Trust Center
Hosting and data residency
Last reviewed: 2026-07-21
Compliance Care's default and intent is that customer data — including all participant information, evidence documents, policies, audit trails, and notifications content — is stored and processed inside Australia.
This page lists every region where compute runs, data sits at rest, or content is processed, including the named exceptions to AU-only and how each is handled.
Where customer data is stored and processed
| Layer | Provider | Region | What is processed there |
|---|---|---|---|
| Authenticated application (Larenta, Next.js) | AWS App Runner | Sydney (ap-southeast-2) | All requests carrying customer data. |
| Primary database (Postgres, Auth, Storage) | Supabase | Sydney (ap-southeast-2) | Tenant records, participant data, evidence files, audit events, RLS-scoped storage objects. |
| Audit trail | Supabase (append-only audit_events) | Sydney (ap-southeast-2) | Append-only audit events on customer data. |
| Billing | Stripe AU | Australia | Billing contact and metadata, GST invoice records; card details held by Stripe. No participant data. |
| Transactional email | Resend | Tokyo (ap-northeast-1) — named exception, see below | Sign-in links, contact-form notification and acknowledgement, newsletter and digest email. Recipient address, display name, and message content only. Content carries no participant PII. |
| Business email | Microsoft 365 | Australia (tenant region) | Contact-form enquiries delivered to the monitored mailbox. |
| Bot protection on public forms | Cloudflare Turnstile | Global edge | Visitor connection and browser signals only; no form content. |
Planned controls (not yet in force)
These controls are designed and staged but not yet live. Each will appear in the table above (and in the sub-processor list where a new provider is involved) before it processes customer data:
- Audit-log mirror — nightly append-only mirror of
audit_eventsto AWS S3 with Object Lock (compliance mode, Sydney), 7-year retention. - Anti-virus scanning on uploads — malware scanning of every upload before acceptance into Storage.
- Document ingest OCR (AWS Textract, Sydney) — only if a high-volume structured-forms ingest path ships.
- E-signature (DocuSign AU or AdobeSign AU, selection pending) — signature workflows on policy and engagement documents; AU residency confirmed before first send.
Marketing site (no customer data)
The public marketing site at compliancecare.com.au is served from the same Sydney infrastructure, with supplementary hosting and edge caching on Vercel (Sydney syd1). It carries no authenticated customer session. Contact-form submissions are written to the Sydney Supabase project (which remains the record of the enquiry) and delivered to the Microsoft 365 mailbox by Resend — they do not persist on the edge.
Named exception: transactional email (Resend)
Email we send — sign-in and verification links, contact-form notification and acknowledgement, and newsletter or digest email — is delivered by Resend, whose processing region for our sending domain is Tokyo (ap-northeast-1). Resend does not offer an Australian region.
Why this changed: our original vendor was Amazon SES in Sydney. AWS declined production access for that account twice (case 178399382300285), which leaves an SES account able to email only addresses it has itself verified — it cannot send a sign-in link to a new customer. We moved to a vendor that can actually deliver, and disclose the residency consequence here rather than leave the claim inaccurate.
Handling rules in force:
- Only the recipient's email address, display name, and the content of that message leave Australia. No participant records, worker records, evidence documents, or audit events are transmitted through email delivery.
- The record of a contact-form enquiry is written to the Sydney Supabase project first; email delivery is a notification on top of that record, not the system of record.
- The disclosure is made to individuals under APP 8 in our Privacy Policy §7, and the vendor is listed in our sub-processor register.
- If an equivalent provider offering an Australian region becomes available, this arrangement is re-evaluated at the next scheduled review.
Named exception: Anthropic (Claude) API
Inference for AI features runs on Anthropic's Claude API, which is not hosted in Australia.
Handling rules in force:
- The Anthropic Data Processing Agreement is executed and on file as a condition of any production use of the API. Where the DPA is not yet executed, no AI features are enabled and the affected paths return a clear "AI features not yet enabled" state.
- Inputs to the Claude API are limited to the content needed for the requested task (e.g., the document being mapped, the policy clause being drafted). Identifiers are de-identified or omitted where the task does not require them.
- Anthropic's policy is that API inputs and outputs are not used to train models. We rely on the API's published zero-retention or 30-day-retention settings as documented in our AI handling page.
- Every AI call is logged in our append-only audit trail (timestamp, model and version, prompt cache hit, input token count, output token count, cost). Customers can export this log.
- AI features are gated behind explicit user action. There is no background AI processing of customer data.
See AI handling for full detail.
What we do not do
- We do not replicate customer data into non-AU regions for analytics, reporting, or backup convenience.
- We do not use a third-party CDN to cache authenticated responses.
- We do not allow ad-hoc data exports to staff laptops. Operator access to production data is via short-lived, audited sessions only.
Change log
| Date | Change |
|---|---|
| 2026-05-25 | Initial publication. |
| 2026-07-14 | Aligned to the live stack: application hosting is AWS App Runner Sydney (not Fly.io); transactional email is Amazon SES Sydney; Microsoft 365 and Cloudflare Turnstile added; Textract, S3 audit mirror, AV scanning, SMS, and e-signature moved out of the live table (SMS/Twilio dropped; the rest listed as planned controls). |
| 2026-07-21 | Transactional email moved from Amazon SES (Sydney) to Resend (Tokyo ap-northeast-1) after AWS declined SES production access twice, which left that account unable to email any address it had not itself verified. Added as a second named exception to AU residency, with the scope limits (recipient address, display name, message content only — no participant, worker, evidence, or audit data) and the reason stated. Marketing-site paragraph corrected: the Sydney Supabase project remains the record of a contact-form enquiry; email is the notification on top of it. |
