Skip to main content

How we handle systems and data.

Check where information is processed, which providers are involved, who can access it and what an agreement covers. This page points to the current documents for our own systems. A custom project’s controls are defined in its scope.

01

Infrastructure

  • Primary databases for CoordHub and RedRock PM: Supabase PostgreSQL on AWS Sydney (ap-southeast-2). Other processing locations are listed in the data residency and sub-processor documents below
  • Application hosting: serverless functions for CoordHub, RedRock PM and this website pinned to Sydney (Vercel syd1), with global CDN and automatic DDoS mitigation for static assets
  • Encryption at rest: AES-256 applied to all stored data (Supabase default, cannot be disabled)
  • Encryption in transit: TLS 1.2 or higher enforced across all connections
02

Access Control

  • Product access is designed around roles, database policies and reviewable permissions; the exact controls differ by system
  • Authentication and credential handling depend on the service in use. Ask for the current control description when evaluating a particular system
  • A new custom build receives its own access model and test plan in the written scope
03

Compliance Frameworks

  • Regulated workflows require the organisation and its qualified advisers to validate requirements and remain accountable for decisions
  • System records can support reviews and evidence, but software alone cannot establish compliance
  • Privacy responsibilities and roles are set out in the agreement for the relevant service or custom project
  • If a data breach is likely to result in serious harm, we will notify the people affected and the OAIC
04

Data Handling

  • We do not sell customer data. Our privacy notice explains collection and use for this website
  • Processing locations and providers differ by system; consult the data residency and sub-processor documents below
  • Export, retention and deletion are governed by the agreement for the relevant service or custom project
05

Development Practices

  • Automated test suites covering unit and integration scenarios across both products
  • Type-checking and automated tests run in continuous integration on pull requests to each product's main branch
  • Automated dependency scanning, in place today and being extended across the platform

Security questions or penetration test requests? hello@redrocksystems.com.au

REDROCK SYSTEMS PTY LTD  ·  ABN 53 696 760 433  ·  ACN 696 760 433  ·  Perth, Western Australia