Operated by Orixian Solutions Pty Ltd (ABN 40 627 250 186), Australia.
Compliance posture
Stable Baseline operates under ISO/IEC 27001-aligned technical and organisational controls: layered tenant isolation, TLS 1.3 in transit and encryption at rest, multi-factor authentication and enterprise SAML SSO, immutable audit logging with 12-month default retention, and a daily automated security verification suite run against production. Orixian Solutions has not yet undergone an external SOC 2 or ISO 27001 audit; external attestation is a future consideration we will evaluate alongside customer demand and our go-to-market stage. Our infrastructure subprocessors, AWS/Supabase (Sydney), Microsoft Azure (Australia), Cloudflare and Stripe, each maintain SOC 2 Type II and/or ISO 27001 attestations, and the controls they provide are inherited by Stable Baseline.
We operationalise the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and the GDPR for EEA/UK data subjects, through our Privacy Policy and our request mailbox at [email protected]. Our management-approved policies are listed below; the full text of any policy is available for customer review on request.
Architecture & hosting: your data lives in Australia
- Database, authentication, file storage, application functions: Supabase managed PostgreSQL on AWS Asia Pacific (Sydney). All persistent workspace content resides here.
- Document, design and meeting processing: Microsoft Azure, Australia regions. Transient processing state is purged on an hourly cycle.
- Diagram rendering: Orixian-managed render server hosted in Sydney.
- Application delivery: Cloudflare global edge (hosting, CDN, WAF, DDoS protection). Content transits the edge encrypted and is not retained at rest.
- Payments: Stripe. Card details never reach Orixian systems.
- Email: Resend (transactional only, no marketing lists).
Customer tenants are isolated by access controls enforced at the database layer, reinforced at the application layer, and probed continuously by automated cross-tenant isolation tests.
Encryption
- In transit: TLS 1.3 on every endpoint; HTTPS enforced with HSTS.
- At rest: encrypted managed storage for the database and file stores.
- Secrets: platform and customer AI keys are held in an encrypted secrets vault, never in code or configuration files.
- File access: short-lived signed URLs.
Access control
- Multi-factor authentication (TOTP) is available to every account and required for administrative access, which is restricted to named personnel with step-up re-authentication for destructive operations.
- Enterprise SAML 2.0 SSO (Microsoft Entra ID, Okta, Google Workspace) with DNS-verified domains and per-member enforcement.
- Role-based access control (Owner, Admin, Team Lead, Member, Editor, Viewer) with per-resource permission overrides.
- Agent/MCP access uses capability-scoped API keys that are individually revocable, rate-limited, and attributable in the audit log.
AI & your data
- Platform AI features run through Vercel AI Gateway with Zero Data Retention enforced: the gateway retains no prompts or outputs (data is permanently deleted when a request completes) and requests are routed only to model providers operating under Vercel's negotiated zero-data-retention agreements. Your content is never used to train models, ours or anyone else's.
- Bring your own AI (Enterprise): connect your own provider accounts (OpenAI, Anthropic, Azure AI Foundry and others) and AI requests flow to your provider under your agreement. Platform AI routing is bypassed entirely.
- Only the prompt and the relevant workspace context for a request are sent; AI processing is transient.
- Text embeddings for search and the Knowledge Graph are computed inside our own Australian infrastructure and never leave it; no external provider is engaged for embeddings.
Secure development
- A daily automated security verification suite of ~500 offensive and defensive tests runs against production: dependency scanning against OSV.dev and the CISA KEV catalogue, static analysis with security rules, secret scanning, TLS/security-header probes, and live tenant-isolation attack probes. Findings feed a posture report reviewed daily.
- Pre-commit and pre-deploy security gates block secrets and known-vulnerable dependencies.
- Penetration tested: white-box review plus authenticated live probes; every confirmed finding fixed and verified in production. A full-codebase security audit closed all critical and high findings.
Resilience
- Managed daily database backups with recovery objectives of RTO 24 hours / RPO 24 hours (operational targets; contractual commitments are made in Enterprise agreements).
- Fully managed, serverless-first infrastructure: hardware failure is absorbed by AWS, Azure and Cloudflare.
- Graceful degradation: if AI or rendering workers are disrupted, your documents remain readable and editable.
- Annual restore verification, recorded.
Incident response
Our Cybersecurity Incident Response Plan governs detection, containment, eradication, recovery, notification and post-incident review. We commit to notifying affected customers within 48 hours of confirming a security incident that materially affects their data, with ongoing updates until resolution, and we support customers' obligations under the Australian Notifiable Data Breaches scheme and GDPR Article 33.
Vulnerability disclosure
Report findings to [email protected] (see /.well-known/security.txt). We acknowledge within 3 business days and remediate by severity: critical 7 days, high 30 days, medium 90 days.
Subprocessors
The full list (provider, purpose, region, attestations) is published at /subprocessors. Material additions are announced at least 30 days in advance.
Policies
Each management-approved policy is reviewed at least annually; full text available for customer review on request:
Data retention at a glance
Contact
Security, privacy and data-subject requests, legal and contracts: [email protected] · vulnerability reports: [email protected]. Orixian Solutions Pty Ltd, Mount Waverley VIC 3149, Australia.