01
Encrypted at rest
The database volume and the application host's disks are encrypted. The database is not reachable from the public internet — it accepts connections only from the application's own security group.
Security
Systemise holds commercially sensitive information — what you charge, what work costs you, and who your clients are. This page sets out where that data lives, how it is protected, and which third parties touch it. Everything stated here is implemented today.
How we work
Six things that are in place today. Where a control is not yet in place, it is not listed.
01
The database volume and the application host's disks are encrypted. The database is not reachable from the public internet — it accepts connections only from the application's own security group.
02
All traffic is served over HTTPS. Plain HTTP exists only to answer the certificate renewal challenge and redirect you to the secure address.
03
Each sign-in creates its own session with an expiry and a last-seen time. Any single session can be revoked — useful when a phone is lost — and revoking it immediately invalidates the refresh tokens issued under it, without disturbing anyone else on your team.
04
Refresh tokens are kept only as a SHA-256 digest. The token itself is never written to the database, so a copy of the database does not yield working credentials.
05
The iOS and Android apps store credentials in the platform's own secure storage — the iOS Keychain and the Android Keystore — rather than in ordinary application storage.
06
The database is backed up automatically with thirty days of retention, and a final snapshot is taken before any teardown, so decommissioning cannot quietly destroy your records.
Your data
Access and portability matter as much as encryption. These are commitments about what you can do with your own records.
Export whenever you want
Quotes, jobs, receipts, contacts and invoices can be exported. You are not required to stay in order to keep your history.
Deletion on request
Ask us to delete your account and we will confirm what will be removed and complete it within 30 days. Note that New Zealand tax law requires you to keep invoices, receipts and GST records for seven years, so export before you go.
We do not sell your data
Your records are not sold, rented, or shared with advertisers, and they are not used to train models for anyone else.
The Xero connection is yours
You authorise it, and you can disconnect it from the same screen at any time. Systemise reads and writes only what the connection scope allows.
Scoped to your workspace
Every record belongs to one company workspace, and access is controlled by role, so financial detail need not be visible to everyone who can see the schedule.
These are the external services that may process your data as part of delivering Systemise. We will update this list before adding another.
| Provider | Purpose | Region |
|---|---|---|
| Amazon Web Services | Hosting, database and file storage, in the Asia Pacific (Sydney) region. This is where your job records live. | Australia |
| Amazon SES | Outbound email — quotes, invoices and notifications you send from Systemise. Currently routed through a United States region, which means the contents of those emails cross the border. | United States |
| Stripe | Subscription billing. Card details are entered with Stripe and held by Stripe; Systemise never receives or stores your card number. | United States |
| Xero | Accounting, and only if you choose to connect it. Contacts, suppliers and coding move between the two systems. | New Zealand / global |
| Sentry | Error monitoring, so faults are diagnosed from real failures rather than guesswork. Diagnostic data may include the page and account involved. | Global |
| Cloudflare | DNS and edge protection for the website and its certificates. | Global |
Send security or privacy questions to [email protected] and a person will answer. If you are completing a vendor questionnaire, send it through and we will fill it in.