Security you can verify, not just claims.
Australian-hosted, encrypted end-to-end, and aligned with the Electronic Transactions Act 1999. Here's exactly what we hold today, and where we're heading.
Strong technical controls — already shipped.
AES-256 at rest
Every document encrypted with AES-256 in Sydney-region storage (ap-southeast-2).
TLS 1.3 in transit
Modern TLS end-to-end. No plaintext traffic between browser, API, or storage.
Tamper-evident PDFs
Completed envelopes are sealed with a PKCS#12 digital signature.
Hash-chained audit trail
Append-only, SHA-256 hashed audit events with trusted UTC timestamps.
Row-level access control
Database-enforced isolation on every record — not just an app-layer check.
Role-based permissions
Owner, admin, standard, and read-only roles, with Google SSO available.
Domain locking
Admins lock their company domain to prevent rogue signups under their brand.
Australian data residency
Your documents and metadata never leave Australia.
Operating under the rules that matter for Australian business.
Electronic Transactions Act 1999 (Cth)
Consent capture, signer authentication, and an integrity hash on every completed envelope satisfy the ETA's reliability and integrity tests.
Australian Privacy Act 1988 / APPs
APP-aligned data handling with export and deletion workflows. Data Processing Agreement available on request.
Notifiable Data Breaches scheme
Documented incident response playbook with automatic owner and admin alerts on qualifying events.
GDPR (EU customers)
Processing performed in Australia. DPA and Standard Contractual Clauses available for EU and UK customers.
PCI DSS
Card data is handled entirely by Stripe (PCI DSS Level 1). KoalaDoc never sees a card number.
What we don't hold yet — and how we'll get there.
We won't badge a certification we haven't earned. Here's the honest status of every framework customers ask us about.
SOC 2 Type II
Evidence collection underway on a continuous-compliance platform. Targeting SOC 2 Type I within 12 months and Type II 6 months after that. No CPA attestation has been issued yet — we will not claim one until it has.
ISO 27001:2022
Many Annex A technical controls are already implemented. Next phase is the formal ISMS — policy set, internal audit, and certification-body engagement. Targeted 12–18 months.
HIPAA (US Protected Health Information)
KoalaDoc is not a HIPAA Business Associate today and a BAA is not available from our infrastructure providers on the current plan. Please do not upload US-regulated PHI. A HIPAA-eligible deployment is on the longer-term roadmap.
IRAP / Australian Government PROTECTED
Not assessed today. On the radar based on enterprise and public-sector demand — get in touch if this is a requirement for you.
A short, deliberate list of sub-processors.
Lovable Cloud (Sydney, ap-southeast-2)
Primary database, authentication, and document storage.
Cloudflare
Edge delivery, web application firewall, and DDoS protection.
Resend
Transactional and notification email.
CloudConvert
PDF rendering and document conversion.
Stripe
Payments (PCI DSS Level 1). No card data touches KoalaDoc.
Found something? Tell us, and we'll work with you in good faith.
We commit to acknowledging valid reports within two business days and working towards a fix or mitigation within 90 days. No legal action against researchers acting in good faith.
security@koaladoc.com.auCompliance isn't a tick-box. It's the foundation.
ETA 1999
Every envelope satisfies the Electronic Transactions Act 1999, with tamper-evident PDFs and trusted UTC timestamps.
Sydney data residency
Your documents never leave Australia. Encrypted at rest with AES-256, hosted in ap-southeast-2.
Privacy Act 1988
APP-aligned data handling. Export and deletion workflows for end-to-end Australian privacy compliance.
Breach notifications
Built-in incident response with the Notifiable Data Breaches scheme — owners and admins are alerted immediately.
Try KoalaDoc free for seven days.
No credit card. No subscription. Send your first envelopes on us and decide afterwards.
Get started for free