Trust & Security

Last updated: 3 July 2026

Our commitment

Panaptic is built and operated by Panaptic Pty Ltd (ACN 625 971 075), an Australian company. Security and privacy are core to how we build the platform. This page summarises the practices we use to protect your data and how we handle it.

Data hosting and residency

Panaptic is hosted on Google Cloud. Your core application data - the connections, tasks, data spaces, and content you create - is stored and processed in Australia.

Some features rely on third-party providers located outside Australia. Where you use AI features, relevant content is sent to the AI providers listed under Sub-processors for processing. Payment and transactional email are also handled by overseas providers. We list every such provider below so you know where your data may travel.

Encryption

  • In transit: all traffic to and within the platform is encrypted using TLS 1.2 or higher.
  • At rest: all data is encrypted using AES-256 (Google Cloud default encryption). The credentials you store for external connections are additionally encrypted at the application layer with a separate key.

Access control

Access to production systems is limited to the small number of staff who need it to operate and support the service. We enforce multi-factor authentication, grant access on a least-privilege basis, and remove access promptly when a team member changes role or leaves.

Application security

  • Code is reviewed before it is deployed to production.
  • Deployments are built through an automated pipeline into containerised, access-controlled environments.
  • We monitor our dependencies and update them in response to known vulnerabilities.

We have not yet engaged an independent third party for penetration testing. We intend to do so as we grow, and will update this page when we do.

Availability and backups

Our production database runs in a multi-zone, high-availability configuration within the Sydney region. It is backed up automatically every day, with backups retained and encrypted in the same region, and we run continuous backups that allow point-in-time recovery to any moment within the recovery window. We actively monitor the health and performance of the platform and alert our operations team to issues. We do not currently publish a formal uptime target.

Sub-processors

We use the following third parties to deliver the service. Your data may be processed by them in the course of providing specific features.

Sub-processor Purpose Location
Google Cloud Hosting, storage, database Australia (Sydney)
Stripe Payment processing United States / global
Resend Transactional email delivery United States
Cloudflare Edge security and bot protection Global
Anthropic, OpenAI, Google Cloud (Vertex AI) AI model processing for AI features United States / global

We review this list regularly and will update it when it changes.

Privacy

We handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth). Our Privacy Policy explains what we collect, how we use it, and who we share it with. You can request access to, correction of, or deletion of your personal information by contacting us at privacy@panaptic.ai.

Incident response and breach notification

We maintain an incident response process for identifying, investigating, and responding to security events. We comply with the Notifiable Data Breaches scheme and will notify affected customers and the Office of the Australian Information Commissioner where required, without undue delay.

Responsible disclosure

If you believe you have found a security vulnerability, please email security@panaptic.ai. We will acknowledge your report within five business days and keep you updated as we investigate. We will not pursue or support legal action against researchers who act in good faith, avoid privacy violations and service disruption, and give us a reasonable opportunity to respond before disclosing publicly. We appreciate responsible disclosure.

Compliance and roadmap

We are an early-stage company and aim to be straightforward about where we are. We are working towards alignment with the ACSC Essential Eight and are maturing our security practices as we grow. We do not currently hold formal security certifications. If that changes, we will say so here.

Contact

For security questions, questionnaires, or to request further documentation under NDA, contact security@panaptic.ai. We are happy to support your procurement and due-diligence process.