Security at DocChaser

Your clients trust you with their most sensitive financial documents, and you trust us with them. Here's how we protect that data — in plain language, without the marketing buzzwords.

Encryption everywhere

All traffic is encrypted in transit with TLS, and data is encrypted at rest in the database and file storage.

Row-level access control

Every table enforces row-level security so one practice can never read another practice's data — enforced at the database, not just in application code.

Expiring client portal links

Client portal links are single-purpose, tokenised and expire. Clients never need a password, and a forwarded link stops working after use or expiry.

Audit trail on staff actions

Approvals, rejections, dismissals and other staff actions are recorded with the actor and timestamp, so you can always see who did what.

Managed infrastructure

DocChaser runs on managed cloud infrastructure (Supabase and edge hosting) with automatic patching, isolated environments and encrypted backups.

Breach response

We follow the Notifiable Data Breaches scheme: if a breach is likely to cause serious harm we notify affected individuals and the OAIC.

Payments

Payments are processed by Stripe. Your card details go directly to Stripe and are never stored on, or visible to, our servers. Stripe is certified to PCI DSS Level 1, the highest level of payment industry certification.

Xero access

The Xero integration uses OAuth 2.0 — you authorise DocChaser on Xero's own site and we never see your Xero password. Access tokens are stored encrypted, and you can disconnect at any time from Settings → Integrations, which revokes our access.

Data location

Our primary database and storage are hosted with Supabase. Some subprocessors (delivery of email/SMS, AI document matching) may process data outside Australia — see our Privacy Policy for the full list and the safeguards that apply.

Report a vulnerability

If you've found a security issue, please report it responsibly to security@docchaser.com.au. We ask that you give us a reasonable opportunity to investigate and fix the issue before any public disclosure. We commit to acknowledging reports within 2 business days.

An honest note

No system is perfectly secure, and we won't claim certifications we don't hold. What we do commit to: the controls above are real and enforced, we keep the list on this page accurate, and if something goes wrong we'll tell you promptly and honestly. If your practice has a security questionnaire, send it to security@docchaser.com.au and we'll answer it directly.