Security at CoreDocket

Last reviewed: 27 August 2026

CoreDocket holds personal information belonging to our customers and to their customers, including names, addresses, contact details, signatures, site photographs and safety records. This page sets out where that information is held, the measures that protect it, and how long it is retained. It is written to answer the questions commonly raised in a client or contractor security assessment.

Where your data lives

Information held in your account is stored in Australia.

  • Your database, files and sign-inSydney, Australia

    Supabase, region ap-southeast-2.

  • The application that serves your screensSydney, Australia

    Vercel functions are pinned to the syd1 region, confirmed from production response headers.

  • BackupsSydney, Australia

    Retained with the database, in the same region.

A limited number of specific functions are performed outside Australia, including sending email and SMS, processing card payments and address lookup. Each is identified in the sub-processor list, together with the information it receives.

How it is protected

  • Encrypted in transit and at rest. TLS on every connection, with HSTS. Disk-level encryption on the database and file storage.
  • Each organisation’s records are isolated from every other organisation’s. Isolation is enforced in the database on every row, rather than by application code. It therefore holds independently of any fault in the application.
  • Files are stored privately. Photographs, signatures and attachments are not accessible by URL. Access is granted individually and expires.
  • Permissions are set by you and enforced on the server. What each person may see and do is determined by the account owner, and each permission is checked at the point the action is performed.
  • Signed safety records cannot be altered retrospectively. A signature is recorded against the specific version of the document that was signed. A subsequent edit creates a new version requiring fresh signatures; it does not alter the record already signed.
  • Browser security headers are applied to protect against clickjacking, content-type sniffing and referrer leakage.

Who can reach your data

The people you invite to your account, with the permissions you assign them. CoreDocket personnel access customer information only to operate the service, to provide support at your request, or where required by law. We do not browse customer records, we do not use your information to market to your customers, and we do not sell it.

Access to production systems is restricted to CoreDocket personnel who require it. Card details are entered on Stripe’s hosted checkout page and are not received or stored by CoreDocket.

How long we keep it

Your business records remain yours. They are retained while your account is open, made available on request, and deleted on your instruction. CoreDocket does not apply a retention period of its own to records you may be required by law to keep.

  • Your jobs, dockets, customers, photographs and signatures

    While your account is open, then 90 days after it closes.

    These are your business records. No retention limit is applied while your account is open. The 90-day period allows a closed account to be exported.

  • Safety documents and the signatures on them

    While your account is open, without alteration.

    A signature is recorded against the specific version of the document that was signed, and is not affected by later edits to that document.

  • Timesheets and leave

    While your account is open.

    These are employee records. Responsibility for retaining them rests with the employer, for seven years under the Fair Work Act 2009 (Cth). CoreDocket does not delete them on a schedule of its own.

  • Job SMS, both directions

    While your account is open.

    No automatic deletion period currently applies. Twilio also retains its own copy of message content.

  • Website analytics on coredocket.com.au

    90 days, then automatically deleted.

    Deletion is applied automatically in the database.

  • Billing records

    7 years.

    Required for taxation and corporate record-keeping.

Access and export

Records may be exported at any time, including while an account is overdue or suspended. CoreDocket does not withhold Customer Data in order to secure payment. Where an account is closed, data is retained for 90 days so that it may still be retrieved, and is then deleted or de-identified.

Data breaches and reporting

No system is entirely secure. In the event of a data breach likely to result in serious harm, we will notify the affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme. Affected customers will be informed of what is known at the time rather than on completion of the assessment.

If you believe you have found a security problem in CoreDocket, email enquiries@coredocket.com.au with sufficient detail to reproduce it. We will acknowledge the report, and we will take no action against any person who reports a genuine issue in good faith and who does not access or alter the data of others in the course of doing so.

Your responsibilities

The security of an account also depends on how it is administered. Each person should hold their own login rather than share one, permissions should reflect what each role requires, and access should be withdrawn when a person leaves. An account on which logins are shared cannot produce a reliable record of who performed a given action.