Security at DocChaser
Your clients trust you with their most sensitive financial documents, and you trust us with them. Here's how we protect that data — in plain language, without the marketing buzzwords.
Encryption everywhere
All traffic is encrypted in transit with TLS, and data is encrypted at rest in the database and file storage.
Row-level access control
Every table enforces row-level security so one practice can never read another practice's data — enforced at the database, not just in application code.
Expiring client portal links
Client portal links are single-purpose, tokenised and expire. Clients never need a password, and a forwarded link stops working after use or expiry.
Audit trail on staff actions
Approvals, rejections, dismissals and other staff actions are recorded with the actor and timestamp, so you can always see who did what.
Managed infrastructure
DocChaser runs on managed cloud infrastructure (Supabase and edge hosting) with automatic patching, isolated environments and encrypted backups.
Breach response
We follow the Notifiable Data Breaches scheme: if a breach is likely to cause serious harm we notify affected individuals and the OAIC.
Payments
Payments are processed by Stripe. Your card details go directly to Stripe and are never stored on, or visible to, our servers. Stripe is certified to PCI DSS Level 1, the highest level of payment industry certification.
Xero access
The Xero integration uses OAuth 2.0 — you authorise DocChaser on Xero's own site and we never see your Xero password. Access tokens are stored encrypted, and you can disconnect at any time from Settings → Integrations, which revokes our access.
Data location
Our primary database and storage are hosted with Supabase. Some subprocessors (delivery of email/SMS, AI document matching) may process data outside Australia — see our Privacy Policy for the full list and the safeguards that apply.
Report a vulnerability
If you've found a security issue, please report it responsibly to security@docchaser.com.au. We ask that you give us a reasonable opportunity to investigate and fix the issue before any public disclosure. We commit to acknowledging reports within 2 business days.
An honest note
No system is perfectly secure, and we won't claim certifications we don't hold. What we do commit to: the controls above are real and enforced, we keep the list on this page accurate, and if something goes wrong we'll tell you promptly and honestly. If your practice has a security questionnaire, send it to security@docchaser.com.au and we'll answer it directly.
