Security and hosting
This page summarises how HighSign hosts and protects your data. It's a plain-English overview for your own risk team, a client or an insurer; the full statement is the live /security page, which this summarises and does not exceed.
Australian hosting and residency
Customer data is hosted in Australia (Supabase, Sydney region), and the application's server functions are pinned to the same Sydney region, so requests don't leave the country in normal operation. A small number of sub-processors may process limited data overseas; where they do, HighSign takes reasonable steps to ensure comparable protection consistent with the Australian Privacy Principles.
HighSign is offered to customers internationally. If you are outside Australia, including in the EU or United Kingdom, you can request a data processing agreement and details of how your data is handled by contacting us.
Tenant isolation
Every organisation's workspace is logically isolated. Access is scoped to your own organisation in application code on every request, and the system is designed so that one customer can never read or change another's data. Row-level security policies are also defined at the database as a further layer of defence. Only your governance team signs in, with roles (owner, admin, approver, reviewer); staff never authenticate at all.
Encryption and secrets
All traffic is served over TLS with HSTS, and the app sets a strict security-header and content-security policy. Data is encrypted at rest by the hosting provider. API keys and service credentials live only in server-side configuration, never in the browser or the code repository.
The activity log
Governance actions, policy changes, decisions, exceptions, attestations and incidents, are recorded to a chronological activity log you can show an auditor.
The declared-signals boundary
HighSign governs the AI tools and data classes you declare, and the answers your staff request. It does not intercept network traffic, read staff messages, or monitor individuals. Staff tool checks record that a lookup happened, for adoption metrics, but HighSign does not record who made it. Requests and reports carry only the name a person chooses to give, so you can reply.
AI safety
Verdicts are computed deterministically from your policy rules; no AI model sits in the answer path. See AI safety for how the optional AI drafting features work.
Sub-processors
| Sub-processor | What it handles | Where |
|---|---|---|
| Supabase | Database, authentication, file storage | Australia (Sydney) |
| Vercel | Application hosting and server compute | Functions pinned to Sydney; global edge for static assets |
| Stripe | Subscription billing and payment processing | Active only when billing is enabled |
| Resend | Transactional email (sign-in links, notifications) | Active only when email is enabled |
| Anthropic | Optional AI drafting and research features | Active only when enabled; sent only public tool information, never client data |
HighSign does not sell personal information and does not run advertising trackers.
Breach response
If an eligible data breach affecting your information occurred, it would be assessed and affected customers and your data protection authority notified in line with applicable breach-notification rules (in Australia, the OAIC and the Notifiable Data Breaches scheme).
Related
- /security for the full statement this page summarises
- Privacy and data use for what's collected and how it's used
- AI safety for the answer-path guarantee and optional AI features
This page is a summary for convenience, not legal advice. Security questions or a due-diligence questionnaire: hello@howll.ai.