Trust & Security

Last updated: 31 May 2026

Brokers trust lsbroker with their clients' enquiry details, so protecting that information is central to how we build. This page sets out where your data lives, how it's protected, and the independently-audited infrastructure we rely on. Everything below is verifiable โ€” we've linked to each provider's own security documentation.

๐Ÿ‡ฆ๐Ÿ‡บAustralian data residency

Your account and lead data are stored in a database hosted in Sydney, Australia. Our database provider deploys each project into the region chosen at creation and keeps the data within that region โ€” so your primary data stays onshore. (Some supporting services, noted below, may process limited data overseas; this is detailed in our Privacy Policy.)

๐Ÿ›ก๏ธBuilt on independently-audited infrastructure

lsbroker runs on established providers that are independently audited and certified to recognised security standards. We inherit and build on those controls:

ProviderRoleIndependent certifications
Supabase Database, authentication & hosting (Sydney region) SOC 2 Type 2, ISO 27001 ยท supabase.com/security
Vercel Website & application hosting / delivery SOC 2 Type 2 ยท security.vercel.com
Stripe Subscription billing & payments PCI DSS Level 1, SOC 2 Type II, ISO 27001 ยท stripe.com/security
Resend Lead-notification & account email delivery SOC 2, GDPR ยท resend.com/security
To be precise: these certifications are held by the named providers. lsbroker is built on this certified infrastructure โ€” we don't claim to independently hold these certifications ourselves.

๐Ÿ”’Encryption

Data is encrypted in transit using TLS, and at rest using strong encryption (AES-256) across our hosting and database providers. Connections to lsbroker and its calculators are served over HTTPS.

๐Ÿ’ณPayments โ€” we never see your card

All subscription payments are handled directly by Stripe, a PCI DSS Level 1 certified payment processor (the highest level). Card details are entered into Stripe's secure systems โ€” lsbroker never receives or stores full card numbers, which keeps that sensitive data out of our environment entirely.

๐Ÿ“ŠYour data, used only to run the service

๐ŸšจData breach response

We comply with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988 (Cth). If an eligible data breach affecting personal information were to occur, we are committed to notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by law.

๐ŸคFor brokers โ€” data handled on your behalf

Enquiry information submitted through your branded calculator belongs to you. We process and store it on your behalf to deliver the service, and route it to you by email and (optionally) to your connected spreadsheet. This is designed to support your own obligations under the Australian Privacy Principles. If you need a written data-processing statement for your records or your own compliance, contact us.

โœ‰๏ธQuestions

Security or data questions, or a request for documentation? Email admin@lsbroker.com.au.