Contech/Cost

Security

Last updated: 12 August 2026

Infrastructure

ContechCost is served from Cloudflare Workers (globally distributed edge infrastructure) and backed by Supabase regional projects. Australian and New Zealand customer data is stored in Sydney and UK customer data in London; the US regional project is provisioned in N. Virginia pending launch. Customer data is routed according to the workspace region. All infrastructure is managed by third-party providers whose own compliance posture is listed under Subprocessors below.

Encryption

  • In transit: TLS 1.3 enforced on all connections via Cloudflare. Older TLS versions are disabled.
  • At rest: Database volumes are encrypted at rest by Supabase (AES-256).
  • Passwords: User passwords are hashed by Supabase Auth using bcrypt. We never store plaintext credentials.

Access Controls

  • All customer data is isolated by organisation. Row-level security policies are enforced at the database layer — no application code can read another organisation's data.
  • Multi-factor authentication (MFA) is supported via TOTP. Organisation admins can view enrolled MFA status for members.
  • API keys and service credentials are stored as encrypted secrets on the Cloudflare Worker runtime. They are never committed to source control.
  • Internal team access to production infrastructure requires individual authentication to the relevant platform (Cloudflare, Supabase, GitHub). There are no shared credentials.

Audit Logging

All MCP tool calls are logged with timestamp, organisation, and tool name. Logs are retained for a minimum of 90 days.

Dependency and Code Security

  • Automated vulnerability scanning via GitHub Dependabot (weekly, with automatic fix PRs for CVE-affected dependencies).
  • GitHub CodeQL/code scanning is not currently enabled. Security-sensitive changes are reviewed and covered by the required test workflow before release.

Incident Response

In the event of a confirmed security incident affecting customer data, we will notify affected organisations by email within 72 hours of our own confirmation of the incident, consistent with applicable data protection law.

Subprocessors

The following third parties process customer data on our behalf:

Responsible Disclosure

If you have found a security vulnerability, please read our Responsible Disclosure Policy before reporting. Security reports go to support@contechcost.com.