Live · Trust Centre

Trust Centre

Everything you need to satisfy yourself — or your firm's risk committee — that STEADCALM is safe to trust with your household's most sensitive paperwork.

Current posture

  • Post-quantum key exchange (ML-KEM-768, FIPS 203) · On the roadmap
  • AES-256-GCM data-at-rest · Enabled
  • TLS 1.3 minimum · Enforced
  • Client-side zero-knowledge vault keys · On the roadmap
  • Row-level access control on every record · Enforced
  • Passkey / WebAuthn MFA · Available; required for admin
  • Australian data residency · Enforced

Compliance

  • Australian Privacy Act 1988 (APPs) · Compliant
  • SOC 2 Type II · In progress
  • ISO/IEC 27001 · Roadmap
  • APRA CPS 234 aligned control set · Compliant

Sub-processors

We publish and version the full sub-processor list. All are Australian-region where offered and contractually bound to APP-equivalent standards. Contact us for the current PDF.

Incident history

No material security incidents to date. We commit to publishing material incidents within 72 hours, per our Data Ethics Charter.

Contact

  • Security: security@steadcalm.com
  • Privacy: privacy@steadcalm.com
  • Support: hello@steadcalm.com