Security Overview

Last updated: 13 July 2026

The short version

Your business data is encrypted in transit and at rest, stored in enterprise-grade infrastructure, isolated per business, and only accessible by you and users you explicitly invite. We don't sell it, we don't train models on it, and you can delete everything at any time.

Where your data lives

ReferSuite runs on enterprise-grade cloud infrastructure with a managed database backend used by thousands of production applications. Data is stored in region-restricted clusters and never leaves the vendor network.

  • All application traffic served over HTTPS with TLS 1.2+ (strong ciphers only)
  • Database traffic encrypted end-to-end (TLS)
  • Data at rest encrypted (AES-256) by the storage layer
  • Daily automated backups with point-in-time recovery

Multi-tenant isolation

Every business account is tagged with a unique gym_id. Every database query is filtered by that ID at the API layer, so two businesses using ReferSuite can never see each other's leads, campaigns, or member data — even if they share the same physical database cluster. Even ReferSuite administrators cannot view individual customer records under our current privacy mode.

Authentication & access

  • Passwords are hashed with bcrypt (never stored in plain text)
  • Sessions use signed JWTs with short expiries and rotation on suspicious activity
  • Rate limiting + brute-force protection on all login endpoints
  • You control which staff have access to your account

Third-party services we use

We use a small number of trusted providers for specialised functions. Each is bound by their own strict privacy and security terms:

ProviderPurposeData shared
StripeSubscription billingCard details processed by Stripe directly — we never touch them
ResendEmail deliveryRecipient email + message body only
TwilioSMS delivery + inbound repliesRecipient phone number + message body only
CloudinaryImage uploads (logos, hero images)Only images you explicitly upload
OpenAI / Anthropic / GoogleAI features (send-time, drip copy)Anonymised prompts — no member PII sent to LLMs

We never sell your data or share it for marketing purposes.

Payments

All card processing is handled by Stripe, which is PCI DSS Level 1 certified (the highest tier). ReferSuite servers never see, touch, or store your card number.

Backup & disaster recovery

  • Automated database snapshots run daily, retained for 30 days
  • Point-in-time recovery available within the last 24 hours
  • Application code deployed via immutable containers — rolling back to any prior version takes minutes

What happens if there's a breach

Under Australia's Notifiable Data Breaches scheme (Part IIIC of the Privacy Act 1988), we're required to notify affected users and the OAIC within a reasonable timeframe if a breach is likely to cause serious harm. Our response plan includes immediate containment, forensic review, individual notifications, and public disclosure where required.

Your control

  • Export all your data at any time (CSV / JSON)
  • Delete your account and everything in it permanently, in one click
  • Opt any member out of communications instantly (STOP replies, unsubscribe links, and manual toggles)

What we don't have (yet)

We believe in being honest about our scope. ReferSuite is a small, independent Australian SaaS. As of today we do not hold:

  • SOC 2 Type II certification
  • ISO 27001 certification
  • HIPAA compliance (we don't handle health records)

These are on the roadmap for when we grow into enterprise contracts that specifically require them. We follow the same underlying controls those certifications audit against — we just haven't paid for the badges yet.

Report a vulnerability

Found a security issue? Please email us at security@refersuite.com. We investigate every report and appreciate responsible disclosure — please give us a reasonable window before publishing details.

Questions

Get in touch: security@refersuite.com. See also our Privacy Policy.