resets are permitted.

🔑

Secure Password Policies

Passwords must be a minimum of 8 characters. Passwords are stored as hashed values and never in plain text. Forgot password flows use time-limited 6-digit reset codes that expire after 15 minutes.

📝

Audit Logging

All significant actions including logins, profile changes, password resets, plan upgrades and admin operations are recorded in a tamper-evident audit log with timestamps and IP addresses.

👤

Role-Based Access Control

Users can only access their own scan data and profile. Admin functions are restricted to authorised IT Service Link administrators. The marketing database and user management are accessible only to verified admins.

Infrastructure Security

☁️

Supabase PostgreSQL

Data is stored in Supabase PostgreSQL with encryption at rest and in transit. Supabase is SOC 2 Type II certified and implements industry-standard security controls including network isolation, automated backups and point-in-time recovery.

🔒

HTTPS and TLS Encryption

All communications between your browser and Scan365.ai are encrypted using TLS 1.3. HTTP connections are automatically redirected to HTTPS. SSL certificates are managed automatically via GitHub Pages.

💳

Payment Security via Stripe

Scan365.ai does not store payment card numbers. All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment provider. Card data is tokenised and never passes through Scan365.ai servers.

🌐

Static Frontend Hosting

The Scan365.ai frontend is hosted on GitHub Pages with no server-side code execution, eliminating entire classes of server-side vulnerabilities. API calls are made directly to Supabase using row-level security policies.

Responsible Disclosure

🛡️ Report a Vulnerability

If you discover a security vulnerability in Scan365.ai, please report it responsibly to admin@itsl.com.au with the subject line "Security Vulnerability Report". We commit to acknowledging your report within 48 hours and providing a resolution timeline within 3 to 5 business days. We will not take legal action against researchers who follow responsible disclosure guidelines.

Questions About Our Security?

Our team at IT Service Link is happy to answer any security or compliance questions.

📧 Contact Our Security Team