Security Overview
Last updated: 13 July 2026
The short version
Your business data is encrypted in transit and at rest, stored in enterprise-grade infrastructure, isolated per business, and only accessible by you and users you explicitly invite. We don't sell it, we don't train models on it, and you can delete everything at any time.
Where your data lives
ReferSuite runs on enterprise-grade cloud infrastructure with a managed database backend used by thousands of production applications. Data is stored in region-restricted clusters and never leaves the vendor network.
- All application traffic served over HTTPS with TLS 1.2+ (strong ciphers only)
- Database traffic encrypted end-to-end (TLS)
- Data at rest encrypted (AES-256) by the storage layer
- Daily automated backups with point-in-time recovery
Multi-tenant isolation
Every business account is tagged with a unique gym_id. Every database query is filtered by that ID at the API layer, so two businesses using ReferSuite can never see each other's leads, campaigns, or member data — even if they share the same physical database cluster. Even ReferSuite administrators cannot view individual customer records under our current privacy mode.
Authentication & access
- Passwords are hashed with bcrypt (never stored in plain text)
- Sessions use signed JWTs with short expiries and rotation on suspicious activity
- Rate limiting + brute-force protection on all login endpoints
- You control which staff have access to your account
Third-party services we use
We use a small number of trusted providers for specialised functions. Each is bound by their own strict privacy and security terms:
| Provider | Purpose | Data shared |
|---|---|---|
| Stripe | Subscription billing | Card details processed by Stripe directly — we never touch them |
| Resend | Email delivery | Recipient email + message body only |
| Twilio | SMS delivery + inbound replies | Recipient phone number + message body only |
| Cloudinary | Image uploads (logos, hero images) | Only images you explicitly upload |
| OpenAI / Anthropic / Google | AI features (send-time, drip copy) | Anonymised prompts — no member PII sent to LLMs |
We never sell your data or share it for marketing purposes.
Payments
All card processing is handled by Stripe, which is PCI DSS Level 1 certified (the highest tier). ReferSuite servers never see, touch, or store your card number.
Backup & disaster recovery
- Automated database snapshots run daily, retained for 30 days
- Point-in-time recovery available within the last 24 hours
- Application code deployed via immutable containers — rolling back to any prior version takes minutes
What happens if there's a breach
Under Australia's Notifiable Data Breaches scheme (Part IIIC of the Privacy Act 1988), we're required to notify affected users and the OAIC within a reasonable timeframe if a breach is likely to cause serious harm. Our response plan includes immediate containment, forensic review, individual notifications, and public disclosure where required.
Your control
- Export all your data at any time (CSV / JSON)
- Delete your account and everything in it permanently, in one click
- Opt any member out of communications instantly (STOP replies, unsubscribe links, and manual toggles)
What we don't have (yet)
We believe in being honest about our scope. ReferSuite is a small, independent Australian SaaS. As of today we do not hold:
- SOC 2 Type II certification
- ISO 27001 certification
- HIPAA compliance (we don't handle health records)
These are on the roadmap for when we grow into enterprise contracts that specifically require them. We follow the same underlying controls those certifications audit against — we just haven't paid for the badges yet.
Report a vulnerability
Found a security issue? Please email us at security@refersuite.com. We investigate every report and appreciate responsible disclosure — please give us a reasonable window before publishing details.
Questions
Get in touch: security@refersuite.com. See also our Privacy Policy.