Security

Your data is our priority.

Bank-grade security for your business data. Built with enterprise-grade protections from day one.

Security Features

How we protect your data

Encryption at Rest & In Transit

All data is encrypted using AES-256. TLS 1.3 protects data in transit between your device and our servers.

SOC 2 Type II Certified

Our infrastructure provider maintains SOC 2 Type II certification, ensuring rigorous security controls.

Two-Factor Authentication

Add an extra layer of security with TOTP-based 2FA. Required for all admin accounts.

Role-Based Access Control

Granular permissions ensure team members only access what they need. Full audit trails.

Automated Backups

Real-time replication and daily encrypted backups. Point-in-time recovery available.

Australian Data Residency

Your data stays in Australia. Hosted in AWS Sydney region with local compliance.

Compliance & Certifications

Meeting industry standards

Australian Privacy PrinciplesCompliant
Notifiable Data Breaches SchemeCompliant
PCI DSS (via Stripe)Compliant
ISO 27001In Progress
SOC 2 Type IICertified

Our Security Practices

How we maintain security

Regular third-party penetration testing
Automated vulnerability scanning
Employee security training
Strict access controls
Incident response plan
Bug bounty program
Security-focused code reviews
Dependency monitoring

Data Handling

Data Storage

All data is stored in AWS Sydney region (ap-southeast-2). We use multiple availability zones for redundancy.

Data Retention

Active account data is retained indefinitely. Canceled accounts are deleted after 30 days. Backups are retained for 90 days.

Data Access

Only authorized employees can access customer data, and only for support purposes. All access is logged and audited.

Data Breach Response

We have a comprehensive incident response plan. In the unlikely event of a breach, we will notify affected users within 72 hours as required by Australian law.

Report a Security Issue

Found a vulnerability? We take security seriously and appreciate responsible disclosure. We offer rewards for valid security reports.

Contact Security Team

support@conkr.com.au