How we protect data
Encrypted, hosted in Australia, least privilege.
- TLS 1.3 in transit, AES-256 at rest, with keys managed in a hardware-backed key service.
- Production data hosted in Australian cloud regions with availability-zone redundancy.
- Least-privilege access: production access is limited to a named on-call list, requires hardware two-factor, is time-boxed, and every access is logged and reviewed monthly.
- Separate development, staging and production environments. Production data is never copied into development.
- Automated dependency scanning, static analysis in the build pipeline, and infrastructure as code with peer review.
- Annual third-party penetration test, with the summary letter available to enterprise customers under NDA.
- Daily encrypted backups, restore-tested quarterly.
Account security you control
Two-factor on every plan, SSO for enterprise.
Two-factor authentication is available on every plan including the free one, and we recommend an authenticator app over SMS. SAML single sign-on and SCIM provisioning are available on enterprise agreements.
You can see every active session and sign out of any of them from settings. We email you when a new device signs in.
Reporting a vulnerability
security@kwirl.com.au. We will not pursue good-faith research.
Report to security@kwirl.com.au, with a proof of concept if you have one. We acknowledge within one business day and give you a fix timeline within five.
We will not take legal action against research that stays within a test account, does not access another user’s data, does not degrade the service, and gives us reasonable time to fix before disclosure. Do not run automated scanning against production without written authorisation.
Our incident response process
Detect, contain, assess, notify, review.
Every suspected incident is triaged within one hour of detection by the on-call engineer and assigned a severity. A Sev-1 pages the incident commander immediately.
Containment comes before investigation: isolate the affected system, rotate credentials, and stop the bleeding. We preserve logs and evidence before remediating where that is possible.
We complete an assessment of whether personal information was involved within 30 days at the outside, and typically within 72 hours.
- Hour 0–1: triage, severity, incident commander assigned.
- Hour 1–8: contain, rotate credentials, preserve evidence.
- Hour 8–72: assess scope and affected users, prepare notifications.
- By hour 72: notify affected users and regulators where the threshold is met.
- Within 14 days: blameless post-incident review published to affected customers.
Breach notification
Seventy-two hours to you. Regulators as the law requires.
Where an eligible data breach is likely to result in serious harm, we notify the Office of the Australian Information Commissioner and affected individuals as soon as practicable, under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth).
For New Zealand users we notify the Office of the Privacy Commissioner and affected individuals under section 114 of the Privacy Act 2020, as soon as practicable after becoming aware of a notifiable privacy breach.
For United States users we notify under the applicable state breach-notification statute, within the deadline that state sets.
Our own commitment, regardless of threshold: we tell affected users within 72 hours of confirming an incident, in plain language, with what happened, what was exposed, what we have done, and what you should do.
Vendors and business continuity
Reviewed before we use them, and we can run without any one of them.
Every processor is security-reviewed before onboarding and re-reviewed annually. Contracts require breach notification to us within 24 hours.
Our recovery objectives are a four-hour recovery time and a one-hour recovery point for production data. Continuity plans are exercised twice a year.
Questions about this policy
Write to legal@kwirl.com.au for anything on this page, privacy@kwirl.com.au for a privacy request, or security@kwirl.com.au to report a vulnerability. Postal mail reaches us at Kwirl Australia Pty Ltd, Australia.