Trust & security
Your data is encrypted in transit and at rest
We follow Australian Privacy Principles (APPs) and use industry-standard TLS + AES-256.
Encryption
- TLS 1.2+ on every page — HSTS preload enabled, no HTTP fallback.
- AES-256 at rest for sensitive fields (email, payment tokens, audit log).
- Bcrypt password hashing with cost 12 — never stored in plain text.
- No card data stored on our servers — payment is handled by Paddle Billing (PCI-DSS Level 1).
Access control
- Role-based — student, admin, super-admin.
- 2FA required for all admin accounts.
- Session timeout after 30 minutes of inactivity.
- Audit log for every wallet, attempt, and payment event (retained 7 years for tax/AUD).
Privacy compliance
PassPilot Education Pty Ltd complies with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). We do not sell or rent personal data. For full details, see our Privacy Policy.
Sub-processors
- Paddle Billing (payments, merchant of record) — Ireland / UK
- Stripe / PayPal (affiliate payouts) — USA
- OpenAI, Anthropic, Google AI, Z.AI, Pollinations (grading) — various regions
- Postmark (transactional email) — USA
Vulnerability disclosure
If you've found a security issue, please email security@passpilot.com.au with:
- URL or component affected
- Steps to reproduce
- Impact assessment (your view)
We aim to acknowledge within 24 hours and triage within 72 hours. Please do not publicly disclose until we've had a chance to fix.
Breach policy
In the event of a data breach affecting personal information, we will notify affected users within 72 hours of discovery (per the Notifiable Data Breaches scheme), and report to the Office of the Australian Information Commissioner (OAIC) as required.