Security & data protection

Your invoice data, looked after properly

Invoice Harbour handles sensitive financial and client information for Australian care providers. We treat that data with the same care you give the people you support: encrypted, access-controlled, hosted onshore, and handled in line with the Privacy Act.

How we protect your data

Security built into every layer

Encrypted everywhere

Your data is encrypted with TLS 1.2 or higher as it travels, and with AES-256 while it is stored, so it is protected both where it sits and as it moves.

Access on a need-to-have basis

Role-based access controls limit who can see what, and multi-factor authentication protects every account from compromised passwords.

Stored and processed in Australia

Invoice Harbour’s database and backups run on AWS in Sydney, and the application runs in the Sydney region. Your data, and your clients’ data, is stored and processed in Australia.

Continuous backups

Data is continuously backed up across AWS Sydney availability zones, so it survives a hardware failure without losing your work.

Monitored and tested

We monitor the platform for performance and security, and run regular vulnerability assessments so issues are found and fixed.

Privacy Act compliant

We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, with no advertising cookies and no selling of data.

Onshore by design

Australian data, hosted in Australia

Care providers handle some of the most sensitive information there is: client names, service details, and the financial records behind them. Where that data lives matters.

Invoice Harbour stores your data and backups on Amazon Web Services infrastructure in Sydney, and runs its application in the Sydney region, so your data, and the data of the clients you support, is stored and processed in Australia. It is encrypted at rest with AES-256 and in transit with TLS 1.2 or higher, so it is protected both where it sits and as it moves.

Privacy & retention

You stay in control of your data

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. We use only essential and analytics cookies, never advertising cookies, and we do not sell your data.

While your account is active, your invoice files, extracted data and audit logs are kept for the life of the account. If you leave, we delete or anonymise your data within 30 days, unless the law requires us to keep it longer.

For the full detail on what we collect, why, and how we handle it, see our Privacy Policy.

Frequently asked

Security questions, answered

Where is our data stored?

Your data and its backups are stored on Amazon Web Services infrastructure in Sydney, across multiple Sydney availability zones, and the Invoice Harbour application runs in the Sydney region. Your data is stored and processed in Australia.

Who can see our invoices and client data?

Access is governed by role-based controls, so people in your organisation only see what their role allows. On our side, access to customer data is restricted to the staff who need it to operate and support the platform, and every account is protected by multi-factor authentication.

Any third-party providers that help us host or process data are bound by confidentiality and security obligations at least as protective as the ones in our own Terms of Service.

What happens to our data if we leave?

While your account is active, your invoice files, extracted data and audit logs are retained for the lifetime of the account. After you close your account, we delete or anonymise your data within 30 days, unless a longer period is required by law. System logs may be kept for up to 12 months for security and accounting purposes.

How do you protect against unauthorised access?

Data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256), access is limited by role and protected with multi-factor authentication, and we run regular vulnerability assessments and remediation. We also monitor the platform continuously for security and diagnose errors as they arise.

How do I report a security concern?

If you believe you have found a vulnerability or have a security question, please email security@invoiceharbour.com.au with the details. We take every report seriously and will respond as quickly as we can.

Questions about security?

We are happy to walk your team through how Invoice Harbour protects your data. Book a demo, or email us with any security questions.