Switch from DocuSignSee how it works →
Security & trust

Security you can verify, not just claims.

Australian-hosted, encrypted end-to-end, and aligned with the Electronic Transactions Act 1999. Here's exactly what we hold today, and where we're heading.

What you get today

Strong technical controls — already shipped.

AES-256 at rest

Every document encrypted with AES-256 in Sydney-region storage (ap-southeast-2).

TLS 1.3 in transit

Modern TLS end-to-end. No plaintext traffic between browser, API, or storage.

Tamper-evident PDFs

Completed envelopes are sealed with a PKCS#12 digital signature.

Hash-chained audit trail

Append-only, SHA-256 hashed audit events with trusted UTC timestamps.

Row-level access control

Database-enforced isolation on every record — not just an app-layer check.

Role-based permissions

Owner, admin, standard, and read-only roles, with Google SSO available.

Domain locking

Admins lock their company domain to prevent rogue signups under their brand.

Australian data residency

Your documents and metadata never leave Australia.

Standards we align with today

Operating under the rules that matter for Australian business.

Electronic Transactions Act 1999 (Cth)

Consent capture, signer authentication, and an integrity hash on every completed envelope satisfy the ETA's reliability and integrity tests.

Aligned

Australian Privacy Act 1988 / APPs

APP-aligned data handling with export and deletion workflows. Data Processing Agreement available on request.

Aligned

Notifiable Data Breaches scheme

Documented incident response playbook with automatic owner and admin alerts on qualifying events.

Aligned

GDPR (EU customers)

Processing performed in Australia. DPA and Standard Contractual Clauses available for EU and UK customers.

Aligned

PCI DSS

Card data is handled entirely by Stripe (PCI DSS Level 1). KoalaDoc never sees a card number.

Out of scope
On the roadmap

What we don't hold yet — and how we'll get there.

We won't badge a certification we haven't earned. Here's the honest status of every framework customers ask us about.

SOC 2 Type II

Evidence collection underway on a continuous-compliance platform. Targeting SOC 2 Type I within 12 months and Type II 6 months after that. No CPA attestation has been issued yet — we will not claim one until it has.

In progress

ISO 27001:2022

Many Annex A technical controls are already implemented. Next phase is the formal ISMS — policy set, internal audit, and certification-body engagement. Targeted 12–18 months.

Planned

HIPAA (US Protected Health Information)

KoalaDoc is not a HIPAA Business Associate today and a BAA is not available from our infrastructure providers on the current plan. Please do not upload US-regulated PHI. A HIPAA-eligible deployment is on the longer-term roadmap.

Not supported

IRAP / Australian Government PROTECTED

Not assessed today. On the radar based on enterprise and public-sector demand — get in touch if this is a requirement for you.

Planned
Who handles your data

A short, deliberate list of sub-processors.

Lovable Cloud (Sydney, ap-southeast-2)

Primary database, authentication, and document storage.

Cloudflare

Edge delivery, web application firewall, and DDoS protection.

Resend

Transactional and notification email.

CloudConvert

PDF rendering and document conversion.

Stripe

Payments (PCI DSS Level 1). No card data touches KoalaDoc.

Responsible disclosure

Found something? Tell us, and we'll work with you in good faith.

We commit to acknowledging valid reports within two business days and working towards a fix or mitigation within 90 days. No legal action against researchers acting in good faith.

security@koaladoc.com.au
Built for Australia

Compliance isn't a tick-box. It's the foundation.

ETA 1999

Every envelope satisfies the Electronic Transactions Act 1999, with tamper-evident PDFs and trusted UTC timestamps.

Sydney data residency

Your documents never leave Australia. Encrypted at rest with AES-256, hosted in ap-southeast-2.

Privacy Act 1988

APP-aligned data handling. Export and deletion workflows for end-to-end Australian privacy compliance.

Breach notifications

Built-in incident response with the Notifiable Data Breaches scheme — owners and admins are alerted immediately.

Try KoalaDoc free for seven days.

No credit card. No subscription. Send your first envelopes on us and decide afterwards.

Get started for free