Skip to content
Trust & Security

Your data.
Our responsibility.

CHAIOS is an Australian business. We take our legal obligations seriously and build on infrastructure that meets internationally recognised security standards. This page explains how we protect you and your data.

Australian compliance

Built under Australian law

CHAIOS operates from Australia and observes all relevant Australian privacy, consumer and data protection laws.

Privacy Act 1988

CHAIOS complies with the Privacy Act 1988 (Cth). We only collect personal information that is necessary to provide our services, and we handle it in accordance with our published Privacy Policy.

Australian Privacy Principles

We observe all 13 Australian Privacy Principles (APPs), including lawful collection, purpose limitation, data quality, access rights, and cross-border disclosure obligations.

Australian Consumer Law

Our services and any associated paid offerings comply with the Australian Consumer Law (Schedule 2 of the Competition and Consumer Act 2010), including consumer guarantees and fair trading obligations.

Infrastructure security

Certified infrastructure, end to end

CHAIOS is built on a carefully selected stack of enterprise-grade providers — each independently audited and certified to international security standards.

Supabase

Database, Authentication & Storage

SOC 2 Type IIGDPR Compliant

Supabase powers our database, user authentication and file storage. All data is encrypted at rest and in transit. Row-level security policies ensure users can only access their own data.

Vercel

Web Application Hosting

SOC 2 Type IIISO 27001GDPR Compliant

Vercel hosts the CHAIOS web application. Their infrastructure is built on enterprise-grade cloud providers with automatic TLS, DDoS protection and global edge deployment.

Hostinger

Website Hosting & DNS

ISO 27001GDPR Compliant

Hostinger hosts the CHAIOS marketing website and manages DNS. Their data centres are ISO 27001 certified and operate with 24/7 monitoring and physical security controls.

Stripe

Payment Processing

PCI DSS Level 1SOC 2 Type IIISO 27001

All payment processing is handled exclusively by Stripe, the world's leading payment platform. Stripe is a PCI DSS Level 1 Service Provider — the highest level of payment security certification. CHAIOS never sees, receives or stores any card data.

Resend

Transactional Email

SOC 2 Type IIGDPR Compliant

Resend delivers transactional emails such as account verification and notifications. Email content is transmitted over encrypted connections and access is restricted to authorised services only.

Payment card security

PCI DSS compliance

The Payment Card Industry Data Security Standard (PCI DSS) sets the global benchmark for how card data must be handled.

PCI DSS Level 1 — Service Provider

Stripe handles all card data

All payment processing is performed entirely within Stripe's environment. Stripe holds PCI DSS Level 1 certification — the highest tier available — achieved through annual audits by an independent Qualified Security Assessor (QSA). CHAIOS never receives, transmits or stores cardholder data at any point.

In plain language:When you pay for CHAIOS Sentry Pro or make a donation, your card details are entered directly into Stripe's secure payment form and never touch our servers. We never see your card number, expiry or CVV — at any point.

Our security practices

What we do on our end

Beyond our infrastructure certifications, CHAIOS applies its own security principles across every part of the product.

Encryption in transit & at rest

All data is encrypted over TLS in transit. Data at rest is encrypted by our infrastructure providers using AES-256 or equivalent standards.

No card data — ever

CHAIOS never sees, processes or stores payment card numbers. All card data is handled entirely within Stripe's PCI DSS Level 1 certified environment.

Data minimisation

We only collect information that is necessary to deliver our services. We do not sell or share personal data with third parties for marketing purposes.

Row-level security

Our database enforces row-level security so each user can only ever access their own data — even if a query error were to occur at the application layer.

Access controls

Internal access to production systems is restricted, logged and reviewed. Least-privilege principles are applied across all services.

Australian data handling

We take reasonable steps to ensure any cross-border transfers of personal information are handled in accordance with APP 8 and equivalent protections.

Get in touch

Privacy requests & security concerns

To exercise your privacy rights, request access to your data, or report a security vulnerability, please contact us directly. We aim to respond to all privacy requests within 30 days in accordance with the Privacy Act.

This page was last reviewed in May 2026. Certifications listed reflect publicly available information from each provider's security documentation.