1. Platform security controls
We apply technical and organisational measures designed to protect account and session data:
- Encryption in transit: All traffic between your browser or device and our platform is encrypted with TLS. API calls and dashboard sessions use HTTPS only.
- Row-level security (RLS): Our database enforces access controls at the row level. A driver cannot query another driver’s sessions; a site manager cannot modify chargers outside their assigned sites unless explicitly authorised.
- Role-based access: We use a multi-role model (driver, site manager, business owner, head administrator). Permissions are enforced in the application and at the database layer.
- Audit logging: Key onboarding and configuration actions are logged with a timestamp and the identity of the user who performed them.
- Least-privilege access: Internal service accounts and automated processes are granted only the permissions required for their function.
- Leaked password protection: During signup and password changes, we check passwords against the Have I Been Pwned database to flag compromised credentials.
- Payment data: We do not store raw card numbers. Payment information is collected and tokenised by our payment processor (Stripe) under PCI DSS standards.
2. Hosting and subprocessors
The platform is hosted on Supabase (database, authentication, realtime APIs, edge functions) and deployed via a cloud edge network. Our payment processor is Stripe. We use transactional email and analytics services that process data on our behalf. A current list of material subprocessors is available on request by emailing info@tetheredaustralia.com.au.
3. Incident handling
If we become aware of a security incident that is likely to result in serious harm to affected individuals, we will:
- Assess and contain the incident promptly.
- Notify affected users as required under the Australian Notifiable Data Breaches scheme.
- Notify the Office of the Australian Information Commissioner (OAIC) where required.
- Publish a summary of the incident and remedial steps taken if the impact is material to the platform.
To report a security concern, email info@tetheredaustralia.com.au. We aim to acknowledge receipt within one business day and provide an initial assessment within five business days.
4. Your responsibilities
Security is a shared effort. We ask that you:
- Keep your account credentials confidential and do not share login access with others.
- Use a strong, unique password and enable any multi-factor authentication options we make available.
- Report suspicious activity, phishing attempts, or unauthorised access immediately.
- Ensure that any devices you use to access the platform are running current software and are free of malware.
- Comply with the Acceptable Use Policy, including the prohibition on reverse engineering, probing, or bypassing security controls.
5. What we do not guarantee
No platform can be completely secure. We operate the controls above in good faith and review them regularly, but we do not warrant that the platform will be free from vulnerability or unauthorised access. You use the platform at your own risk and should maintain your own backups of critical business records where appropriate.
6. Changes
We may update this page as our security practices evolve. The "last updated" date above shows when it was last changed. Material changes to our security posture will be communicated via in-platform notice or email where appropriate.