Your data.
Our responsibility.
CHAIOS is an Australian business. We take our legal obligations seriously and build on infrastructure that meets internationally recognised security standards. This page explains how we protect you and your data.
Built under Australian law
CHAIOS operates from Australia and observes all relevant Australian privacy, consumer and data protection laws.
Privacy Act 1988
CHAIOS complies with the Privacy Act 1988 (Cth). We only collect personal information that is necessary to provide our services, and we handle it in accordance with our published Privacy Policy.
Australian Privacy Principles
We observe all 13 Australian Privacy Principles (APPs), including lawful collection, purpose limitation, data quality, access rights, and cross-border disclosure obligations.
Australian Consumer Law
Our services and any associated paid offerings comply with the Australian Consumer Law (Schedule 2 of the Competition and Consumer Act 2010), including consumer guarantees and fair trading obligations.
Certified infrastructure, end to end
CHAIOS is built on a carefully selected stack of enterprise-grade providers — each independently audited and certified to international security standards.
All payment processing is handled exclusively by Stripe, the world's leading payment platform. Stripe is a PCI DSS Level 1 Service Provider — the highest level of payment security certification. CHAIOS never sees, receives or stores any card data.
PCI DSS compliance
The Payment Card Industry Data Security Standard (PCI DSS) sets the global benchmark for how card data must be handled.
Stripe handles all card data
All payment processing is performed entirely within Stripe's environment. Stripe holds PCI DSS Level 1 certification — the highest tier available — achieved through annual audits by an independent Qualified Security Assessor (QSA). CHAIOS never receives, transmits or stores cardholder data at any point.
In plain language:When you pay for CHAIOS Sentry Pro or make a donation, your card details are entered directly into Stripe's secure payment form and never touch our servers. We never see your card number, expiry or CVV — at any point.
What we do on our end
Beyond our infrastructure certifications, CHAIOS applies its own security principles across every part of the product.
Encryption in transit & at rest
All data is encrypted over TLS in transit. Data at rest is encrypted by our infrastructure providers using AES-256 or equivalent standards.
No card data — ever
CHAIOS never sees, processes or stores payment card numbers. All card data is handled entirely within Stripe's PCI DSS Level 1 certified environment.
Data minimisation
We only collect information that is necessary to deliver our services. We do not sell or share personal data with third parties for marketing purposes.
Row-level security
Our database enforces row-level security so each user can only ever access their own data — even if a query error were to occur at the application layer.
Access controls
Internal access to production systems is restricted, logged and reviewed. Least-privilege principles are applied across all services.
Australian data handling
We take reasonable steps to ensure any cross-border transfers of personal information are handled in accordance with APP 8 and equivalent protections.
Privacy requests & security concerns
To exercise your privacy rights, request access to your data, or report a security vulnerability, please contact us directly. We aim to respond to all privacy requests within 30 days in accordance with the Privacy Act.
This page was last reviewed in May 2026. Certifications listed reflect publicly available information from each provider's security documentation.