Security & Compliance
Last updated: September 2026 · Tradie Safe Pro
Tradie Safe Pro is built with security and compliance as foundational principles — not an afterthought. This page outlines the safeguards we have in place today to protect your business and customer data, and how we work with larger customers who require formal certification.
Data Encryption
All data is encrypted in transit over TLS and at rest on managed cloud infrastructure. Card data never touches our servers — it is handled entirely by Stripe, a PCI-DSS Level 1 certified processor.
Strict Data Isolation
Every business's records are isolated with row-level security (RLS). A user can only ever read, edit or delete their own company's data — never another customer's. Access rules are enforced server-side, not just in the UI.
Secure Authentication
We use managed authentication with secure session handling and offer email/password plus trusted OAuth providers. Sensitive operations require server-side identity verification.
Audit Logging
Key actions across quotes, invoices, safety documents and team activity are recorded in an immutable activity log for accountability and traceability.
Hardened Payments
All payment webhooks are signature-verified, and public payment flows run through narrow, authenticated backend functions — no open relays. We never store full card numbers or CVVs.
Your Data, Your Control
You can cancel your subscription and keep access until your paid period ends, or permanently delete your account and personal data at any time from Settings → Account. Tax records are retained only where the law requires it.
Input & Access Hardening
All user input is validated and sanitised server-side to prevent XSS, IDOR and phishing abuse. Age verification and AI-consent gates enforce responsible feature access.
Multi-Jurisdiction Privacy
Our privacy practices align with the Australian Privacy Act 1988 (APPs), plus GDPR, CCPA, UK GDPR, PIPEDA (Canada) and the NZ Privacy Act — covered in detail on our Legal page.
Enterprise & Tender Readiness
As we scale into larger construction firms, head contractors and government work, we understand some procurement teams require formal third-party certification such as SOC 2 or ISO 27001. Our architecture and security practices are designed with these standards in mind so that, when the need arises, we can pursue formal certification quickly through a compliance automation partner.
If your organisation requires a SOC 2 / ISO 27001 attestation, a completed security questionnaire, or a data processing agreement as part of onboarding, please reach out — we will work with your team to meet your requirements.
Security enquiries, vulnerability reports and compliance requests: security@tradiesafepro.com
Privacy & data requests: privacy@tradiesafepro.com · Full policies: Legal & Compliance Hub
Registered address: Unit 7, 3 Key Street, Dandenong, Victoria 3175, Australia
© 2026 Tradie Safe Pro — All rights reserved