MineFloMineFlo

Security at MineFlo

How we protect your data and operations

Last updated: 3 June 2026

1. Infrastructure


2. Encryption


3. Authentication & Access Control


4. Application Security


5. Data Isolation & Multi-Tenancy


6. Data Residency


7. Backup & Recovery


8. Incident Response

If a security incident occurs, our response process is:

  1. Detection & Containment — Identify the scope and contain the incident immediately
  2. Assessment — Determine what data was affected and the severity
  3. Notification — Notify affected users and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches (NDB) scheme — within 30 days of becoming aware of an eligible breach
  4. Remediation — Fix the vulnerability and implement measures to prevent recurrence
  5. Post-incident review — Document lessons learned and update security controls

Report security concerns to: security@mineflo.io


9. Essential Eight Alignment

MineFlo’s security practices align with the Australian Signals Directorate’s Essential Eight framework:

ControlStatus

Application control

Managed via Vercel’s serverless platform

Managed

Patch applications

Dependencies updated regularly via automated tooling

In Place

Configure Microsoft Office macros

Not applicable — web-based platform

In Place

User application hardening

CSP headers, input sanitisation

In Place

Restrict administrative privileges

RBAC with graduated permission levels

In Place

Patch operating systems

Managed by Vercel’s serverless infrastructure

Managed

Multi-factor authentication

On roadmap for Q3 2026

Planned

Regular backups

Automated via Turso managed infrastructure

Managed

10. Compliance Roadmap

We are actively working toward industry-standard certifications:

ISO 27001 — Information Security Management System certification. Target: 2027

SOC 2 Type II — Independent audit of security controls. Target: 2027

Essential Eight Maturity Level 2 — ASD cyber security baseline. In progress

SOCI Act readiness — Critical infrastructure compliance framework. Monitoring requirements

We believe in transparency about where we are today, not just where we’re going. If you have specific security requirements, contact us at security@mineflo.io and we’ll provide detailed responses.


11. Responsible Disclosure

If you discover a security vulnerability in MineFlo, please report it responsibly:


12. Contact

For security questions, concerns, or to request our vendor security questionnaire response:

Security: security@mineflo.io
General: support@mineflo.io
Entity: Hodl Labs Pty Ltd, Perth, Western Australia


We’re a small team that takes security seriously. If you have questions, just ask.

← Back to MineFlo