Where your data lives
In Australia. AssessDesk's database, uploaded files and their backups are stored in Australia: the database in Sydney (Neon, on Amazon Web Services) and files in Cloudflare R2's Oceania region. The app runs on Vercel in Sydney.
Listed suppliers. Our suppliers, and where they process information, are listed in our Privacy Policy.
Keeping it private
Encryption. Everything is encrypted in transit (HTTPS) and at rest.
Separation between customers. Every consultancy's information is kept separate, and that separation is checked on every request and covered by automated tests that run before any change goes live.
Private files. Files are never public. They are handed out through short-lived links, only after a permission check.
Access by role. Clients only see their own organisation, and only what their consultancy shares with them. Team roles control what each team member can see and do.
Signing in
Two-step sign-in. Team members use two-step sign-in, with an authenticator app, and can add passkeys (Face ID, Touch ID). Client users can turn on two-step sign-in too.
Passwords. Passwords are stored only in a one-way scrambled form (scrypt), never readable, even by us.
Lockout. After repeated failed sign-ins an account is locked for 15 minutes, and we're alerted.
Backups and recovery
Database. The database is backed up continuously and can be restored to any point in the previous 7 days, with daily snapshots kept for 14 days.
Files. Uploaded files are backed up daily to a separate store. A deleted file can be recovered for 30 days.
Watching for problems
Alerts. Errors and suspicious sign-in activity alert us by email. Alerts carry technical details only, never your content.
Activity records. Sign-ins, changes, downloads and exports are recorded with the time and IP address, so you have an audit trail. These records are kept for 2 years.
Our own accounts. Every account we use to run AssessDesk (hosting, database, files, email, payments, code and domains) is protected with two-step sign-in.
Breach response. We follow a written plan for responding to privacy breaches, and will tell you without undue delay if one affects your data.
When you leave
Your data, your exit. When your subscription ends your team can still sign in, read-only, for 30 days to view and export everything. After that your data is permanently deleted, and backup copies expire within a further 30 days.
Reporting a security issue
If you think you've found a security problem in AssessDesk, please email support@assessdesk.co.nz. We'll respond promptly, and we ask that you don't access other people's data or disrupt the service while looking.