Security Information
Last updated: 14th August 2025
1. Data Encryption
All data transmitted between your device and our servers is encrypted using industry-standard SSL/TLS protocols.
2. Secure Storage
Your personal information is stored on secure servers with restricted access and regular security audits.
3. Account Security
We recommend using strong, unique passwords and keeping your account information confidential.
4. Regular Updates
Our security measures are regularly reviewed and updated to protect against emerging threats.
5. Incident Response
In the unlikely event of a security breach, we have procedures in place to respond quickly and notify affected users.
6. Third-Party Security
We carefully vet all third-party services and ensure they meet our security standards before integration.
7. Reporting Security Issues
If you discover a security vulnerability, please report it immediately to support@cluckyspns.com.
8. Technical Safeguards
- Encryption: AES-256 encryption for data at rest, TLS 1.3 for data in transit
- Authentication: Multi-factor authentication for administrative access
- Access Controls: Role-based access with principle of least privilege
- Monitoring: 24/7 security monitoring and intrusion detection systems
- Backups: Encrypted daily backups with offline storage
9. Physical Security
Our servers are hosted in SOC 2 Type II certified data centers with biometric access controls, 24/7 physical security, environmental monitoring, and redundant power systems.
10. Employee Security
All employees undergo background checks and mandatory security training. Access to personal data is strictly limited to authorized personnel on a need-to-know basis.
11. Penetration Testing
We conduct quarterly penetration testing by independent security firms and immediately address any vulnerabilities discovered during these assessments.
12. Security Certifications
Our security infrastructure maintains compliance with ISO 27001, SOC 2 Type II, and follows NIST Cybersecurity Framework guidelines.
13. Compliance
Our security practices comply with relevant Australian and international data protection regulations including the Australian Privacy Act, GDPR, and PCI DSS standards where applicable.