Security is a precondition, not an add-on
How Blufire protects your data: the infrastructure we are built on, the controls we run, who processes your data, and the documents you can request. Your data is stored in Australia, and we connect to your systems read-only.
The controls we run
Blufire handles commercial and customer data for businesses turning over millions, so security is a precondition of the product, not an add-on. We build on infrastructure that is already certified to the highest standards, keep your data in Australia, give each customer an isolated environment, and only ever read from your systems. We are transparent about every provider that touches your data, and we are pursuing our own SOC 2 Type 2 certification.
Data profile
Product security
- Encryption at rest and in transit
- Multi-factor authentication
- Append-only audit logging
- Single sign-on (SAML / SCIM)
Resilience
- Point-in-time recovery
- Encrypted redundant backups (AU)
- Continuous monitoring
- Verified data deletion
Your data lives in Sydney
Core data is stored in the AWS Sydney region and stays in Australia. A small number of specialist providers process specific data in transit, and every one is listed in the sub-processor table below.
Certified infrastructure, honest claims
What you can access today, and what is on the way. Request gated documents from our security team.
Compliance
Documents
Nine areas, itemised
Four verifiable controls in each of the nine areas a vendor security review asks about.
Data security
- AES-256 encryption at rest
- TLS encryption in transit
- Per-tenant encryption keys
- Crypto-shred on deletion
Access control
- Row-level security
- Single sign-on (SAML / SCIM)
- Multi-factor authentication
- Least-privilege access
Infrastructure
- Supabase (SOC 2 / ISO 27001)
- Vercel (SOC 2 / ISO 27001)
- Google Cloud and AWS
- Environment segregation
Data residency
- Stored in AWS Sydney
- Encrypted backups in AU
- Core data stays in Australia
- Transparent sub-processors
Data privacy
- Data minimisation
- Opt-out, anonymised benchmarking
- Breach notification
- We never sell your data
AI
- Transparent AI use
- No training on your data
- Zero-data-retention option
- Analytics product uses no AI
Data connections
- Read-only access only
- Official APIs (Shopify, Google)
- OAuth you can revoke
- Tokens never logged
Isolation
- Separate database per tenant
- No shared data tables
- Default-deny access
- Per-tenant Cube context
Continuity
- Point-in-time recovery
- RTO ~1h / RPO ~5min
- 12-month hot audit log
- 7-year cold archive
Every provider that touches your data
Every third-party provider Blufire relies on. Locations in blue store your data in Australia.
| Company | Purpose | Location |
|---|---|---|
| Supabase | Primary database, authentication and storage | Australia (Sydney) |
| Amazon Web Services | Cloud infrastructure and audit-log storage | Australia (Sydney) |
| Cloudflare | Encrypted secondary backup storage (R2) | Australia (Sydney) |
| Upstash | Caching layer (Redis) | Australia (Sydney) |
| Fly.io | Application and client-portal hosting | Australia / global |
| Vercel | Web application hosting (runs on AWS) | USA |
| Advertising and analytics data access | Global, AU region | |
| Anthropic | AI processing for the service platform (Claude) | USA |
| Inngest | Background job and workflow orchestration | USA |
| Resend | Transactional email delivery | USA / global |
| WorkOS | Enterprise single sign-on (SAML / SCIM) | USA |
| Voyage AI | Text embeddings for similarity matching | USA |
Questions security teams ask
Who to contact
Running a vendor security review? We will walk your team through the architecture and complete your questionnaire.
Security
Report a vulnerability, request our security documentation, or run a review: security@blufire.com.au. Please give us a reasonable chance to remediate before any public disclosure.
Privacy
Privacy questions, data-handling and erasure requests, and DPA requests: privacy@blufire.com.au.