Security & Trust Centre
Last updated: 27 July 2026 · Maintained by the KomplyDox team.
KomplyDox stores sensitive workforce records — inductions, licences, incidents, invoices, bank and tax details. This page describes the controls we have in place today to protect that information. It is maintained by KomplyDox as a plain-English description of how the platform works, not an independent certification.
Encryption in transit and at rest
Tenant isolation
Role-based access & capabilities
Sensitive fields ring-fenced
Multi-tenant database, per-company data
Managed hosting
Backups & recovery
Audit trail
Authentication
Shared responsibility
Security is a partnership. KomplyDox is responsible for the platform, its infrastructure, and the controls listed above. Each customer company is responsible for how they use it inside their business.
What KomplyDox does
- Enforces tenant isolation at the database level.
- Encrypts data in transit and at rest.
- Ships regular security updates to the platform.
- Monitors the platform for suspicious activity.
- Runs automated security checks on every release.
What you should do
- Only invite people who should have access.
- Give each member the lowest role that lets them do their job.
- Remove or suspend members as soon as they leave.
- Use a strong, unique password for your KomplyDox account.
- Report anything suspicious to us straight away.
Data handling
What we collect
Details you enter into the platform: profile information, licences, inductions and training records, vehicle and inspection data, incidents, complaints, toolbox talks, invoices, and any files you upload. See our Privacy Policy for the full list.
Where it lives
Primary data is stored in Australia-region managed Postgres. Uploaded files are stored in the same region. Emails and push notifications are dispatched through Resend and standard web push infrastructure.
Retention & deletion
Compliance records (inductions, licences, signed agreements, incidents) are retained for the life of your account so you can evidence past compliance. You can request export or deletion of your company's data by emailing us.
Sub-processors
We use a small set of trusted providers to run KomplyDox: Supabase (database, auth, storage), Cloudflare (hosting/CDN), Resend (transactional email), Stripe (subscription billing) and the Australian Business Register (ABN/GST verification).
Report a security issue
If you believe you've found a vulnerability in KomplyDox, please email us at support@komplydox.com.au with a description and steps to reproduce. Please give us a reasonable window to investigate and fix before public disclosure. We do not take legal action against good-faith security researchers.
This page describes the security controls currently in place on the KomplyDox platform and is intended as a plain-English summary for customers. It is not an independent audit or certification. For contractual security terms, please contact us for a copy of our Data Processing Agreement.