At a glance
1. Hosting & infrastructure
Regovix is a distributed platform. Different components use different infrastructure providers, each selected for reliability, security, and compliance.
| Component | Provider | Location | Standard |
|---|---|---|---|
| Website & serverless functions | Netlify, Inc. | United States | SOC 2 Type II |
| HSEQ apps (RiskMatrix, RiskReady, InductGuard, ToolboxGen, IncidentLoop, FleetCheck, ChemTrack, AuditMate, WellnessCheck, ComplianceVault, DGVault) | Base44 platform | United States | Base44 policy applies |
| RegWatchAI alert database | Supabase (PostgreSQL) | Singapore (ap-southeast-1) | SOC 2 Type II |
| Payment processing | Stripe, Inc. | United States | PCI DSS Level 1 |
| AI processing (RegWatchAI, CallAssist, chatbot) | Anthropic PBC | United States | SOC 2 Type II |
Australian data residency: If your organisation requires Australian data residency, please contact us at maddypat@regovix.com.au. Custom deployment options and Data Processing Agreements (DPAs) are available for enterprise and government clients with specific data sovereignty requirements.
2. Encryption & access controls
Encryption in transit
All data transmitted between your browser and Regovix is encrypted using TLS (HTTPS). We enforce HTTPS across all pages โ there is no option to access Regovix over an unencrypted connection.
Encryption at rest
RegWatchAI alert data stored in Supabase is encrypted at rest using AES-256 encryption. Data stored within the Base44 platform is encrypted according to Base44's security standards โ refer to Base44's security documentation for details.
Access controls
- Access to customer data is restricted to Madhu Pattarambil (Founder) on a strict need-to-know basis
- Role-based access controls within each app โ workers, supervisors, and administrators each see only what their role permits
- No Regovix personnel can access your account data without your explicit consent or a valid legal obligation
- Payment card data is never stored by Regovix โ all payment processing is handled exclusively by Stripe
Authentication
- All Regovix accounts are protected by password authentication โ passwords are hashed and never stored in plain text
- Session tokens expire automatically after inactivity
- RegWatchAI uses licence key authentication โ keys are validated server-side
3. AI data handling
Regovix uses Claude AI (Anthropic) to power specific features. Understanding how AI data is handled is important for HSEQ compliance teams considering data governance.
Which products use Anthropic AI?
| Product | AI used for | Data sent to Anthropic |
|---|---|---|
| RegWatchAI | Classifying regulatory alerts, generating compliance analysis | Regulatory source content, your query inputs |
| CallAssist | Live call guidance, transcription analysis | Call transcription text, operator queries |
| Website chatbot | Answering visitor questions about Regovix | Your chat messages only |
| 11 core HSEQ apps | AI features within Base44 platform | Processed by Base44 โ refer to Base44 Privacy Policy |
Anthropic does not train its AI models on API data by default. Data submitted through RegWatchAI, CallAssist, or the Regovix chatbot is used solely to generate the response and is not retained by Anthropic for model training under their standard API terms. Avoid submitting sensitive personal information (individual worker names, medical details, personal incident details) into AI input fields where it is not required for the task.
4. Subprocessors
Regovix uses the following third-party subprocessors to deliver the service. We have assessed each for security and compliance before use.
| Subprocessor | Purpose | Location | Data processed |
|---|---|---|---|
| Netlify, Inc. | Website hosting, serverless functions, form processing | USA | Web traffic, contact form submissions |
| Base44 | Application platform for 11 HSEQ apps | USA | All data entered into core HSEQ apps |
| Supabase | RegWatchAI alert database | Singapore | Regulatory alert data, scan timestamps |
| Anthropic PBC | Claude AI โ RegWatchAI, CallAssist, chatbot | USA | AI input text only โ not retained after response |
| Stripe, Inc. | Payment processing and subscription management | USA | Payment card data, billing information |
| GitHub, Inc. | Source code repository and deployment pipeline | USA | Application code only โ no customer data |
5. Backups & availability
RegWatchAI database (Supabase)
- Automated daily backups with point-in-time recovery on Supabase infrastructure
- Database hosted in Singapore (ap-southeast-1) with high availability
- If the live scraper fails, the app degrades gracefully to cached alerts โ no service interruption for users
HSEQ apps (Base44)
- Backup and availability managed by Base44 platform โ refer to Base44 service documentation for uptime SLAs
Website (Netlify)
- Deployed via GitHub with instant rollback capability to any previous version
- Netlify CDN provides global availability with automatic failover
6. Incident response
Data breach notification
If a data breach occurs that is likely to result in serious harm, Regovix will:
- Notify affected customers by email within 72 hours of becoming aware of the breach
- Notify the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches (NDB) scheme
- Provide a clear description of what occurred, what data was affected, and what steps are being taken
Reporting a security issue
If you discover a security vulnerability, please report it responsibly to maddypat@regovix.com.au with the subject line "Security Issue". We will acknowledge within 1 business day.
7. Data export & portability
Your compliance data belongs to you. Regovix is designed so you are never locked in.
- PDF export โ every risk assessment, SWMS, incident report, audit, and toolbox register can be exported as a professional PDF at any time
- CSV export โ tabular data (chemical registers, DG stock, fleet records, wellness check-ins) can be exported as CSV
- After cancellation โ your data remains accessible for 30 days, giving you time to export everything
- Account deletion โ upon request, all personal data is securely purged within 90 days
- DPA available โ Data Processing Agreements available on request for enterprise and government clients
To request a data export or account deletion, email maddypat@regovix.com.au. Export requests processed within 5 business days. Deletion requests processed within 90 days.
8. Regulatory compliance status
| Regulation / Standard | Status | Notes |
|---|---|---|
| Australian Privacy Act 1988 | Compliant | 13 Australian Privacy Principles applied. Full Privacy Policy at regovix.com.au/privacy |
| Notifiable Data Breaches (NDB) scheme | Compliant | Breach notification procedures in place |
| Australian Consumer Law | Compliant | Consumer guarantees apply. Refund policy at regovix.com.au/terms |
| GST โ A New Tax System Act 1999 | Compliant | GST registered. ABN 19 735 810 326. GST applied at checkout for Australian businesses. |
| ISO 27001 (Information Security) | Not yet certified | Planned for Year 2 as enterprise customer base grows |
| SOC 2 Type II (Regovix entity) | Not yet certified | Subprocessors Netlify, Anthropic, Supabase and Stripe hold their own SOC 2 certifications |
9. Questions & enterprise enquiries
Talk to Madhu directly
For security questions, Data Processing Agreements, custom deployment options, Australian data residency requirements, or volume pricing for 50+ users โ contact the founder directly.
Responses within 1 business day ยท Sydney, NSW ยท ABN 19 735 810 326