SSessionBeacon

Security & Data Breach Response

Version 1.0 · Effective 19 June 2026

How we protect data and how we respond to security incidents.

We take the security of your information seriously. This page summarises the measures we use and how we respond to security incidents, including our obligations under the Notifiable Data Breaches (NDB) scheme in the Privacy Act 1988 (Cth).

How we protect data

  • Encryption in transit (HTTPS/TLS).
  • Passwords stored using the Argon2id hashing algorithm — never in plain text.
  • Role-based access controls; every query is scoped to the requesting user.
  • Rate limiting and abuse protections on sensitive endpoints.
  • Security headers (CSP, HSTS and others) and unguessable, revocable feed tokens.
  • An append-only audit log of sensitive actions.

Reporting a vulnerability

If you discover a security vulnerability, please report it privately to [email protected]. Give us a reasonable chance to investigate and fix the issue before any public disclosure. Please do not access or modify other users' data while testing.

Data breach response plan

If we become aware of a suspected data breach, we will:

  1. Contain — immediately limit the breach and preserve evidence.
  2. Assess — investigate what happened, what data is involved, and the risk of serious harm, promptly and within 30 days.
  3. Notify — where the breach is likely to result in serious harm, notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the NDB scheme.
  4. Remediate — fix the root cause and take steps to prevent recurrence.
  5. Review — record the incident and update controls and this plan.

Related

See our Privacy Policy and Data Retention Schedule.