Security — the boring page that matters.
You're trusting us with client information. Here is exactly where it lives, how it's protected, and — just as important — what we never ask for.
What we never ask for
- No fund logins. SuperChase never asks for your (or your client's) super fund portal credentials — not once, not optionally.
- No TFNs. Tax file numbers are not collected and have no field anywhere in the product.
- No sending from your inbox. We draft letters; you send them from your own email. We never connect to or send through your mailbox.
Where your data lives
All practice and client data is stored in a dedicated database in Sydney, Australia (Supabase, on AWS ap-southeast-2). It does not leave Australia. Data is encrypted in transit (TLS) and at rest.
Practice isolation
Every table enforces row-level security: your practice's data is invisible to every other practice at the database layer, not just the application layer. There are no shared workspaces and no cross-practice queries.
Payments
Billing runs entirely through Stripe. Your card number never touches our servers and we cannot see it.
The Fund Response Index
The published index uses aggregated response-time data only — fund names and day counts. No client information, practice names, or request contents are ever included.
Deletion
Ask and it's gone: contact us to delete your practice and all client data permanently. Cancelling your subscription does not silently delete data (so you can come back), but a deletion request removes everything.
Honest limits
SuperChase is a young product from a small independent team. We hold no SOC 2 or ISO 27001 certification yet — we'd rather tell you that plainly than imply otherwise. The architecture above is real, verifiable, and built conservative-first.