Security & Privacy

What we collect, what we don't, where it lives, and what to do if something looks wrong.

What we store

  • Account data — email address, hashed password (bcrypt), subscription status, created/updated timestamps.
  • Verification cases — ABN searched, entity name, selected checks, check results (public register data only), assurance score, watermark code, timestamps. Cases are linked to your account.
  • Phone verification records — call scheduling data, Twilio call ID, transcript (when available), parsed result. No actual audio is retained after transcript extraction.
  • Payment records — transaction reference, amount, product purchased, timestamp. We do not store card numbers. Card processing is handled by eWAY; their PCI DSS certification covers card data.
  • Usage logs — server access logs retained for 90 days for security and debugging purposes.

What we never store

  • Full card numbers, CVV codes, or unmasked PANs — these go to eWAY only.
  • Bank account numbers or BSB combinations you enter for verification — these are checked against the register and discarded; they are not persisted.
  • Third-party authentication tokens (Google, LinkedIn) — Gumshoe does not use OAuth sign-in.
  • Raw IP addresses associated with individual searches beyond the standard 90-day server log window.
  • Data sourced from government registers beyond what is required to display your verification result. We do not build profiles on individuals.

Where your data lives

Gumshoe is self-hosted in Australia on Oracle Cloud Infrastructure (OCI), Melbourne region. Your data does not leave Australia except where third-party services are involved:

  • Twilio (phone verification) — call metadata may be processed in the US per Twilio's data processing agreement.
  • Google Places API — business address lookups for phone cross-reference. Query parameters only (no account data).
  • eWAY — payment processing. PCI DSS Level 1 certified. Card data does not touch our servers.

Encryption

  • All traffic over HTTPS/TLS 1.2+. HSTS enforced.
  • Passwords hashed with bcrypt (cost factor 12).
  • Database connections encrypted in transit.
  • Backups encrypted at rest on OCI Block Storage.

Government data provenance

Gumshoe sources data from the following Australian government registers. These are public records — we display them, we do not create them.

RegisterSourceLicence
Australian Business Register (ABR)ATO / ABRCC BY 3.0 AU
ASIC Companies & Business NamesASICCC BY 3.0 AU
Personal Property Securities RegisterAFSAPublic
Insolvency registerAFSAPublic
FWO enforcement registerFair Work OmbudsmanPublic
ACCC enforcement registerACCCPublic
Superannuation fund registerAPRA / ATOPublic
Charities registerACNCCC BY 4.0
AusTender contractsFinanceCC BY 4.0
Modern Slavery statementsDIBPPublic
WGEA employer reportsWGEACC BY 4.0
Tax Transparency disclosuresATOPublic
BSB directoryAustralian Payments NetworkLicensed

Analytics

Gumshoe uses Umami, a privacy-friendly analytics platform self-hosted in Australia. Umami does not use cookies, does not fingerprint visitors, and does not share data with third parties. No ad networks or tracking pixels are used on this site.

Responsible disclosure

If you find a security vulnerability in Gumshoe, please report it to security@gumshoe.au. We will acknowledge your report within 2 business days and keep you updated on our response. We do not pursue legal action against researchers acting in good faith.

Please do not publicly disclose a vulnerability before we have had a reasonable opportunity to address it (90 days is our standard).

Disputes and corrections

If a business believes a Gumshoe verification result is incorrect, see our disputes and corrections page.