Security
๐ We take the privacy and security of your information seriously and protect it with industry-standard measures. This page explains how.
1. SSL / TLS Encryption
All data transmitted between your browser and our website and tools is encrypted using TLS (Transport Layer Security). You can verify this by the padlock icon in your browser's address bar. This ensures that information you enter โ including personal details and assessment answers โ cannot easily be intercepted in transit.
2. Payment Security
All payments are processed by Stripe, a globally trusted payment platform that is PCI DSS Level 1 compliant โ the highest level of certification in the payments industry. We do not store, process, or transmit your full credit card details on our servers. Stripe handles all payment data directly and securely.
3. Data Storage
To deliver your report and allow you to retrieve it later, we store your assessment answers, scores, generated report and the email address it was sent to in a secure database hosted by Supabase in Sydney, Australia. Access to this database is restricted and protected by credentials that are never exposed to your browser.
We retain this information only for as long as we reasonably need it, and then delete or de-identify it, as described in our Privacy Policy. We do not sell your assessment data, and we share it only with the service providers needed to operate our tools (including the AI provider that generates your report), as set out in our Privacy Policy. You can ask us to delete your information at any time.
4. Hosting Infrastructure
Our website and tools are hosted on Netlify, a trusted cloud infrastructure provider with enterprise-grade security, DDoS protection, and automatic HTTPS enforcement. Netlify's infrastructure is built on leading cloud providers with SOC 2 compliance.
5. Access Controls
Access to backend systems and customer data is restricted to authorised personnel only, using strong authentication. We apply the principle of least privilege and review access permissions regularly.
6. Email Security
Our domain is protected with industry-standard email security protocols, including:
- SPF (Sender Policy Framework) โ helps prevent email spoofing;
- DKIM (DomainKeys Identified Mail) โ verifies email authenticity; and
- DMARC โ protects against unauthorised use of our domain in emails.
7. Your Responsibilities
To help keep your information secure, we recommend:
- Keeping the report files we send you in a safe place;
- Not sharing access to your email account or report links with others;
- Keeping your own device and browser up to date; and
- Logging out of shared devices after use.
8. Reporting a Security Issue
If you discover a potential security vulnerability in our website or services, please contact us promptly and responsibly. We take all reports seriously and will respond as quickly as we can.
๐ง admin@ventureguardglobal.com.au
Please do not publicly disclose security issues before giving us a reasonable opportunity to address them.
9. Incident Response
In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988 (Cth).