Skip to content
Security & your data

Your business runs on us. Here’s how we keep it safe.

Your customers, your jobs, your documents. In plain English, here is exactly where it all lives, what we deliberately never store, and how every business is walled off from every other.

What we never store

The scary stuff isn’t ours to lose.

Your customers' card numbers

Payments run straight to Stripe, a PCI-compliant global provider. Card details never touch our servers, so in the worst case there is simply nothing for an attacker to steal.

Readable passwords

Every password is one-way scrambled (hashed) before it is ever saved, in a vault our public system cannot read. Not even we can see a password, so a database breach cannot hand them over.

Step 01

Staff request and upload

Your team requests or uploads documents straight through their own portal login, no email chains.

Step 02

Lands in your Drive workspace

Files go into the Google Drive workspace we set up and share with your team, auto-renamed and dropped into the right compliance folder.

Step 03

Linked in Rule 72

Rule 72 holds a secure link to each file, so you open it from the portal or straight in Drive.

How we protect it

Built to be safe by default.

Your documents live in a Drive workspace we share with you

Files are saved to a Google Drive workspace we set up for your business, auto-renamed and filed into your compliance folders, and shared with your team. You can open or download any of them at any time. If you run Microsoft 365, we can connect it instead during your build.

Strict tenant isolation

Every business's data is separated at the database level with row-level security, so one client can never see another's customers, jobs, staff or files. Isolation is enforced by the platform, not left to the app.

Encrypted in transit, Australian-hosted

The whole platform runs over HTTPS with modern security headers, hosted in Sydney on Vercel and Supabase. Your data stays in the region you expect.

We never touch card details

Payments run through Stripe, a PCI-compliant global provider. Card numbers go straight to Stripe and are never seen or stored by Rule 72.

Access controls & SSO

Unlimited staff logins with role-based access. Enterprise plans add single sign-on (SSO) and advanced access controls to fit your organisation's policies.

Built for compliance

Licences, registrations, certificates and renewals are tracked in the portal, which flags anything expired or expiring in the next 30 days, and every document is captured digitally and kept audit-ready. No printing, no filing cabinet.

Our security checklist

What’s switched on, in plain English.

Every business's data is walled off at the database level, so one client can never see another's
Encrypted in transit and at rest. HTTPS enforced everywhere, with modern browser security headers
Hosted in Sydney, Australia, so your data stays in the region you expect
Automatic daily backups of the whole database
Card payments handled entirely by Stripe (PCI-compliant) and never stored by us
Passwords stored one-way encrypted and never kept in a readable form
Internal database controls locked down from public access and reviewed after every change

Australian-based, GST-registered.

RULE OF 72 GROUP PTY LTD · ABN 29 692 877 633. Hosted in Sydney on Vercel and Supabase. Payments handled by Stripe. Have a security or procurement question? We are happy to walk your team through it.

Own your data. Run one login.

Book a discovery call →