← Back to home

Security Centre

Last reviewed: 2 August 2026

SafeSite AI Technology is designed to protect customer information using technical and organisational security measures appropriate to the platform and the risks associated with processing compliance records. Security is considered throughout the design, development and operation of the platform.

Authentication and access

  • Secure user authentication.
  • Row-Level Security (RLS) is used to help enforce tenant isolation within the platform. As of 2 August 2026, Supabase Security Advisor reports zero errors, warnings or suggestions for the production database.
  • Access controls are designed to ensure users can access only data belonging to their own organisation.
  • Authentication is provided through trusted managed infrastructure.

Infrastructure

  • Production infrastructure is hosted using managed cloud services.
  • Data is encrypted in transit using HTTPS/TLS.
  • Secrets and API credentials are stored securely and are not exposed to client-side applications.
  • Security-sensitive platform operations are restricted to authorised server-side processes.

Data protection

  • Customer data is stored within managed cloud infrastructure.
  • Personal data is processed in accordance with our Privacy Policy and Data Processing Agreement.
  • Access to customer information is limited to what is reasonably necessary to operate and support the platform.

Platform security

  • Rate limiting helps protect the platform against abuse and excessive automated requests.
  • Secure payment processing is provided through Stripe.
  • Authentication, database and hosting services are provided through managed cloud infrastructure selected for security, reliability and operational resilience.
  • Dependencies and platform components are regularly reviewed and updated as part of ongoing maintenance.

AI processing

AI is used to assist with document generation, document review and compliance analysis. Customer Content is processed only to provide the requested service. We do not use Customer Content to train AI models for the benefit of other customers. AI processing is subject to the same access controls and contractual protections described in our Privacy Policy and Data Processing Agreement. Customers remain responsible for reviewing AI-generated outputs before operational use.

Third-party providers

SafeSite AI Technology relies on specialist providers for hosting, authentication, database services, AI processing and payment processing. Current providers are listed in our Privacy Policy and Data Processing Agreement.

Continuous improvement

Security controls are reviewed and updated as the platform evolves to address software updates, emerging threats and changing legal and regulatory requirements.

Responsible disclosure

If you believe you have identified a security vulnerability, please email security@safesiteaitechnology.com. Please include sufficient information to help us understand and reproduce the issue where possible.

We ask that vulnerabilities are reported privately and are not publicly disclosed until we have had a reasonable opportunity to investigate and, where appropriate, remediate the issue.