Blufire Trust Center
How Blufire protects your data: the infrastructure we are built on, the controls we run, who processes your data, and the documents you can request. Your data is stored in Australia, and we connect to your systems read-only.
Overview
Blufire handles commercial and customer data for businesses turning over millions, so security is a precondition of the product, not an add-on. We build on infrastructure that is already certified to the highest standards, keep your data in Australia, give each customer an isolated environment, and only ever read from your systems. We are transparent about every provider that touches your data, and we are pursuing our own SOC 2 Type 2 certification.
Compliance
Documents
What you can access today, and what is on the way. Request gated documents from our security team.
SOC 2 and penetration-test reports are on our compliance roadmap and are not yet available. The certifications shown in Compliance are held by our infrastructure providers, not by Blufire, and underpin the services we run on.
Data profile
Product security
- ✓Encryption at rest and in transit
- ✓Multi-factor authentication
- ✓Append-only audit logging
- ✓Single sign-on (SAML / SCIM)
Resilience
- ✓Point-in-time recovery
- ✓Encrypted redundant backups (AU)
- ✓Continuous monitoring
- ✓Verified data deletion
Data security
- ✓AES-256 encryption at rest
- ✓TLS encryption in transit
- ✓Per-tenant encryption keys
- ✓Crypto-shred on deletion
Access control
- ✓Row-level security
- ✓Single sign-on (SAML / SCIM)
- ✓Multi-factor authentication
- ✓Least-privilege access
Infrastructure
- ✓Supabase (SOC 2 / ISO 27001)
- ✓Vercel (SOC 2 / ISO 27001)
- ✓Google Cloud and AWS
- ✓Environment segregation
Data residency
- ✓Stored in AWS Sydney
- ✓Encrypted backups in AU
- ✓Core data stays in Australia
- ✓Transparent sub-processors
Data privacy
- ✓Data minimisation
- ✓Opt-out, anonymised benchmarking
- ✓Breach notification
- ✓We never sell your data
AI
- ✓Transparent AI use
- ✓No training on your data
- ✓Zero-data-retention option
- ✓Analytics product uses no AI
Data connections
- ✓Read-only access only
- ✓Official APIs (Shopify, Google)
- ✓OAuth you can revoke
- ✓Tokens never logged
Isolation
- ✓Separate database per tenant
- ✓No shared data tables
- ✓Default-deny access
- ✓Per-tenant Cube context
Continuity
- ✓Point-in-time recovery
- ✓RTO ~1h / RPO ~5min
- ✓12-month hot audit log
- ✓7-year cold archive
Sub-processors
Every third-party provider Blufire relies on. Locations in teal store your data in Australia.
| Company | Purpose | Location |
|---|---|---|
| Supabase | Primary database, authentication and storage | Australia (Sydney) |
| Amazon Web Services | Cloud infrastructure and audit-log storage | Australia (Sydney) |
| Cloudflare | Encrypted secondary backup storage (R2) | Australia (Sydney) |
| Upstash | Caching layer (Redis) | Australia (Sydney) |
| Fly.io | Application and client-portal hosting | Australia / global |
| Vercel | Web application hosting (runs on AWS) | USA |
| Advertising and analytics data access | Global, AU region | |
| Anthropic | AI processing for the service platform (Claude) | USA |
| Inngest | Background job and workflow orchestration | USA |
| Resend | Transactional email delivery | USA / global |
| WorkOS | Enterprise single sign-on (SAML / SCIM) | USA |
| Voyage AI | Text embeddings for similarity matching | USA |
We update this list as our infrastructure changes and notify customers with a data-processing agreement of material changes.
Knowledge base
Where is my data stored?+
Do you train AI models on my data?+
Can I delete my data?+
Do you write changes back to my store or ad accounts?+
Are you SOC 2 certified?+
Can I get a DPA or do a security review?+
Security
Report a vulnerability, request our security documentation, or run a review: info@blufire.com.au. Please give us a reasonable chance to remediate before any public disclosure.
Privacy
Privacy questions, data-handling and erasure requests, and DPA requests: info@blufire.com.au.