We treat your project data like the foundation of a building: it must be unshakeable, localised, and private.
Your files, database records, and backups are stored at rest in Australia, in Google Cloud's Melbourne region. Your legal and financial records stay on Australian infrastructure.
Two honest caveats. AI inference is the exception to in-Australia processing: most AI features route to Google's global endpoint, so that processing may happen outside Australia, while contract intelligence and embeddings are pinned to Australian regions. And because Google is a United States company, storing data in Australia does not put it beyond the reach of US law. No provider built on a US hyperscaler can honestly claim otherwise, and we would rather tell you that than imply a guarantee we cannot give. Full detail is in our Privacy Policy.
Every piece of data is encrypted, both when it's moving between your device and our servers, and when it's stored.
We don't just hide data behind a user interface, we lock it at the database level.
ClaimStack uses AI to help with tasks like extracting invoice data, transcribing site notes, and scanning receipts. Here's how we keep your data safe:
Our platform is built following OWASP security guidelines, with protections against injection attacks, cross-site scripting, request forgery, and other common web vulnerabilities. All API inputs are validated, all sessions are secured with short-lived tokens, and all state-changing operations require cryptographic verification.
We continuously monitor the platform for suspicious activity with real-time alerts and comprehensive access logging. In the event of a security incident, we have documented procedures for containment, investigation, and remediation. Where we conclude a breach is likely to result in serious harm, we notify affected individuals and the Office of the Australian Information Commissioner as soon as practicable, under Australia's Notifiable Data Breaches scheme.
Built to comply with the Australian Privacy Principles and the Notifiable Data Breaches scheme
Aligned to the Australian Signals Directorate's security controls
Immutable audit trails, document retention, and multi-party data isolation
Not yet certified — independent audit planned
We carefully vet all service providers. Each is bound by data processing agreements and subject to ongoing security review. Our trusted partners include providers for:
Found a vulnerability? Have a security question? Get in touch:
ClaimStack Pty Ltd, Security Team
Security: security@claimstack.com.au
Support: support@claimstack.com.au
Website: www.claimstack.com.au
If you discover a vulnerability, please email us before disclosing publicly. We typically respond within 24 hours.
This policy is reviewed regularly and updated as necessary. Material changes will be communicated to all users.