Suiviro Legal
Security & Data Protection
Last updated: 6 July 2026
This page is maintained by Suiviro Pty Ltd and describes the security and data-protection controls actually in place today. It is app-owned content, not an independent audit or certification.
1. Hosting and data residency
The Suiviro web application is served from Cloudflare's global edge network. Application data (database, authentication, file storage) is hosted on Supabase, which runs on Amazon Web Services in Sydney, Australia (ap-southeast-2). Customer records, jobs, client contact details and uploaded files stay in the Australian region under normal operation.
Some subprocessors (listed in section 11 of the Privacy Policy) operate globally and may process transient data outside Australia to deliver their service (for example email and SMS routing, OAuth callbacks, payment processing).
2. Encryption
In transit
All traffic between your browser or device and Suiviro is encrypted with HTTPS/TLS. Traffic between Suiviro and its subprocessors (Supabase, Xero, ClickSend, Paddle, Google, Microsoft) also uses TLS.
At rest
Database contents and uploaded files are encrypted at rest using AES-256 by the underlying AWS infrastructure that Supabase runs on. Backups inherit the same encryption.
3. Authentication and access control
- Email and password sign-in with sessions managed by our authentication provider. Passwords are hashed by the provider; Suiviro never sees or stores raw passwords.
- Password strength minimums are enforced at signup and password change. Breach-database screening against Have I Been Pwned is enforced at signup and password change; passwords found in known breaches are rejected.
- Role-based access inside every business (Owner, Admin, Scheduler, Staff, Viewer) enforced by database-level row-level security policies, not just UI checks.
- Business data isolation: users can only read or write data belonging to businesses where they hold an approved membership. This is enforced in the database.
- Suiviro staff access to production systems is restricted to a small number of individuals and requires MFA on the underlying provider accounts (Supabase, Cloudflare, source control).
In-app multi-factor authentication is not currently offered to end users. Google or other social sign-in is not currently exposed in the sign-in UI.
4. Internal notes never reach clients
Suiviro treats internal notes as strictly business-only. Client-visible surfaces (the client portal, SMS and email templates, and synced Google/Outlook calendars shared with clients) never include site notes, staff feedback or client notes. This is enforced in code, not just by convention.
5. Payments and financial data
Subscription payments are processed by Paddle as Merchant of Record. Suiviro does not store card numbers, CVC codes or full bank account details. Xero, Google Calendar and Microsoft 365 (Outlook mail and calendar) integrations use OAuth 2.0. Access and refresh tokens for these integrations are encrypted at rest using AES-256-GCM with an application-managed key before being written to the database, in addition to database-level encryption and row-level security scoping tokens to authorised business members. Only the scopes required for the connected features are requested.
6. Backups and recovery
Our managed database provider performs automated daily backups of the production database. Point-in-time recovery may be enabled on eligible plans. Recovery objectives are governed by the underlying provider plan and are not separately guaranteed by Suiviro. A restore drill of a production backup export has been performed and verified against expected row counts; drill results are held internally.
Backups reduce the risk of data loss but do not eliminate it. Suiviro does not guarantee zero data loss in the event of an incident, and to the extent permitted by law does not accept liability for lost Client Data beyond the limits set out in the Terms of Service. You remain responsible for exporting any records you consider critical to your business.
7. Logging and monitoring
Suiviro records application errors, authentication events, admin actions, integration activity (Xero, calendars, messaging), notification sends and receipts, and inbound webhook events. Logs are retained for troubleshooting, abuse investigation and security review.
8. Secrets management
Third-party API keys, OAuth client secrets and signing keys are stored in the platform secrets store and injected into server-only code at runtime. They are not committed to source control and are not exposed to the browser. Access is limited to Suiviro production maintainers. Keys are rotated when a compromise is suspected, when a maintainer leaves, and on request.
9. Webhooks and public API endpoints
Inbound webhooks from Xero, Paddle, ClickSend and Microsoft Graph are validated by signature or shared secret before any data is written. Requests that fail verification are rejected without side effects.
10. Vulnerability management
Dependencies are updated on a regular cadence and reviewed when security advisories are published. GitHub Dependabot alerts and automatic Dependabot security-update pull requests are enabled on the source repository, and database schema and row-level security policies are checked with an automated scanner on the Lovable platform. No third-party penetration test has been commissioned yet. Suiviro does not currently operate a bug-bounty program; responsible disclosure is welcomed at security@suiviro.com.
11. Incident response
Suiviro maintains an internal incident-response process covering detection, containment, investigation, notification and post-incident review. In the event of an eligible data breach under the Australian Notifiable Data Breaches (NDB) scheme, affected account holders and the Office of the Australian Information Commissioner (OAIC) will be notified as soon as practicable in accordance with Part IIIC of the Privacy Act 1988 (Cth).
To report a suspected incident, email security@suiviro.com.
12. Data retention and deletion
Business data is retained while a Suiviro account is active. On account deletion (see Privacy Policy), business, client, job and communication records are removed from the production database within 30 days. Backups roll off according to the Supabase backup retention schedule. Anonymised or aggregated operational metrics may be retained longer.
13. Compliance posture (honest)
- Australian Privacy Principles (APPs): Suiviro operates under Australian law and structures its handling of personal information to align with the APPs. See our Privacy Policy.
- GDPR: Where a Suiviro customer processes EU personal data through the service, Suiviro acts as a processor. A Data Processing Agreement is available.
- SOC 2 / ISO 27001: Suiviro is not SOC 2 or ISO 27001 certified. Some subprocessors (Cloudflare, AWS, Supabase, Paddle, Google, Microsoft) hold their own certifications; Suiviro inherits infrastructure-level controls but does not claim its own certification.
- Independent penetration test: not currently commissioned.
14. Your responsibilities
- Use a unique, strong password and keep sign-in devices secure.
- Grant staff only the role they need and remove access when they leave.
- Review connected integrations (Xero, Google, Microsoft) periodically.
- Report suspected security issues promptly.
15. Contact
Security matters: security@suiviro.com. Privacy matters: privacy@suiviro.com. General: admin@suiviro.com. Postal notices: Suiviro Pty Ltd (ACN 699 266 987, ABN 30 699 266 987), PO Box 2060, Marmion WA 6020, Australia.
Questions about this document? Email admin@suiviro.com.