Security & Privacy
Last updated - July 2026
This page is a summary of our security and privacy approach, and is not a binding technical specification, audit report, or exhaustive list of controls.
On this page
Security philosophy
AppHub is designed so the database is the authority for roles, organisation boundaries, app availability, app grants, and app data access. User interface checks support the experience, but access decisions are enforced by server-side and database controls.
Apps are modular. Each hosted application is expected to keep its own data separate from other applications unless a documented shared platform service is used.
Organisation data isolation
Organisation-scoped data is designed to stay inside the relevant organisation boundary. Access policies enforce same-organisation reads and writes, and administrators do not receive a silent blanket bypass to customer data.
Where an application has a designated data owner, owner access is explicit and limited to approved app surfaces rather than broad access to every table or file.
Explicit access gates
Users see and launch only the applications they are granted. App availability, per-user app grants, account status, and organisation context are checked before access is allowed.
Removing access is treated as a revoke until it is deliberately re-added by an authorised operator.
Audited support access
Cross-organisation support access, where available, is deliberate, session-bound, and audited. It is intended for support and management workflows where the operator must act in the context of another organisation.
Support access is not designed to be silent or ambient. The platform records sensitive administrative actions for accountability.
Secure file and application intake
Public and authenticated intake flows use validation, review, scanning or gating appropriate to the workflow. Applications added to AppHub are expected to pass review before they are made available to users.
Public forms and selected browser-only tools may use rate limiting and bot protection to reduce automated abuse.
Platform hardening
AppHub is delivered through Cloudflare's global edge network and uses hosted Supabase services for authentication and database storage. Operational controls include environment separation, server-only secrets, rate limiting for selected public endpoints, and review of privileged server paths.
No public summary can guarantee that every threat is eliminated. Customers should still use strong account hygiene, least-privilege grants, and prompt reporting of suspected compromise.
Personal information we collect
AppHub may collect account details, organisation details, contact enquiries, authentication events, application access records, audit logs, submitted files, form responses, and other information users provide through hosted applications.
We use this information to provide AppHub, authenticate users, administer organisations and application access, respond to enquiries, secure the platform, investigate incidents, maintain records, and comply with legal obligations.
Overseas storage and processing
Personal information may be stored and processed outside Australia. The primary Supabase data store is hosted in Seoul, South Korea. AppHub is also delivered through Cloudflare's global edge network, which may process requests in locations outside Australia.
This disclosure is intended to support Australian Privacy Principle 8 transparency for overseas disclosure and processing.
Subprocessors
Current named subprocessors include Supabase for database and authentication hosting, and Cloudflare for edge compute, content delivery, and Turnstile bot protection.
Subprocessors may change as AppHub evolves. We aim to keep this public summary current when material platform providers change.
Cloudflare Turnstile
AppHub uses Cloudflare Turnstile to reduce spam and automated abuse on selected public workflows. Use of Turnstile is subject to Cloudflare's Privacy Policy.
Retention
We retain information for as long as needed to provide AppHub, meet operational and security needs, comply with legal obligations, resolve disputes, and maintain audit records. Retention periods may differ by application, file type, customer agreement, and legal requirement.
Backups, logs, and audit records may persist for a limited period after data is removed from active use.
Access, correction, and complaints
To request access to or correction of personal information, raise a privacy concern, or make a complaint, contact support@apphub.au. We may need to verify your identity and organisation before acting on a request.
If you are an end user of a customer organisation, we may direct you to that organisation where it controls the relevant information or account relationship.
