Trust & Security
How we handle your data, where it lives, and what we're doing to keep it safe.
Last updated: August 2026
Data Residency & Sovereignty
All data processed by NaSy Hub products is stored and processed within Australia. We use Australian-resident infrastructure (AWS Sydney / Azure Australia East regions). No client data leaves the country.
- ·Data stored in AWS ap-southeast-2 (Sydney) or Azure Australia East
- ·TLS 1.3 in transit, AES-256 at rest
- ·No cross-border data transfer for Australian clients
- ·Umami Analytics — privacy-respecting, no cookies required
No Model Training on Client Data
We do not train AI models on client data. Period. Any data you submit to our products — tenders, financial information, business profiles — is used only to deliver the service you requested.
- ·No client data used for model fine-tuning or training
- ·API calls to Gemini / Anthropic are ephemeral — not stored for training
- ·Data retained per product SLA; deleted on account closure
- ·Audit log available on request for enterprise clients
Compliance & Frameworks
NaSy Hub aligns with Australian regulatory frameworks and security best practices. We're building toward formal certifications as the business scales.
- ·Privacy Act 1988 (Cth) — Australian Privacy Principles (APPs) aligned
- ·Essential Eight maturity model — aligned for small business
- ·NSW AI Assessment Framework — alignment in progress
- ·SOC 2 — roadmap for Q1 2027
- ·Commonwealth Digital Marketplace — application in progress
Authentication & Access
We use modern authentication patterns. No passwords stored on our servers. Agent access is scoped and audited.
- ·OAuth 2.0 / magic-link authentication — no password storage
- ·Agent access scoped to specific channels and functions
- ·All access logged and auditable
- ·No shared credentials — every agent has individual identity
Infrastructure Transparency
What we run on, and how we secure it.
- ·Frontend: Vercel Edge Network (global CDN, DDoS protection)
- ·Backend: Supabase (Postgres, Auth, Storage)
- ·AI: Gemini API + Anthropic API — no data retention for training
- ·Analytics: Umami (self-hosted, no cookies, no tracking scripts)
- ·Email: Cloudflare Agentic Inbox (Australia-resident)
- ·Automated security audits via cron agent (daily)
Have a security question?
Contact us at security@nasyhub.com for vulnerability disclosures or security inquiries.
We aim to acknowledge reports within 24 hours.