Security & trust

Security at Notara

How the systems we build are secured, where your data lives, which providers we rely on, and how to reach us if you find a problem.

Last reviewed 3 September 2026

Sydney
Your database and server-side code sit in an Australian region wherever the data should stay onshore.
Yours
Hosting and database accounts are registered to your business, and the repository moves to you at handover.
Vanta
Compliance preparation for when your own customers start asking for SOC 2 or ISO 27001.
Vanta

Vanta automates the evidence collection and continuous monitoring behind SOC 2, ISO 27001, HIPAA and other frameworks.

Vanta integrations on our stack
Vercel Supabase GitHub

A Vanta partner

Notara is a Vanta partner. When your own customers start asking for SOC 2 or ISO 27001, that preparation is work we can run for you. The rest of this page covers what your system runs on, how we build on top of it, and what happens if something goes wrong.

Where your own business needs a certification, that is what our Vanta partnership is for. In practice it means three things:

  • If your customers have started asking for SOC 2 or ISO 27001, we can set your business up on Vanta and run the technical side of preparing for the audit.
  • The platforms we build on — Vercel, Supabase and GitHub — each have a Vanta integration, so the evidence Vanta collects comes from your live infrastructure rather than from screenshots.
  • We build so the technical controls an auditor asks about — backups, encryption, access boundaries, change history — are in place from the first deployment rather than retrofitted later. The organisational side, such as periodic access reviews, stays with your team.

The audit itself is carried out by an independent auditor. Vanta and Notara make the preparation faster and keep the evidence continuous.

Learn more about Vanta →

How we build

How we build on top of it

The providers secure the infrastructure. These are the decisions that are ours.

Managed authentication

Sign-in runs on Supabase Auth rather than code we write ourselves. Password hashing and session handling come from the platform, and multi-factor authentication is available from it where a project asks for it.

Access enforced in the database

Postgres row-level security on the tables that hold your data, so a user can only reach the rows they are allowed to. The rule lives in the database, not in one screen somebody could forget to check.

Least privilege

Roles are defined up front — owner, staff, customer — and each sees only what its job needs. Administrative access to the hosting and database accounts is limited to the people working on your project.

Secrets out of the code

API keys and credentials live in each platform’s encrypted environment configuration, not in the repository, and are rotated at handover.

Card data never touches your system

Payments go through Stripe’s hosted elements, so card numbers travel straight to Stripe. The system we build never sees, stores or transmits one.

Backups and a way back

Daily database backups on Supabase’s paid plans, point-in-time recovery for projects that need it, and a written restore procedure in the handover documentation. A project left on a free plan has no automatic backups, and we say so before it goes live.

Data in Australia when it needs to be

Both platforms offer Sydney regions: Supabase ap-southeast-2 and Vercel syd1. Neither is the default, so where your data should stay onshore we set them deliberately, and we tell you which parts of the system still run elsewhere.

AI kept to what it needs

Where a build includes an AI feature it calls Anthropic’s Claude API under their commercial terms, which by default do not use your inputs or outputs to train models. The model is sent the minimum it needs for the task, and the call leaves Australia, so we tell you before an AI feature goes near personal information.

Accounts in your name

Hosting and database accounts are registered to your business. The repository moves into your organisation at handover, every credential is rotated at that point, and our access can be removed the same day.

Responsible disclosure

Found something? Tell us.

If you believe you have found a security issue in a service Notara operates, such as this website, email hello@notara.com.au with “Security” in the subject line and enough detail to reproduce it. We will acknowledge the report, keep you informed while it is fixed, and credit you if you would like us to.

Please act in good faith: do not access, change or delete data that is not yours, do not run denial-of-service tests, and give us a fair chance to fix the issue before disclosing it publicly. We will not pursue researchers who follow those rules on a service we operate.

Systems we have built for clients belong to those clients, and we cannot authorise testing of a system we do not operate. If you believe you have found an issue in one, tell us and we will pass it to the owner rather than asking you to probe further.

Machine-readable contact /.well-known/security.txt
Contact: mailto:hello@notara.com.au
Expires: 2027-09-01T00:00:00.000Z
Preferred-Languages: en
Canonical: https://notara.com.au/.well-known/security.txt
Policy: https://notara.com.au/security

Notara handles personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply, and our Privacy Policy covers how we treat information inside client systems. Where a breach affects a client’s own system, the duty to assess and notify under the Notifiable Data Breaches scheme generally sits with the client as the entity holding the information, and we support that assessment. This is general information about how we work, not legal advice about your own obligations.

Vercel, Supabase, Vanta, Stripe, Anthropic, Resend and GitHub are trademarks of their respective owners, used here to identify the services Notara builds on. No endorsement is implied. Vercel, the Vercel design and related marks, designs and logos are trademarks or registered trademarks of Vercel, Inc. or its affiliates in the US and other countries.

Common questions from vendor reviews

Can you help us get SOC 2 or ISO 27001?

Yes. Notara is a Vanta partner, so we can set your business up on Vanta and run the technical side of getting you ready. Vanta automates the evidence collection and continuous monitoring behind SOC 2, ISO 27001, HIPAA and other frameworks, and the platforms we build on all have Vanta integrations, so the evidence comes from your live infrastructure. The audit itself is carried out by an independent auditor.

Where is my data stored?

In the region chosen for your project. Vercel and Supabase both offer Sydney regions, and for Australian clients who need data kept onshore that is where we put the database and the server-side code. Neither platform defaults to Sydney, so it is a setting we choose deliberately. Some things still leave: the content delivery network is global, provider logs and billing records are processed in the United States, and any AI or email feature calls a service there too. We will tell you which of those apply to your build.

Who can access my data?

Your own users, according to the roles built into the system. During the build and any support period, the people working on your project have administrative access to the hosting and database accounts. Those accounts are registered to your business, so you can revoke that access at any time; the repository moves into your organisation at handover.

Will you sign an NDA or data-processing terms?

Yes. Confidentiality is standard in our agreements, and where your industry or your customers require specific data-processing or security terms, they can be written into the scope of work.

Do you use AI on my data?

Only where an AI feature is part of the scope you agreed to. Those features call Anthropic’s Claude API under their commercial terms, which by default do not use inputs or outputs to train models, and the model is sent the minimum it needs for the task. The call goes to a service outside Australia, so it is an overseas disclosure your own privacy obligations may cover. There is more on this in our article on AI and personal information.

What happens to your access when the project ends?

It is removed. The accounts are in your name, credentials are rotated at handover, and the handover documentation lets another developer run the system without us.

Can you complete our security questionnaire?

Yes. Send it to hello@notara.com.au. Most of the answers are on this page, and for provider-level questions we will point you to the relevant trust centre document.

Need this for a vendor review?

Send your questionnaire to hello@notara.com.au, or book a 30-minute call and we will walk through it with whoever is signing off.

Book a call