Security and your data
Last updated: 11 August 2026
A status report can carry sensitive detail about your organisation’s work, so it matters where it lives and who can reach it. This page describes, plainly, how Reportoir handles that today.
Payments never touch our systems
Checkout happens entirely on Stripe’s hosted payment pages. Your card number goes to Stripe — a certified PCI DSS Level 1 payment processor — and never passes through or gets stored on Reportoir’s servers. What we hold is your subscription’s status and billing email, not payment credentials.
Where your data lives
The Reportoir application and your organisation’s data — projects, reports, contributor details — are hosted on Google Cloud in Australia. Two narrow exceptions sit outside that region: payment records live with Stripe, which operates globally including the United States, and the single small service that starts a checkout from this website runs in a US Google Cloud region — it stores nothing and simply passes the signup details to Stripe.
Encryption
All traffic to reportoir.com and app.reportoir.com is encrypted in transit with TLS, and data is encrypted at rest on Google Cloud’s infrastructure.
Access to your reports
The people who submit reports never need passwords: Reportoir sends them expiring, single-purpose magic links that grant access only to their own reporting task. Administrative access to your organisation’s workspace is limited to the people your organisation invites, and access to production systems on our side is restricted to those who operate the service.
A deliberately small surface
This marketing website is a static site — it has no database and holds no customer data. Its only server-side code is the single function that creates a Stripe checkout session. Keeping the surface small is a security choice: what isn’t there can’t leak.
Certifications, honestly
Reportoir is a young product and we don’t yet hold formal certifications such as SOC 2 or ISO 27001. We rely on the certified infrastructure of Google Cloud and Stripe underneath us, and we’re happy to answer security questionnaires from prospective customers — just get in touch.
Reporting a vulnerability
If you believe you’ve found a security issue in Reportoir, please email hello@reportoir.com with enough detail to reproduce it. We’ll acknowledge your report promptly, keep you informed as we fix it, and won’t take action against good-faith research.
Questions about how we handle personal information are covered in our privacy policy.