Security Policy
Last updated 20 August 2026
Compozer (we, Provider) is committed to protecting the security and confidentiality of Customer Data processed through our platform. This policy describes the technical and organisational measures we maintain, and supplements the security obligations in our Agreement and Data Processing Agreement (DPA). In this policy, Customer Data means data our customers process through the platform, including Customer Content and Customer Personal Data as those terms are defined in the DPA.
1. Infrastructure and hosting
1.1 Compozer is hosted on Amazon Web Services (AWS), with production data and application compute located in Australia.
1.2 Our production application runs on a serverless architecture within a private virtual network (VPC). AWS manages patching and maintenance of the underlying operating systems and runtimes.
1.3 Persistent data is stored in MongoDB Atlas (a managed database service) and managed object storage.
1.4 Customer Content is delivered through a content delivery network and may be cached and processed at edge locations outside Australia. Persistent data remains in Australia.
2. Encryption
2.1 In transit: Data transmitted between users and the platform, and between our services and our data stores, is encrypted using TLS 1.2 or higher.
2.2 At rest: Customer Data in our database and object storage is encrypted at rest using AES-256 encryption provided by our infrastructure providers (AWS and MongoDB Atlas).
3. Access control and tenant isolation
3.1 User authentication is handled by Auth0, a dedicated third-party identity provider.
3.2 Access within the platform is governed by role-based access control (Owner, Admin, Designer, and Member roles), enforcing least-privilege access to account resources.
3.3 Compozer is a multi-tenant service. Each customer's data is logically isolated, and access is scoped to the authenticated account to prevent cross-account access.
3.4 Access to production infrastructure is restricted to authorised personnel on a need-to-know basis.
3.5 Application secrets and credentials are stored in a dedicated secrets management service, not in source code.
4. Payments
4.1 Payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor. Compozer does not store full payment card numbers on its systems.
5. Subprocessors
5.1 We engage a limited set of third-party subprocessors to provide the Service. A current list is maintained as part of, and kept up to date under, our DPA and is published at compozer.com/trust/subprocessors.
6. Personnel and organisational measures
6.1 Personnel with access to Customer Data are bound by confidentiality obligations.
6.2 Access to Customer Data is limited to what is necessary to operate, support, and improve the Service.
7. Data retention and deletion
7.1 We retain Customer Data for the duration of the customer relationship. On termination, Customer Data is deleted or returned in accordance with our DPA, other than copies held in routine backups, which are deleted in the ordinary course of our backup cycle.
8. Incident response
8.1 We use monitoring and logging across our infrastructure, including AWS and MongoDB Atlas monitoring and audit logs, to help detect potential security incidents, and we receive security notifications from our infrastructure providers.
8.2 We maintain an internal incident response procedure covering how we triage a suspected incident, assess whether Customer Data or personal data was affected, contain and remediate it, notify affected customers, and conduct a post-incident review.
8.3 In the event of a personal data breach affecting Customer Data, we will notify affected customers without undue delay, as set out in our DPA and in accordance with applicable law.
9. Business continuity
9.1 Customer Data is protected by automated, managed database backups to support recovery. Backups are retained on a rolling schedule for up to 12 months.
10. Updates and contact
10.1 We may update this policy to reflect changes in our practices; material changes are reflected by updating the 'last updated' date above. Security questions and reports can be sent to security@compozer.com.