Legal
Security Policy
Effective date: 27 July 2026
1. Our approach to security
Protecting your data is fundamental to how Akweno is built. We follow a defence-in-depth approach, applying security controls at the infrastructure, application and data layers so that no single control is relied upon alone.
Security considerations are built into how we design and ship features, not added afterwards. Where we rely on third-party providers, we choose established platforms with strong security track records and configure them conservatively.
No online service can guarantee absolute security. Our goal is to reduce risk to a level appropriate for the sensitivity of the information the Services hold.
2. Infrastructure and hosting
The Services run on established cloud infrastructure providers, including Vercel for application hosting and Supabase for managed database and authentication services. These providers operate hardened data centres with their own physical, network and operational security controls.
We rely on managed infrastructure so that:
- Operating systems and platform components are patched and maintained by specialist providers
- Network boundaries and firewalls are managed at the platform level
- The application is deployed through a controlled, auditable pipeline
- Infrastructure is monitored for availability and anomalies
3. Encryption
We use encryption to protect your data both in transit and at rest:
- All traffic between your browser and the Services is encrypted using industry-standard TLS (HTTPS)
- Data stored in our managed database and file storage is encrypted at rest by our infrastructure providers
- Connections between application components and the database are encrypted
- Passwords are never stored in plain text — only securely salted and hashed representations are kept
4. Authentication and account security
Authentication is handled by Supabase Auth, a managed authentication service. This means:
- Passwords are hashed using industry-standard algorithms and are never accessible to us in readable form
- Sessions are managed with secure, signed tokens
- Sign-in activity is subject to rate limiting to slow down automated attacks
- Multi-factor authentication is supported where available
You control access to your own account, and we recommend using a strong, unique password.
5. Access controls and data isolation
Your data is logically isolated so that you can only ever access your own records. We enforce this at the database level, not only in application code:
- Row Level Security (RLS) policies are applied to user data tables so that every query is scoped to the authenticated account that owns the data
- Sensitive or privileged fields are locked down with additional database policies and grants
- Privileged and administrative operations are restricted to trusted server-side processes and are never exposed to the browser
- Internal administrative access to production systems is limited to authorised personnel on a need-to-know basis
6. Application security
We apply a range of controls within the application itself:
- Database queries are parameterised to guard against injection attacks
- User input is validated and sanitised on the server
- Sensitive endpoints are rate limited to reduce abuse and brute-force attempts
- Uploaded files are validated by inspecting their actual contents, not just their file extension, before being accepted
- Security-related HTTP response headers (such as content-type protections and transport security) are applied across the site
- Documents are served with protections that prevent them from being interpreted as executable content
7. Document storage
Documents you upload — such as leases, statements, invoices and reports — are stored in private cloud storage. They are not publicly accessible, and are only served to you through authenticated, access-controlled requests. Files are validated on upload before they are stored.
8. AI data handling
Some Akweno features use artificial intelligence to assist you — for example document extraction, expense categorisation and portfolio questions. We handle data used by these features carefully:
- The in-app AI assistant is read-only and cannot change your data or make decisions on your behalf
- Access to your portfolio data by AI features is limited, and broader access is opt-in and permission-gated
- Where reasonably available, we configure AI providers so that your submitted data is not used to train publicly available models
- AI conversation history is not retained by default
- Information is transmitted to trusted AI providers only to deliver the requested functionality
AI outputs are indicative and provided for convenience. You remain responsible for reviewing them before relying on them.
9. Payment security
Subscription payments are processed by Stripe, a PCI-DSS compliant payment provider. Akweno does not store your full payment card details. Card data is handled directly by Stripe in accordance with its own security standards and privacy policy.
10. Monitoring and logging
To detect and respond to issues, we maintain monitoring and logging, including:
- Application error capture and diagnostic logging
- Audit logging of sensitive administrative actions
- Infrastructure-level availability and performance monitoring
We aim to minimise the amount of sensitive personal information captured in logs.
11. Backups and data retention
Our managed database provider maintains regular, encrypted backups to support recovery in the event of a failure. Backups are retained for a limited period before being securely overwritten. Our approach to how long we keep your information is described in our Privacy Policy.
12. Data residency
Because Akweno is a cloud-based platform, your data may be processed or stored in countries outside your own. Where information is transferred internationally, we take reasonable steps to ensure appropriate contractual and technical safeguards are in place. Further detail is provided in our Privacy Policy.
13. Your responsibilities
Security is a shared responsibility. To help keep your account safe, you should:
- Choose a strong, unique password and keep your login credentials confidential
- Enable multi-factor authentication where available
- Keep your own devices, browsers and email account secure
- Avoid uploading highly sensitive identifiers (such as tax file numbers or passport details) unless a feature specifically requests them
- Notify us promptly if you suspect any unauthorised access to your account
14. Responsible disclosure
We welcome reports from security researchers and users who identify potential vulnerabilities. If you believe you have found a security issue in the Services, please email us at security@akweno.com with enough detail for us to reproduce and investigate the issue.
We ask that you:
- Give us a reasonable opportunity to investigate and remediate before any public disclosure
- Avoid accessing, modifying or deleting data that does not belong to you
- Avoid actions that could degrade the Services or affect other users
We will not pursue action against researchers who report issues in good faith and in line with this policy.
15. Incident response
We maintain processes to investigate and respond to suspected security incidents. In the event of a data breach affecting your personal information, we will act to contain and remediate the incident and will notify affected users and any relevant regulators where required by applicable law, including the Privacy Act 1988 (Cth) and the Notifiable Data Breaches scheme.
16. Changes to this Security Policy
We may update this Security Policy as our practices and technology evolve. The latest version will always be available through our website, and the effective date above will be updated when changes are made.
17. Contact us
For questions about this Security Policy or to report a security concern, please contact: