Australian-owned. Australian-hosted. Enterprise-grade protection for your project data.
TLS 1.3 in transit, AES-256 at rest. Protected at every layer.
All data stored in Australian AWS data centres. Fully compliant with local data protection laws.
2FA via SMS or authenticator app for an extra layer of account protection.
Role-based access so users only see what they need to.
Full audit trail — who accessed what, when, and from where.
Quarterly penetration testing and assessments by independent third parties.
Information security management certification
Security and availability controls
Compliant with APP under Privacy Act 1988
All data stored in AWS Sydney region, ensuring:
Our incident response plan ensures rapid detection, containment, and resolution.
24/7 monitoring with immediate alerts
Affected systems isolated within 1 hour
Users notified within 72 hours
Fix, strengthen defences, post-mortem
Found a vulnerability? Report it responsibly and we commit to:
Email security@buildpaperless.com.au with details. We respond within 24 hours.
We assess and reproduce the issue within 48 hours.
Critical issues patched within 7 days, others based on severity.
Coordinated disclosure after fix. Recognition for responsible reporting.