Trust

Security and data handling

You are asking us to hold licence and insurance records for the contractors your firm engages, and to be the system of record when someone asks you to prove due diligence. That warrants specifics rather than adjectives, so this page is specifics.

Last reviewed 18/09/2026

Questionnaires

Ask us directly

If your procurement process needs a security questionnaire completed, or a copy of anything referenced on this page, ask us and we will send it. We would rather answer the question than have you guess.

Hosting and data

Where your data lives

Hosting region
Google Cloud Sydney (australia-southeast1)
Data residency
All platform data is stored and processed in Australia.

If any data is stored or processed outside Australia, it is named here and in the privacy policy rather than described in general terms.

Encryption in transit
TLS 1.2 or higher
Encryption at rest
AES-256
Backups
Daily
Retention
Seven years

Verification records are retained deliberately — a record that has been deleted cannot evidence what was checked and when, which is the whole point of holding it. Retention periods are set in the agreement with each firm.

Access

Who can reach what

Customer separation
A management firm sees the contractors it has engaged. Contractors are not visible to firms that have not engaged them.
Staff access
Limited to authorised staff.
Audit logging
Application logging is kept for maintenance and fault diagnosis only.
The TradeVerify sign-in page
Sign-in. Accounts lock after repeated failed attempts, and every sign-in is logged. Illustrative capture from the platform — sample data.
User group permissions: view, create, edit and print rights set separately for each area of the platform
Permissions are per group, per area, per action — view, create, edit and print granted separately. Illustrative capture from the platform — sample data.
The audit trail: dated, attributed entries including failed sign-in attempts, permission changes and registry checks, each with a severity
The audit trail. Failed sign-ins, permission changes and system checks are all on the record, attributed and timestamped. Illustrative capture from the platform — sample data.

Sub-processors

Third parties in the chain

Every third party that stores or processes data on our behalf, what it does, and where it does it. This list is the one your client's auditor will ask for.

Sub-processor list. Material changes are notified under the agreement with each firm.
Provider Purpose Processing location
Google Cloud Platform hosting, storage and backups Sydney, Australia (australia-southeast1)
Licence data aggregator Confirming licence details against government registers Australia

Incidents

If something goes wrong

Breach notification
Where we become aware of a data breach likely to result in serious harm, we assess it and notify affected individuals and the Office of the Australian Information Commissioner where required.
Reporting a vulnerability
If you have found a security issue, email security@tradeverify.com.au. We will acknowledge it and keep you updated. Please give us a reasonable opportunity to fix it before disclosing it publicly.

Need the long version?

We will complete your security questionnaire rather than send you a PDF that answers a different one.