SpringFire

Security

Your data stays in Australia. Your audit trail stays intact.

Every claim on this page describes how the platform is built and run today — and the last section says what we don't claim yet.

Database
Azure Australia East
Documents
AWS Sydney, private buckets
AI processing
Australia only
Encryption
TLS 1.2+ · AES-256 at rest

Access

  • Two-factor sign-in by emailed code, with trusted devices so your team isn't re-verifying every session.
  • Your own access levels — grant or deny each area of the system independently; site-limited permissions for multi-location teams.
  • Lockout after five failed logins, HttpOnly secure session cookies, single-use sign-in links.
  • Your data stays yours — every request is filtered to your business at the database, never shared with another customer.

Evidence

  • Audit log of significant actions — who, when, from where, before and after.
  • Consent records with version, timestamp and withdrawal history.
  • Breach register with the fields the Notifiable Data Breaches scheme asks for.
  • Access, correction and deletion requests handled under the Australian Privacy Principles — email support@springfire.com.au.

Infrastructure

  • Security headers and HTTPS-only with HSTS preload on every response.
  • Signed webhooks — every inbound callback from our payment, messaging and voice providers is signature-verified.
  • Secrets live in secure configuration stores, never in the repository.
  • Backups with point-in-time restore and versioned document storage.

A small number of service providers — email, SMS, payments, maps and the optional AI voice line — operate from the United States. Every one is listed, with the data it receives, in our Privacy Policy.

What we don't claim (yet)

Honesty about where we are

We don't currently hold SOC 2 or ISO 27001 certification. Every claim on this page reflects how the platform is actually built and operated today — not a roadmap. Formal certifications are on our medium-term plan and we're happy to walk your compliance team through our controls in the meantime.

We also don't run an automated DSAR (Data Subject Access Request) pipeline. Access, correction, and deletion requests under APP 12 and 13 are handled manually by our team within the 30-day statutory window. Email support@springfire.com.au and we'll respond.

Found a security issue? Report it privately to support@springfire.com.au — we acknowledge responsible disclosures within one business day.

Walk your IT or compliance lead through it.

30 minutes on a video call, on your questions, on our screen.

We use essential cookies only to keep the site working. Nothing tracks you across sites. Read our Privacy Policy for details.