← Back to home

Security & trust

Built to be trusted with high-stakes forms

Comprehendly is a StepCare product. This page summarises our privacy and security posture for New Zealand and Australian customers — what is ready today, and what is actively underway.

Compliance

NZ/AU privacy readiness, GDPR-ready controls, SOC 2–ready posture with attestation in progress, and an independent penetration test underway.

New Zealand Privacy Act 2020

Ready

Privacy Policy with NZ Schedule, collection notices, breach process, and IPP 3A support for indirect collection. Built for customers operating under the Privacy Act 2020.

Australian Privacy Act / APPs

Ready

Privacy Policy with AU Schedule covering sensitive information, APP 8 overseas disclosure, APP 11 security, and the Notifiable Data Breaches scheme.

GDPR

Ready

GDPR-ready controls: lawful-basis thinking, data minimisation, retention discipline, DPA, and EU database residency in Frankfurt. AI language processing may still occur in the United States, as disclosed in the sub-processor list.

SOC 2

Ready — attestation in progress

SOC 2–ready controls are in place (access control, change management, monitoring, least-privilege production access). Formal attestation is in progress; we will publish the report when issued.

Independent penetration test

Underway

An independent penetration test is underway. Findings will be remediated and a summary made available to enterprise customers under NDA.

Data Processing Agreement

Published

A customer DPA is published at /legal/dpa and accepted with the Terms. Enterprise countersignatures available on request.

Infrastructure & data handling

Where your data lives, and what actually gets kept.

Data residency

Primary databases are hosted on Supabase in Sydney (Australia) and/or Frankfurt (EU). AI language processing (OpenAI) and some hosting/CDN services still process data in the United States — disclosed in the Privacy Policy and sub-processor list.

No audio retention

Voice and phone audio is processed in real time and is not persisted as audio files. Twilio call recording is disabled. Answers are linked to transcript quotes for provenance — a record of what was said, not a recording archive.

Phone channel

Phone-based form completion and demo OTP run through Twilio. For population outreach campaigns, customers remain responsible for consent, identification, and unsubscribe / Do Not Call obligations; product controls for that workflow are described in our Forms roadmap.

Backups

The database is backed up automatically through Supabase, and every deployment runs through version-controlled CI/CD rather than manual server changes.

Access control

How we keep the number of people who can touch customer data small.

  • Multi-factor authentication and passkey support on every account
  • Role-based access control (RBAC) across the platform
  • Audit logging on access to sensitive data
  • Production access restricted to a single superadmin account — fewer standing permissions, not more

Sub-processors

Third parties that process personal information for Comprehendly. Full detail, including regions, is in the published sub-processor list.

ProviderPurpose
SupabaseDatabase, authentication, file storage (Frankfurt / Sydney)
VercelApplication and marketing hosting (global CDN)
OpenAISpeech-to-text and language processing (United States; no training on customer content)
TwilioPhone call delivery and OTP (recording disabled)
StripeSubscription billing and payments
ResendTransactional email
Firebase Cloud MessagingMobile push notifications
CloudflareTurnstile bot protection on public demos
CapgoNative app over-the-air updates
GitHubSource control and CI/CD
SentryError monitoring
CookieYesCookie consent management
Google AnalyticsWebsite analytics

Incident response & reporting

We keep a documented incident response process and an up-to-date register of every sub-processor above, so if something goes wrong anywhere in our stack, there is a clear path to find out, contain it, and tell you.

Found a security issue, or think you have? Report it to hello@stepcare.app — we read every message ourselves.

Team & practices

Production access is tightly restricted. Standing access to customer data is limited to the smallest practical set of accounts, with multi-factor authentication and audit logging on sensitive access.

Questions about how we handle your data?

Talk to us directly — no ticket queue, no account manager relay.