This document is in draft. It has been prepared ahead of independent legal review and is published so you can see exactly what we intend to commit to. It takes effect on 14 September 2026. If anything here matters to a decision you are making, ask us and we will confirm it in writing.
Security at Grace
- Provider: Egan, Michael (ABN 37 317 577 102), trading as Strategic Worlds
- Effective date: 14 September 2026
- Last updated: 31 August 2026
- Contact: support.grace@strategicworlds.com.au
Grace helps organisations reach and maintain ISO 9001 and ISO 27001 compliance, so we hold our own platform to a high security standard. This page summarises the measures we take to protect your data. It is a summary, not a contract; our binding commitments are in the Terms of Service and the Data Processing Addendum.
Tenant isolation
Each customer's workspace is logically isolated. Data access is enforced at the database layer using row-level security, so a request scoped to one workspace cannot read or write another's data. The application connects to the database as a least-privilege role that is itself subject to those security policies.
Access, identity and authentication
- Authentication is handled by a specialist managed identity provider (Clerk), so we never store your password.
- Multi-factor authentication is available.
- Access within a workspace is governed by role-based access control — each user only sees and does what their role grants, and workspace administrators manage roles and membership.
- Access to a workspace requires verified membership of that workspace's organisation.
- One Grace operator account ("Grace Admin") holds every permission in workspaces it belongs to. This exists so we can support you and recover your data, and it is the only exception to the rule above. It is set from our own environment and cannot be changed from within your workspace — but it is listed in your Members & roles page like any other member, and everything it does is recorded in your activity log under its own name. It cannot bypass change control: an approved document or process is locked for it exactly as it is for you.
Data protection
- In transit: all traffic is encrypted over HTTPS/TLS, with HSTS enforced.
- At rest: data is stored with our infrastructure providers' encryption at rest.
- Data residency: the primary application database and file storage are hosted in Australia (Sydney). Some supporting services operate overseas — see Sub-processors.
Application and infrastructure security
- Security response headers and a Content Security Policy.
- Audit logging and append-only assessment history, so compliance activity is traceable.
- A managed, serverless hosting platform with routine patching of the underlying infrastructure.
- Dependency and supply-chain hygiene: automated dependency updates and a continuous-integration check that fails the build on high-severity vulnerabilities.
Data handling and privacy
We process personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You own your data; we process it only to provide the Service. See the Privacy Policy and Data Processing Addendum.
Data breach response
We maintain processes to detect, assess and respond to security incidents. If an incident is likely to result in serious harm, we assess it and, where it is an eligible data breach, notify the OAIC and affected individuals under the Notifiable Data Breaches scheme, and notify affected customers so they can meet their own obligations.
Business continuity
Customer data is hosted on managed infrastructure (Vercel and Neon) and relies on those providers' built-in redundancy. Deleted records are retained and restorable rather than destroyed immediately.
We do not yet publish a backup cadence, retention period, or recovery-time objective. We will state those before onboarding a customer under a paid agreement, and we would rather say so than quote figures we have not tested a restore against.
Reporting a vulnerability
If you believe you have found a security issue, please contact support.grace@strategicworlds.com.au. We appreciate responsible disclosure and will work with you to resolve verified issues promptly.
Certifications and roadmap
Grace is software that helps you implement ISO 9001 and ISO 27001 controls; this does not by itself mean Grace is certified. Grace holds no independent security certification or attestation, and we do not claim one. If that changes we will say so here.