Trust & Security
Last updated: 13 June 2026
My PocketHR is built for Australian small businesses handling sensitive workplace information. This page summarises how we protect your data. For the legal detail, see our Privacy Policy and Data Processing Addendum.
Hosting & data residency
Our primary application database and storage are hosted in Australia (Supabase, ap-southeast-2). Edge traffic is served via Cloudflare's global network with origin in Australia. See our sub-processors for the full list.
Encryption
- In transit: all traffic is encrypted with TLS 1.2+ and HSTS.
- At rest: database, file storage and backups are encrypted at rest with industry-standard ciphers.
- Secrets: API keys and tokens are stored in a managed secret store, never in source code.
Access control
- Row-Level Security policies enforce that customers can only access their own data.
- Administrative access is restricted to a small allowlist and logged.
- Service-role credentials never leave the server runtime and are never exposed to the browser.
AI safeguards
- We use enterprise AI gateways (xAI Grok, Google Gemini) under contracts that prohibit using customer inputs or outputs to train their models.
- We do not train our own models on customer content.
- Every AI response includes a visible disclaimer that it is general guidance only — not formal legal advice.
- Risk-flagged matters are routed to human escalation paths.
Payments
All card payments are processed by Stripe. My PocketHR never stores full card numbers — Stripe holds the cardholder data within its PCI-DSS Level 1 environment.
Backups & resilience
Daily encrypted backups are retained on a rolling schedule with point-in-time recovery available on the database. Critical workloads run on auto-scaling infrastructure with multi-region failover at the edge.
Vulnerability management
We run automated dependency and security scans on every code change, and address high-severity findings on a priority basis. To report a vulnerability, email security@mypockethr.com.au. Please give us a reasonable opportunity to respond before any public disclosure.
Incident response
If we become aware of a security incident likely to result in serious harm, we will notify affected customers and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
Contact
Security questions or reports: security@mypockethr.com.au.