Your renovation data, properly protected
We handle sensitive financial and property data. Here's how we keep it safe.
Where your data lives
Supabase (AWS Sydney, ap-southeast-2) — all project data, financial records, and documents.
Vercel (Sydney region) — application hosting and serverless functions.
Your data never leaves Australia unless you use an AI feature — and even then, we strip personal details first.
How we protect it
- Row-level security (RLS) on every database table — you can only see your own projects
- End-to-end encryption in transit (TLS 1.3)
- Hashed passwords (never stored in plain text)
- Rate limiting on all API endpoints
- Server action input validation with Zod schemas
- Content Security Policy headers
- No analytics cookies, no tracking scripts
AI privacy
When you use AI features (like receipt scanning), we strip your name, email, phone number, tax file number, and bank details before sending anything to the AI.
Your data is processed but never retained for AI training.
Your control
- Export all your data anytime
- Delete your account and all data permanently from Settings
- We don't sell your data. We don't show you ads. We make money from paid plans.
Report a vulnerability
Found a security issue? Email security@domara.com.au