Security & Trust

Your venue data is protected by design.

Venues V is built with security at every layer โ€” from encrypted connections and tenant isolation to role-based access and audit trails. Australian hospitality operators trust us with their operational data. Here's how we earn that.

๐Ÿ”’

Encrypted in transit and at rest

All data is transmitted over TLS 1.2+ HTTPS connections. Database storage is encrypted using industry-standard AES-256 encryption managed by our infrastructure provider.

๐Ÿ›ก๏ธ

Tenant isolation via Row-Level Security

Every database query is filtered by Row-Level Security policies. Your venue data is mathematically isolated โ€” other customers' rows are invisible to your application session.

๐Ÿ‘ค

Role-based access control

Owners, managers, cleaners and staff each see only what their role permits. Screen visibility, API access and database policies all enforce the same permission boundaries.

๐Ÿ“ธ

Evidence integrity

Photo evidence is cryptographically hashed at capture time, establishing a tamper-evident chain of proof from the moment an image is taken to the time it's reviewed.

๐Ÿ”

Authenticated API access

Every API request requires a valid session token. Admin operations use a separate service-level client with restricted permissions โ€” never exposed to the client application.

๐Ÿšจ

Content moderation

Chat messages and issue descriptions are screened for objectionable content. Users can report messages and block other users. Moderation actions are logged.

Our security practices

  • Session management: Bounded token lifetimes with automatic refresh. Suspended sessions are recovered gracefully without trapping users behind spinners.
  • Input validation: All form inputs are validated client-side and server-side. File uploads are restricted to image and video types with size limits.
  • Dependency management: Dependencies are locked via package lockfiles and regularly updated to address known vulnerabilities.
  • Infrastructure: Hosted on managed infrastructure with automated backups, security patches and monitoring.
  • Privacy by design: Data minimisation โ€” we only collect what's needed for the product to function. Account deletion requests are processed within 30 days.
  • No shared tenancy in queries: Row-Level Security ensures no cross-tenant data leakage, even at the database engine level.
Australian data hosting
TLS 1.2+ encryption
Row-Level Security
Role-based access
Evidence hashing
GDPR / APP aware

Have security questions?

We're happy to discuss our security practices, data handling, or compliance requirements for your operation.

Contact us โ†’