- Where is data hosted?
- Database, sign-in and files: Supabase, in the AWS West EU (Ireland) region. Application server: Vercel, Dublin region. Email: Resend, EU (Ireland) sending region. Public pages hold no client data and are served from Vercel's global network.
- Who can get in?
- Only people a business invites; public sign-up is switched off. Each person has a role (owner, admin or staff). Row level security in the database keeps each business's records to its own members, and the firm's staff cannot open a business's requests or files through the Suite unless the business adds the firm as a member.
- How do people sign in?
- With a one-time link or 6-digit code sent to their email, which works once and expires in an hour. There are no passwords to leak or reuse. Because the email inbox is the key, we recommend multi-factor sign-in on every email account that uses the Suite.
- Is data encrypted?
- Yes, in transit (TLS 1.2 and 1.3 only, HSTS) and at rest (AES-256, as stated by Supabase, Vercel and Resend). Xero connections are additionally encrypted by the Suite with AES-256-GCM. Details.
- What is logged?
- Every action on a request is logged on its timeline. Account actions (people, roles, invitations, package changes, exports, deletions) go to an audit log that cannot be edited, readable by owners and admins. Actions taken through the Concierge assistant are logged with that source.
- How are uploaded files handled?
- Files are kept in private storage, readable only by members of the business that owns them. Files sent through request links arrive through server-issued signed links, are limited by type and size, and download as attachments rather than opening in the browser.
- What if there is a breach?
- Under our data processing agreement M.A. Whately tells the affected business within 48 hours of becoming aware of a personal data breach, with what is known, and helps with any report to the Data Protection Commission.
- Retention, deletion and export
- Each business sets how long finished requests are kept (3 to 84 months, 24 by default); the daily job then deletes them with their files. Concierge conversations are deleted after 30 days. Owners and admins can download all data at any time. If you leave.
- Is AI used, and on what?
- Only where a business uses it: reading photos and scans of bills, and the Concierge assistant. Requests go to Anthropic's API, which under its Commercial Terms may not train on them. A person approves anything that is sent, posted or filed. The rules.
- How is the code tested?
- An adversarial security review on 23 September 2026 led to fixes, each with a regression test. The backend checks (232 on 1 October 2026) cover isolation between businesses, the firm's no-access rule, link scoping, upload confirmation and paused accounts.
- Certifications
- M.A. Whately itself does not hold an information security certification such as ISO 27001 or SOC 2. The providers that host the Suite do; their reports are listed below, as each provider states them.
- Administrative access
- As with any hosted service, the people who run the Suite's infrastructure can reach the database outside the application. The data processing agreement governs that access, and keys that can reach all data are kept on the server and never sent to a browser.
Certifications belong to each provider, not to M.A. Whately; the wording is the provider's, from the pages linked. Ask for our data processing agreement for the full list with transfer safeguards.