MineFloSecurity at MineFlo
How we protect your data and operations
Last updated: 3 June 2026
1. Infrastructure
- Hosting: Vercel (SOC 2 Type II certified, ISO 27001 compliant) — serverless architecture with automatic scaling and DDoS protection
- Database: Turso (LibSQL) — encrypted at rest, hosted in the Asia-Pacific region with automated backups
- CDN & Edge: Vercel Edge Network — global content delivery with TLS termination at the edge
- DNS & Protection: Cloudflare — DDoS mitigation and DNS security
2. Encryption
- In transit: All data transmitted over HTTPS/TLS 1.2+ — no unencrypted connections are permitted
- At rest: Database encryption at rest via the hosting provider’s encryption layer
- Passwords: Hashed using bcrypt with per-user salts — we never store plaintext passwords
3. Authentication & Access Control
- Session management: Secure HTTP-only cookies with SameSite protection — not accessible via JavaScript
- Role-based access control (RBAC): Platform admin, company admin, site admin, and general user roles with graduated permissions
- Multi-tenancy isolation: Each company’s data is logically isolated — users can only access companies and sites they’ve been invited to
- Company administrator controls: Admins manage user invitations, role assignments, and user removal
4. Application Security
- Input validation: Server-side validation on all API endpoints
- SQL injection prevention: Parameterised queries via Drizzle ORM — no raw SQL interpolation
- XSS protection: React’s built-in output encoding plus Content Security Policy headers
- CSRF protection: SameSite cookie attributes and origin validation
- Dependency management: Regular updates of npm dependencies to address known vulnerabilities
5. Data Isolation & Multi-Tenancy
- MineFlo is a multi-tenant platform. Your organisation’s data is completely isolated from other organisations
- Users can only access data for companies and sites where they hold an active membership
- Company administrators control who has access and what role they hold
- There is no cross-company visibility — one company cannot see, query, or access another company’s data under any circumstances
6. Data Residency
- MineFlo’s primary database is hosted in the Asia-Pacific region
- Application hosting via Vercel operates from multiple global edge locations with primary compute in the nearest available region
- We are committed to offering Australian-hosted data residency (Sydney, AWS ap-southeast-2) for enterprise clients upon request
- All data is processed in accordance with the Australian Privacy Act 1988
7. Backup & Recovery
- Automated database backups maintained by Turso’s managed infrastructure
- Point-in-time recovery capability
- Application code stored in version-controlled repositories with full history
8. Incident Response
If a security incident occurs, our response process is:
- Detection & Containment — Identify the scope and contain the incident immediately
- Assessment — Determine what data was affected and the severity
- Notification — Notify affected users and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches (NDB) scheme — within 30 days of becoming aware of an eligible breach
- Remediation — Fix the vulnerability and implement measures to prevent recurrence
- Post-incident review — Document lessons learned and update security controls
Report security concerns to: security@mineflo.io
9. Essential Eight Alignment
MineFlo’s security practices align with the Australian Signals Directorate’s Essential Eight framework:
ControlStatus
Application control
Managed via Vercel’s serverless platform
ManagedPatch applications
Dependencies updated regularly via automated tooling
In PlaceConfigure Microsoft Office macros
Not applicable — web-based platform
In PlaceUser application hardening
CSP headers, input sanitisation
In PlaceRestrict administrative privileges
RBAC with graduated permission levels
In PlacePatch operating systems
Managed by Vercel’s serverless infrastructure
ManagedMulti-factor authentication
On roadmap for Q3 2026
PlannedRegular backups
Automated via Turso managed infrastructure
Managed
10. Compliance Roadmap
We are actively working toward industry-standard certifications:
ISO 27001 — Information Security Management System certification. Target: 2027
SOC 2 Type II — Independent audit of security controls. Target: 2027
Essential Eight Maturity Level 2 — ASD cyber security baseline. In progress
SOCI Act readiness — Critical infrastructure compliance framework. Monitoring requirements
We believe in transparency about where we are today, not just where we’re going. If you have specific security requirements, contact us at security@mineflo.io and we’ll provide detailed responses.
11. Responsible Disclosure
If you discover a security vulnerability in MineFlo, please report it responsibly:
- Email: security@mineflo.io
- Include a description of the vulnerability and steps to reproduce
- We will acknowledge receipt within 48 hours
- We will not take legal action against researchers who report vulnerabilities in good faith
12. Contact
For security questions, concerns, or to request our vendor security questionnaire response:
Security: security@mineflo.io
General: support@mineflo.io
Entity: Hodl Labs Pty Ltd, Perth, Western Australia
We’re a small team that takes security seriously. If you have questions, just ask.
← Back to MineFlo