Product
Overview
The commercial operating system for construction. Capture a commercial event once, every downstream workflow stays connected.
See the whole product →
Contract models
Fixed, cost plus & open book
Claim a fixed sum, reimburse at actual cost, or bill fully open book. ClaimStack handles each, the right way.
See how →
Solutions
Overview
Built for every side of the contract. One commercial record the whole project team can trust, head contract to supplier.
See how it fits your role →
For subcontractors
Free to collaborate
Invited to a project? Submit claims and variations in a format that holds up, free forever.
See the plan →
Resources
Overview
Practical guides on claims, variations and contracts, plus how ClaimStack connects, who's behind it, and how we keep your commercial data safe.
Read the blog →
Get started
See it on your project
A 30-minute walkthrough on your numbers, where the margin usually leaks.
Book a demo →
Pricing
Enterprise-Grade Security

Data Security

We treat your project data like the foundation of a building: it must be unshakeable, localised, and private.

Last Updated: 4 August 2026

1. Australian Data Residency

Your files, database records, and backups are stored at rest in Australia, in Google Cloud's Melbourne region. Your legal and financial records stay on Australian infrastructure.

  • File storage, database, and backups in Melbourne, Australia (australia-southeast2)
  • Continuous encrypted backups with point-in-time recovery, in the same region
  • Separate production, staging, and development environments
  • DDoS protection across all endpoints

Two honest caveats. AI inference is the exception to in-Australia processing: most AI features route to Google's global endpoint, so that processing may happen outside Australia, while contract intelligence and embeddings are pinned to Australian regions. And because Google is a United States company, storing data in Australia does not put it beyond the reach of US law. No provider built on a US hyperscaler can honestly claim otherwise, and we would rather tell you that than imply a guarantee we cannot give. Full detail is in our Privacy Policy.

2. Bank-Grade Encryption

Every piece of data is encrypted, both when it's moving between your device and our servers, and when it's stored.

  • In Transit: All connections use TLS encryption (HTTPS only), the same standard used by banks and financial institutions
  • At Rest: All database records and files are encrypted using AES-256 server-side encryption
  • Backups: Continuous replication with point-in-time recovery, encrypted and stored across Australian data centres

3. Data Isolation

We don't just hide data behind a user interface, we lock it at the database level.

  • Row-Level Security (RLS): Database-enforced policies ensure Company A can never physically access Company B's data, regardless of what happens at the application level
  • Contract-Based Access: Users only see data for contracts their company is a party to, builder, subcontractor, consultant, or client
  • Role-Based Permissions: Company owners, admins, and users each have distinct access levels, with per-project team assignments
  • Two-Factor Authentication: Optional 2FA for enhanced account security
  • Brute Force Protection: Account lockout, rate limiting, and bot detection on all login endpoints

4. AI Safety & Privacy

ClaimStack uses AI to help with tasks like extracting invoice data, transcribing site notes, and scanning receipts. Here's how we keep your data safe:

  • Your data is never used to train AI models. Google's Service Specific Terms prohibit using our data to train or fine-tune any model without our instruction, which we do not give. We do not fine-tune models on customer content
  • Australian-region processing is used for contract intelligence and embeddings. Other AI features use Google's global endpoint and may be processed outside Australia
  • Limited retention, disclosed: we do not enable request logging or grounding. Google may hold inputs in memory for up to 24 hours for latency, and may retain a prompt for up to 90 days if its safety classifiers flag it for abuse investigation. Neither is used for training
  • Minimal exposure: Only the specific document, image, or audio needed is sent, never bulk project data
  • Human review: All AI-generated results are shown for your review and approval before anything is saved or actioned

5. Application Security

Our platform is built following OWASP security guidelines, with protections against injection attacks, cross-site scripting, request forgery, and other common web vulnerabilities. All API inputs are validated, all sessions are secured with short-lived tokens, and all state-changing operations require cryptographic verification.

6. Monitoring & Incident Response

We continuously monitor the platform for suspicious activity with real-time alerts and comprehensive access logging. In the event of a security incident, we have documented procedures for containment, investigation, and remediation. Where we conclude a breach is likely to result in serious harm, we notify affected individuals and the Office of the Australian Information Commissioner as soon as practicable, under Australia's Notifiable Data Breaches scheme.

7. Compliance

Privacy Act 1988

Built to comply with the Australian Privacy Principles and the Notifiable Data Breaches scheme

ASD Essential Eight

Aligned to the Australian Signals Directorate's security controls

Construction Industry

Immutable audit trails, document retention, and multi-party data isolation

SOC 2 Type II

Not yet certified — independent audit planned

8. Third-Party Providers

We carefully vet all service providers. Each is bound by data processing agreements and subject to ongoing security review. Our trusted partners include providers for:

  • Cloud infrastructure and file storage (Australian region)
  • Database hosting (Australian region)
  • AI processing for document extraction and voice transcription
  • Payment processing (Stripe)
  • Email delivery (Postmark)
  • Accounting integration (Xero)
  • Error monitoring and bot protection

9. Your Part

  • Use strong, unique passwords (consider a password manager)
  • Enable two-factor authentication (2FA)
  • Never share your login credentials
  • Log out on shared devices and report suspicious activity immediately

10. Security Questions or Concerns

Found a vulnerability? Have a security question? Get in touch:

ClaimStack Pty Ltd, Security Team

Security: security@claimstack.com.au

Support: support@claimstack.com.au

Website: www.claimstack.com.au

If you discover a vulnerability, please email us before disclosing publicly. We typically respond within 24 hours.

This policy is reviewed regularly and updated as necessary. Material changes will be communicated to all users.