Security Policy
- Version
- 1.0
- Effective
- 9 August 2026
- Last updated
- 9 August 2026
We take the security of the BuildSource platform and your data seriously. This page describes the measures we use and how to report a security concern. It is provided for transparency and does not form part of a contractual security guarantee.
1. Data protection
- All traffic to the Platform is encrypted in transit using HTTPS/TLS.
- Access to personal and business data is protected by authentication and row-level security policies enforced at the database, so users can only access data they are authorised to see.
- Passwords are hashed and salted by our authentication provider; we never store plaintext passwords.
2. Payments
Payments are processed by Stripe, a PCI-DSS Level 1 certified provider. Card details are handled by Stripe and are not stored on our servers. Payment events are verified using signed webhooks.
3. Application security
- Authentication and authorisation checks are enforced on the server for protected actions.
- Database queries are parameterised to protect against SQL injection.
- We apply security response headers and follow the principle of least privilege for access to systems.
4. Operational security
We restrict administrative access, keep dependencies up to date, and monitor for suspicious activity. In the event of a data breach that is likely to result in serious harm, we will comply with our obligations under the Notifiable Data Breaches scheme in the Privacy Act 1988 (Cth).
5. Reporting a vulnerability
If you believe you have found a security vulnerability, please email [INSERT security@yourdomain.com.au] with details and steps to reproduce. Please give us a reasonable opportunity to investigate and remediate before any public disclosure. We will not pursue action against researchers who act in good faith, avoid privacy violations and service disruption, and do not access or modify data beyond what is necessary to demonstrate the issue.