
Security & Privacy
How we protect your business, your data, and your team.
We take the security of your workplace safety data seriously. Below is a plain-English summary of how JobSafePro handles encryption, hosting, payments, authentication, and AI — so you can make informed decisions and satisfy your internal governance reviews.
SSL / TLS Encryption
The entire platform is served over HTTPS (TLS 1.2+). All traffic between your device and JobSafePro is encrypted end-to-end. You can verify the certificate in your browser at https://app.jobsafepro.com.au.
Hosting & Data Storage
JobSafePro runs on Microsoft Azure (Australian region). Your data is stored in Azure SQL and Azure Blob Storage — both encrypted at rest (AES-256) and in transit.
Azure's underlying infrastructure holds ISO 27001, ISO 27017, ISO 27018, SOC 1 / 2 / 3, and Australian IRAP certifications.
ISO 27001 Alignment
JobSafePro is not yet ISO 27001 certified as a company — that's a significant undertaking (typically 6–12 months and considerable cost), and it's on our roadmap as our customer base grows. In the meantime, we align our internal practices with the ISO 27001 control framework — role-based access control, least-privilege database accounts, audit logging, and MFA enforcement for administrator accounts.
Payment Security
We do not store credit card details on our servers at any point. Payments are processed through Stripe, which is PCI DSS Level 1 certified — the highest tier of payment security certification.
Your card is tokenised by Stripe directly. JobSafePro only ever sees a token reference — never the card number, CVV, or expiry.
Multi-Factor Authentication (MFA)
We support secure MFA login through trusted identity providers:
- Google Sign-In
- Microsoft Sign-In
- Apple Sign-In
Signing in through Google, Microsoft, or Apple lets you use your existing multi-factor authentication setup — hardware keys, authenticator apps, or biometric login — without managing another set of credentials.
AI — What We Send and What's Stored
AI features (voice-to-report, hazard photo analysis, SDS extraction, SOP and quiz generation, safety recommendations) use Anthropic Claude and Azure OpenAI — both enterprise-grade providers.
- Only the content you're processing is sent — never your broader database, employee list, or unrelated records.
- Content sent via these enterprise APIs is not used to train the underlying models — this is a contractual commitment from both providers.
- AI providers don't retain your prompt beyond a short abuse-monitoring window (Anthropic: 30 days; Azure OpenAI can be configured to zero-retention).
The AI output — the drafted incident, the suggested recommendations — is saved into your JobSafePro database because that's the output you asked for. Every AI-generated result is presented as a draft for a human to review and edit before saving.
Your Data, Your Ownership
Your data belongs to you. On request we will export your data in a standard format, or delete it entirely. There is no lock-in.
Need a written security summary?
Happy to provide additional documentation to support your internal governance sign-off — just get in touch.
Contact Us