Grace← Home

DRAFT — NOT LEGAL ADVICE, and a security statement must be TRUE. This describes Grace's intended security posture based on its architecture. Confirm every claim reflects production reality before publishing (for example, that the production authentication instance and all environment settings are in place). Do not claim certifications Grace does not hold.

Security at Grace

Grace helps organisations reach and maintain ISO 9001 and ISO 27001 compliance, so we hold our own platform to a high security standard. This page summarises the measures we take to protect your data. It is a summary, not a contract; our binding commitments are in the Terms of Service and the Data Processing Addendum.

Tenant isolation

Each customer's workspace is logically isolated. Data access is enforced at the database layer using row-level security, so a request scoped to one workspace cannot read or write another's data. The application connects to the database as a least-privilege role that is itself subject to those security policies.

Access, identity and authentication

  • Authentication is handled by a specialist managed identity provider (Clerk), so we never store your password.
  • Multi-factor authentication is available.
  • Access within a workspace is governed by role-based access control — each user only sees and does what their role grants, and workspace administrators manage roles and membership.
  • Access to a workspace requires verified membership of that workspace's organisation.

Data protection

  • In transit: all traffic is encrypted over HTTPS/TLS, with HSTS enforced.
  • At rest: data is stored with our infrastructure providers' encryption at rest.
  • Data residency: the primary application database and file storage are hosted in Australia (Sydney). Some supporting services operate overseas — see sub-processors.md.

Application and infrastructure security

  • Security response headers and a Content Security Policy.
  • Rate limiting to help protect against abuse and automated attacks.
  • Audit logging and append-only assessment history, so compliance activity is traceable.
  • A managed, serverless hosting platform with routine patching of the underlying infrastructure.
  • Dependency and supply-chain hygiene: automated dependency updates and a continuous-integration check that fails the build on high-severity vulnerabilities.

Data handling and privacy

We process personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You own your data; we process it only to provide the Service. See the Privacy Policy and Data Processing Addendum.

Data breach response

We maintain processes to detect, assess and respond to security incidents. If an incident is likely to result in serious harm, we assess it and, where it is an eligible data breach, notify the OAIC and affected individuals under the Notifiable Data Breaches scheme, and notify affected customers so they can meet their own obligations.

Business continuity

Customer data is hosted on managed infrastructure (Vercel and Neon) and relies on those providers' built-in redundancy. Deleted records are retained and restorable rather than destroyed immediately.

We do not yet publish a backup cadence, retention period, or recovery-time objective. We will state those before onboarding a customer under a paid agreement, and we would rather say so than quote figures we have not tested a restore against.

Reporting a vulnerability

If you believe you have found a security issue, please contact [TO CONFIRM: e.g. security@eganservices.com]. We appreciate responsible disclosure and will work with you to resolve verified issues promptly.

Certifications and roadmap

Grace is software that helps you implement ISO 9001 and ISO 27001 controls; this does not by itself mean Grace is certified. [TO CONFIRM: state honestly whether you hold, or are pursuing, any independent certification or attestation, and remove this section if not applicable.]

© 2026 Egan Services · Grace
Privacy PolicyTerms of ServiceData Processing AddendumAcceptable Use PolicySub-processorsSecurity