Security
Last updated: 12 August 2026
Infrastructure
ContechCost is served from Cloudflare Workers (globally distributed edge infrastructure) and backed by Supabase regional projects. Australian and New Zealand customer data is stored in Sydney and UK customer data in London; the US regional project is provisioned in N. Virginia pending launch. Customer data is routed according to the workspace region. All infrastructure is managed by third-party providers whose own compliance posture is listed under Subprocessors below.
Encryption
- In transit: TLS 1.3 enforced on all connections via Cloudflare. Older TLS versions are disabled.
- At rest: Database volumes are encrypted at rest by Supabase (AES-256).
- Passwords: User passwords are hashed by Supabase Auth using bcrypt. We never store plaintext credentials.
Access Controls
- All customer data is isolated by organisation. Row-level security policies are enforced at the database layer — no application code can read another organisation's data.
- Multi-factor authentication (MFA) is supported via TOTP. Organisation admins can view enrolled MFA status for members.
- API keys and service credentials are stored as encrypted secrets on the Cloudflare Worker runtime. They are never committed to source control.
- Internal team access to production infrastructure requires individual authentication to the relevant platform (Cloudflare, Supabase, GitHub). There are no shared credentials.
Audit Logging
All MCP tool calls are logged with timestamp, organisation, and tool name. Logs are retained for a minimum of 90 days.
Dependency and Code Security
- Automated vulnerability scanning via GitHub Dependabot (weekly, with automatic fix PRs for CVE-affected dependencies).
- GitHub CodeQL/code scanning is not currently enabled. Security-sensitive changes are reviewed and covered by the required test workflow before release.
Incident Response
In the event of a confirmed security incident affecting customer data, we will notify affected organisations by email within 72 hours of our own confirmation of the incident, consistent with applicable data protection law.
Subprocessors
The following third parties process customer data on our behalf:
- Supabase — database, authentication, file storage (regional projects: Sydney for AU/NZ; London for UK; N. Virginia for US). supabase.com/security
- Cloudflare — application delivery, DDoS protection, Worker runtime (global edge). cloudflare.com/trust-hub
- Anthropic — AI inference for MCP-connected estimating workflows. anthropic.com/privacy
- Stripe — payment processing and billing. stripe.com/privacy
- Resend — transactional email delivery. resend.com/privacy
Responsible Disclosure
If you have found a security vulnerability, please read our Responsible Disclosure Policy before reporting. Security reports go to support@contechcost.com.