Security

Security and Trust.

Last updated · 30 March 2026

Plain-English summary: This Security & Trust Policy explains the technical, organisational and operational safeguards SubSync AI Pty Ltd uses to protect the security, integrity and availability of the SubSync AI platform ("Platform"), with particular attention to the security of uploaded subcontract documents and commercially sensitive construction industry data. This policy is intended to provide transparency to customers, partners and users regarding how SubSync AI protects data, systems and services. It complements the SubSync AI Terms of Use, Privacy Policy and Responsible AI & Acceptable Use Policy.

1. Purpose

This Security & Trust Policy explains the technical, organisational and operational safeguards SubSync AI Pty Ltd ("SubSync AI", "we", "us", "our") uses to protect the security, integrity and availability of the SubSync AI platform ("Platform"), with particular attention to the security of uploaded subcontract documents and commercially sensitive construction industry data.

This policy is intended to provide transparency to customers, partners and users regarding how SubSync AI protects data, systems and services. It complements the SubSync AI Terms of Use, Privacy Policy and Responsible AI & Acceptable Use Policy.

2. Security Principles

SubSync AI's security program is designed around the following principles:

  • Confidentiality — protecting information from unauthorised disclosure, with particular care for uploaded contract documents and commercially sensitive data
  • Integrity — preventing unauthorised modification of data, systems or Outputs
  • Availability — ensuring reliable and resilient access to services
  • Accountability — maintaining traceability of system activities and access to uploaded documents
  • Privacy protection — safeguarding personal information in accordance with the Privacy Act 1988 (Cth)
  • Output integrity — maintaining the reliability and consistency of AI-generated Outputs

3. Infrastructure Security

The Platform operates on secure cloud infrastructure operated by reputable service providers. Security controls may include:

  • network segmentation and firewall protections
  • secure configuration management
  • continuous monitoring of infrastructure
  • protection against distributed denial-of-service (DDoS) attacks
  • vulnerability scanning and patch management

Infrastructure providers implement industry-standard physical security protections including restricted facility access, surveillance systems and environmental controls.

4. Data Protection

SubSync AI takes reasonable steps to protect Customer Data, uploaded contract documents and personal information. Security practices may include:

  • encryption of data in transit using TLS
  • encryption of sensitive data and uploaded documents at rest
  • access control restrictions based on user roles
  • secure storage of credentials and authentication tokens
  • monitoring for unauthorised access attempts

Personal information is handled in accordance with the SubSync AI Privacy Policy and the Australian Privacy Principles.

Uploaded Contract Documents

Uploaded subcontract agreements and related construction documents are treated as Confidential Information and are subject to the following specific controls:

  • uploaded documents are stored in encrypted form and are isolated from the data of other customers
  • access to uploaded documents by SubSync AI personnel is restricted to authorised individuals with a legitimate business need and is logged
  • uploaded documents are not shared with third parties except as required to deliver the Services and subject to confidentiality obligations
  • uploaded documents are retained for the duration of the subscription and for 12 months after account closure, after which they are deleted or de-identified

5. AI Output Integrity

The reliability and consistency of AI-generated Outputs is a core security and trust concern for SubSync AI. The following controls are maintained to protect Output integrity:

Model Version Control

SubSync AI maintains version control over the AI models used to generate Outputs. Model updates are subject to internal testing and quality review before deployment. Where a model update is likely to materially affect the nature or reliability of Outputs, users will be notified through the Platform or by email.

Output Audit Trail

The Platform maintains records of Outputs generated for each user session during the subscription term and for 12 months following account closure. Users may request a copy of Outputs generated during their subscription by contacting support@subsync.com.au. This audit trail is designed to support users who need to refer back to what the Platform told them about a specific document at a specific time. It does not constitute a representation about the accuracy or completeness of any Output.

AI Subprocessor Controls

The Platform uses third-party AI model providers to process Inputs and generate Outputs. SubSync AI has contractual controls in place with AI subprocessors that:

  • prohibit the use of uploaded customer content for model training or improvement
  • require handling of customer content as confidential
  • require appropriate security controls over customer data

Details of current AI subprocessors are available on request by contacting privacy@subsync.com.au.

6. Access Control

Access to internal systems and production environments is restricted to authorised personnel with a legitimate business need. Controls may include:

  • role-based access control (RBAC)
  • strong authentication requirements including multi-factor authentication for administrative access
  • periodic access reviews
  • logging and monitoring of administrative activity

SubSync AI personnel are subject to confidentiality obligations and internal security policies.

7. Payment Security

SubSync AI uses Stripe to process subscription payments. SubSync AI does not store full payment card details. Payment details are collected and processed directly by Stripe. Additional safeguards for payment-related actions may include:

  • two-factor authentication (2FA) or multi-factor authentication (MFA) for access to accounts and payment-related actions
  • card verification checks and risk-based fraud detection supported by Stripe
  • Strong Customer Authentication controls where supported and applicable
  • monitoring for suspicious or anomalous payment and billing activity

8. Monitoring and Logging

The Platform maintains system logs and monitoring mechanisms designed to detect unusual activity. Monitoring may include:

  • authentication events
  • system access logs
  • API usage monitoring
  • abnormal usage patterns
  • access to uploaded contract documents

Logs may be used to investigate security incidents, detect misuse and improve system security.

9. Incident Response

SubSync AI maintains procedures for responding to security incidents. In the event of a suspected security issue, we may:

  • investigate and assess the incident
  • contain and mitigate the impact
  • notify affected users where appropriate
  • implement corrective actions to prevent recurrence

Where personal information is involved, SubSync AI complies with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth). If you become aware of a suspected security issue affecting the Platform or your data, please notify us immediately at security@subsync.com.au.

10. Vendor and Subprocessor Security

SubSync AI may use trusted third-party vendors or subprocessors to support infrastructure, analytics, payment processing and AI services. We take reasonable steps to ensure service providers implement appropriate security safeguards and are bound by contractual data protection obligations.

Where subprocessors are located outside Australia, we take reasonable steps to ensure they handle personal information and Confidential Information consistently with Australian privacy law and our contractual commitments to customers.

11. Customer Responsibilities

Customers play an important role in maintaining security. Customers must:

  • maintain the confidentiality of account credentials and not share login details
  • enable multi-factor authentication where available
  • promptly report suspected unauthorised access to security@subsync.com.au
  • ensure Authorised End Users comply with security best practices
  • check confidentiality obligations in any document before uploading it to the Platform
  • log out of accounts when using shared or public devices

12. Responsible Disclosure

If you discover a potential security vulnerability or issue affecting the Platform, please notify us promptly. We will investigate credible reports and take appropriate action. Security reports can be sent to: security@subsync.com.au.

We ask that you do not publicly disclose any vulnerability until we have had a reasonable opportunity to investigate and remediate.

13. Service Reliability

SubSync AI aims to maintain reliable service availability through resilient infrastructure and operational monitoring. However, as with all cloud-based systems, uninterrupted availability cannot be guaranteed. We may perform maintenance or updates periodically to maintain system performance and security.

14. Policy Updates

SubSync AI may update this Security & Trust Policy periodically to reflect changes in security practices, technology or regulatory requirements. Material updates may be communicated through the Platform or our website.

15. Governing Law

This Policy is governed by the laws of Victoria, Australia.

Contact

SubSync AI Pty Ltd
Melbourne, Victoria, Australia
General: support@subsync.com.au
Privacy: privacy@subsync.com.au
Security: security@subsync.com.au
Website: subsync.com.au


© SubSync AI Pty Ltd 2026 · ACN 695 835 539 · ABN 68 695 835 539 · Melbourne, Victoria, Australia.