Security & Trust Centre

Last updated: 27 July 2026 · Maintained by the KomplyDox team.

KomplyDox stores sensitive workforce records — inductions, licences, incidents, invoices, bank and tax details. This page describes the controls we have in place today to protect that information. It is maintained by KomplyDox as a plain-English description of how the platform works, not an independent certification.

Encryption in transit and at rest

All traffic to KomplyDox is served over HTTPS (TLS 1.2+). Data at rest — including your database, uploaded documents and backups — is encrypted on the underlying managed infrastructure.

Tenant isolation

Every record belongs to a company. Row-Level Security on the database enforces that a signed-in user can only ever read or write data scoped to the company they belong to and the role they hold.

Role-based access & capabilities

Owners, admins, managers and staff each get a distinct capability set. Sensitive actions such as approving invoices, viewing bank details, assigning vehicles or managing members are gated to the roles you configure.

Sensitive fields ring-fenced

Bank account numbers, BSB, TFN and superannuation details are not readable from the profile record directly — even by company admins. They are only surfaced through secure, purpose-built endpoints (e.g. the user's own bank card, the owner-only payroll export).

Multi-tenant database, per-company data

KomplyDox runs on managed Postgres with Row-Level Security enabled on every tenant table. Policies are scoped to the signed-in user's company and depot access.

Managed hosting

The application runs on Cloudflare's edge network and the backend on managed Supabase (Postgres, Auth, Storage), both of which operate SOC 2-audited infrastructure. KomplyDox does not run its own physical servers.

Backups & recovery

The database is backed up daily by the managed provider with point-in-time recovery available. Uploaded files are stored in replicated object storage.

Audit trail

Sensitive operations — invoice approvals, vehicle assignments, complaint status changes, agreement signatures, membership changes — are recorded with a timestamp and the user who performed them.

Authentication

Sign-in uses managed Supabase Auth with email/password and Google sign-in. Passwords are hashed and never stored in plain text. Session tokens are short-lived and rotated automatically.

Shared responsibility

Security is a partnership. KomplyDox is responsible for the platform, its infrastructure, and the controls listed above. Each customer company is responsible for how they use it inside their business.

What KomplyDox does

  • Enforces tenant isolation at the database level.
  • Encrypts data in transit and at rest.
  • Ships regular security updates to the platform.
  • Monitors the platform for suspicious activity.
  • Runs automated security checks on every release.

What you should do

  • Only invite people who should have access.
  • Give each member the lowest role that lets them do their job.
  • Remove or suspend members as soon as they leave.
  • Use a strong, unique password for your KomplyDox account.
  • Report anything suspicious to us straight away.

Data handling

What we collect

Details you enter into the platform: profile information, licences, inductions and training records, vehicle and inspection data, incidents, complaints, toolbox talks, invoices, and any files you upload. See our Privacy Policy for the full list.

Where it lives

Primary data is stored in Australia-region managed Postgres. Uploaded files are stored in the same region. Emails and push notifications are dispatched through Resend and standard web push infrastructure.

Retention & deletion

Compliance records (inductions, licences, signed agreements, incidents) are retained for the life of your account so you can evidence past compliance. You can request export or deletion of your company's data by emailing us.

Sub-processors

We use a small set of trusted providers to run KomplyDox: Supabase (database, auth, storage), Cloudflare (hosting/CDN), Resend (transactional email), Stripe (subscription billing) and the Australian Business Register (ABN/GST verification).

Report a security issue

If you believe you've found a vulnerability in KomplyDox, please email us at support@komplydox.com.au with a description and steps to reproduce. Please give us a reasonable window to investigate and fix before public disclosure. We do not take legal action against good-faith security researchers.

This page describes the security controls currently in place on the KomplyDox platform and is intended as a plain-English summary for customers. It is not an independent audit or certification. For contractual security terms, please contact us for a copy of our Data Processing Agreement.