Australian data residency
Core database records, private file storage, and backups are hosted in Australia, in the Sydney region.
Security
Taltrax uses tenant isolation, role-based access, private file storage, audit trails, and Australian hosting for the core data-at-rest path.
Core database records, private file storage, and backups are hosted in Australia, in the Sydney region.
Every request is enforced at the database layer through row-level security tied to operator membership; client-side filters are not treated as the security boundary.
File uploads use short-lived server-authorised paths, private buckets, size and content checks, and operator-scoped access.
Access and integrity
Response and recovery
Taltrax maintains breach-response, secret-rotation, continuity, legal-request, and restore procedures. When the production PITR gate is active, RPO near-zero and RTO within four hours are operational recovery targets, not availability guarantees.
To report a suspected vulnerability, emailsupport@taltrax.com with “Security” in the subject. Do not include live credentials or sensitive operator records.
Taltrax’s current service path uses Supabase, Vercel, Cloudflare Turnstile, Resend, Stripe in test mode, and OpenAI only when the optional AI checklist feature is enabled. The OpenAI API is called without requesting response storage; a formal zero-data-retention agreement has not yet been executed. ThePrivacy Policy explains current processing and cross-border disclosures.
No analytics vendor is active. PostHog, Plausible, Sentry, and third-party uptime monitoring remain deferred and are not represented as current security or data-processing controls.