SOC 2 Type II
In progressWorkshop Wrench is on the SOC 2 Type II certification path. Our controls architecture — access management, logging, change management, and incident response — is being audited by a third-party assessor.
Loading
Customer PII, vehicle history, financial records, and payment data. Here is what Workshop Wrench does to protect it — and what we are honest about not having yet.
Controls that are live in the product today — no security theatre, no unverified claims.
Workshop Wrench is on the SOC 2 Type II certification path. Our controls architecture — access management, logging, change management, and incident response — is being audited by a third-party assessor.
All customer data — repair order records, customer PII, financial records, and vehicle history — is encrypted at rest using AES-256. Database-level encryption is enforced at the storage layer.
All traffic between client and server is encrypted using TLS 1.3 with strict HSTS headers enforced. Older TLS versions (1.0, 1.1) are rejected. Certificate management is handled by Cloudflare.
Short-lived JWT Bearer tokens with HttpOnly cookie dual-mode auth. Tokens expire after 24 hours. Refresh tokens are rotated on each use. All API routes are protected by the JWT guard.
API endpoints are protected by adaptive rate limiting via the NestJS throttler module backed by Redis. Login endpoints have stricter limits (5 attempts / 15 minutes). Cloudflare DDoS protection is active at the edge.
Every state change, permission grant, financial operation, and login event is recorded in an append-only audit log. Logs are exportable as CSV and retained for 12 months as standard.
Six granular roles — Owner, Manager, Advisor, Technician, Parts, and Viewer — enforced at both the API and UI layers. Staff can only see and act on what their role permits. Roles are fully audited.
TOTP-based MFA (Google Authenticator, Authy, 1Password) is on the near-term roadmap. SMS OTP is available as an interim step for account recovery. Enterprise plans can request early access to the MFA preview.
99.9%
Uptime SLA
Monthly uptime SLA for all Production plan customers. Status history published at status.workshopwrench.com.au.
Penetration Testing
ScheduledAnnual third-party penetration test by an IRAP-certified assessor. Results shared with Enterprise customers under NDA on request.
AU Data Residency
LiveAll data stored and processed in AWS Sydney (ap-southeast-2). No cross-region replication to non-AU regions without explicit tenant consent.
Australian compliance
Workshop Wrench is designed and operated in compliance with the Australian Privacy Act 1988 and all 13 Australian Privacy Principles. Customer data is handled lawfully, with transparency, and solely for legitimate workshop-management purposes.
Honest answers. If something is not yet complete, we say so.
All customer data — repair orders, customer PII, vehicle history, invoices, and communications — is stored exclusively in the AWS Sydney region (ap-southeast-2). Your data never leaves Australian jurisdiction. Daily encrypted backups are retained for 30 days in the same region.
SOC 2 Type II is in progress. Our controls architecture — access management, audit logging, change management, and incident response — has been designed to meet SOC 2 requirements and is currently being assessed by a third-party auditor. Enterprise customers can request an architecture review while the audit is in progress.
Every database query is scoped by a tenantId guard enforced at the NestJS service layer. A tenant can never read or write data belonging to another tenant. This is tested in our integration test suite on every CI run. Role-based access control (RBAC) is enforced at both the API and UI layers for staff role isolation within a tenant.
Workshop Wrench has a documented incident response procedure. In the event of a confirmed breach affecting personal information, affected workshop owners and the Office of the Australian Information Commissioner (OAIC) are notified within 72 hours, consistent with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988.
Workshop Wrench takes security vulnerabilities seriously. If you discover a potential security issue — including authentication bypasses, data exposure, injection vulnerabilities, or broken access control — we encourage responsible disclosure. Please report findings to [email protected] with a clear description of the issue and reproduction steps. We aim to acknowledge all reports within one business day and will keep you informed of our progress. We do not pursue legal action against good-faith security researchers acting within these guidelines.
Disclosure guidelines
Enterprise buyers can request an architecture review, penetration test report, and information about private deployment options.