Security and data residency are central to how Convena serves Australia organisations. This page summarises our hosting, encryption, access controls, and compliance posture. For privacy-specific rights and data handling, see our Privacy Policy.
Data hosting
Data hosted in Australia. We do not transfer customer data offshore for processing unless required to deliver an integrated service you enable (for example payment processing via Stripe) or where you provide explicit consent.
Australian customer data remains in Australia. We select infrastructure providers with strong physical and logical security controls appropriate for membership and payment data.
Encryption
- In transit: All connections to Convena use TLS 1.3 (or the current industry-standard minimum) to encrypt data between your browser or integrations and our servers.
- At rest: Customer data stored in our databases and object storage is encrypted using AES-256 or equivalent provider-managed encryption.
Secrets and credentials are stored in dedicated secret management systems, not in source code or application logs.
Access controls
We limit who can access production systems and customer data:
- Two-factor authentication (2FA) is available for organisation administrators and required for Convena staff accessing production environments.
- Role-based access control (RBAC) within the Convena app lets your organisation assign permissions by role (for example treasurer vs. committee member).
- Audit logs record significant administrative actions to support accountability and incident investigation.
Backups
We perform automated daily backups of production databases. Backups are retained for 30 days and stored encrypted separately from primary systems. Restore procedures are tested periodically as part of our operational readiness.
Compliance
Convena is designed to support organisations operating under Australia regulations, including:
- Privacy Act 1988 — privacy-by-design practices, data access processes, and contractual terms with subprocessors.
- Spam Act 2003 — tools and guidance to help customers send lawful commercial electronic messages with appropriate consent and unsubscribe mechanisms.
- PCI-DSS (via Stripe) — card payments are processed by Stripe; Convena does not store full card numbers on our servers.
Vulnerability disclosure
If you discover a security vulnerability in Convena, please report it responsibly to security@convena.com.au. We commit to acknowledging reports within 48 hours and will work with you to understand and remediate verified issues. Please do not publicly disclose vulnerabilities until we have had a reasonable opportunity to address them.