Security & your data

Your business runs on us. Here’s how we keep it safe.

Your customers, your jobs, your documents — in plain English, here is exactly where it all lives, what we deliberately never store, and how every business is walled off from every other.

What we never store

The scary stuff isn’t ours to lose.

Your customers' card numbers

Payments run straight to Stripe, a PCI-compliant global provider. Card details never touch our servers — so in the worst case, there is simply nothing for an attacker to steal.

Readable passwords

Every password is one-way scrambled (hashed) before it is ever saved, in a vault our public system cannot read. Not even we can see a password — so a database breach cannot hand them over.

Step 01

Staff request and upload

Your team requests or uploads documents straight through their own portal login, no email chains.

Step 02

Lands in your cloud

Files go directly into your own Microsoft 365 or Google, auto-renamed and dropped into the right compliance folder.

Step 03

Linked in Rule 72

Rule 72 holds a secure link to each file. Open it with your own company login. Nothing is stored on our servers.

How we protect it

Built to be safe by default.

Your documents stay on your own cloud

Files are saved directly to your own Microsoft 365 or Google, auto-renamed and filed into your compliance folders. Rule 72 only holds a secure link, opened with your own company logins. Nothing is stored on our servers.

Strict tenant isolation

Every business's data is separated at the database level with row-level security, so one client can never see another's customers, jobs, staff or files. Isolation is enforced by the platform, not left to the app.

Encrypted in transit, Australian-hosted

The whole platform runs over HTTPS with modern security headers, hosted in Sydney on Vercel and Supabase. Your data stays in the region you expect.

We never touch card details

Payments run through Stripe, a PCI-compliant global provider. Card numbers go straight to Stripe and are never seen or stored by Rule 72.

Access controls & SSO

Unlimited staff logins with role-based access. Enterprise plans add single sign-on (SSO) and advanced access controls to fit your organisation's policies.

Built for compliance

Licences, registrations, certificates and renewals are tracked with reminders, and every document is captured digitally and kept audit-ready — no printing, no filing cabinet.

Our security checklist

What’s switched on, in plain English.

Every business's data is walled off at the database level — one client can never see another's
Encrypted end to end — HTTPS enforced everywhere, with modern browser security headers
Hosted in Sydney, Australia — your data stays in the region you expect
Automatic daily backups of the whole database
Card payments handled entirely by Stripe (PCI-compliant) — never stored by us
Passwords stored one-way encrypted — never kept in a readable form
Internal database controls locked down from public access and reviewed after every change

Australian-based, GST-registered.

RULE OF 72 GROUP PTY LTD · ABN 29 692 877 633. Hosted in Sydney on Vercel and Supabase. Payments handled by Stripe. Have a security or procurement question? We are happy to walk your team through it.

Talk to us →

Own your data. Run one login.

Book a discovery call →