Security
Security
In short
- Hosted in Australia
- The application runs in Vercel's Sydney region and its database is Neon Postgres in Sydney. Document reading, where a company switches it on, is processed in Sydney or Melbourne.
- Encrypted
- Every connection to the application uses HTTPS. The database provider encrypts the data it stores and its backups.
- Signing in
- Passwords are kept only as salted one way hashes, never as the password. Two step sign in with an authenticator app can be turned on in Settings, with backup codes for a lost phone. A session ends after 14 days without use.
- Each account sees only its own
- Every page, export and action checks the signed in account on the server, so an account reaches only its own projects, briefs and files.
- Your data stays yours
- Each brief exports to Word, PDF, DXF and JSON at any time. Download all my data in Settings gives everything an account holds as one file, and Delete my account removes the account and everything in it. We do not sell your data or use it to train AI models.
- AI under your control
- Document reading is off until a company switches it on, sends only the pages an author picks, and keeps only the values the author accepts, never the document. The rules that check a brief never use AI, and every brief can be completed without it.
- Payments through Stripe
- Card details are entered on Stripe's own pages and never reach TworkX.
How documents are handled sets out what document reading sends, where it goes and how long anything is kept.
Who else handles your data
TworkX runs on these services. Each handles only what its part of the service needs.
Vercel
Hosts the application and the website. Every request passes through the application, which runs in Vercel's Sydney region. Vercel keeps short lived request logs (the page asked for, the browser and the response) and the application's settings.
Where: The application runs in Sydney (syd1). Vercel's points of presence around the world take each connection and pass it to Sydney, and Vercel's primary processing facilities are in the United States.
Vercel Data Processing AddendumNeon
The database. Accounts and settings, projects and their site data, briefs, attachments, the usage log and the log of AI use, with its backups.
Where: Sydney, Australia (AWS Asia Pacific, ap-southeast-2).
Neon securityStripe
Payments, invoices, receipts and the billing portal. The subscriber's name, email, billing address, card details and, if given, business name and ABN; the subscription and its invoices. Card details never reach TworkX.
Where: The United States and other countries where Stripe and its service providers operate.
Once billing is switched on.
Stripe Data Processing AgreementResend
Sends the application's email. The address, the subject and the text of each email the application sends: password reset links, website enquiries passed to the business address and the weekly feedback summary.
Where: The United States, where Resend's primary processing takes place.
Resend Data Processing AddendumGoogle Workspace
The business email. Enquiries sent on from the website's forms and correspondence.
Where: Any country where Google or its subprocessors have facilities.
Google Cloud Data Processing AddendumAmazon Web Services (Amazon Bedrock)
Reads the document pages an author chooses to send. Only the pages chosen, for the time it takes to read them. TworkX keeps the values the author accepts and their page references, never the pages.
Where: Sydney or Melbourne, Australia, through the Australian inference profile.
Only where document reading is switched on for the account.
Amazon Bedrock data protectionAnthropic
Writes the AI explanations of the library's questions. The question's text from the library, with the brief's state or territory and, for a formwork brief, the design standard selected. No other project data and no personal information.
Where: Outside Australia, including the United States.
Where AI explanations are set up.
Anthropic Commercial Terms
Report a security problem
If you think you have found a security problem in TworkX, please tell us at team@tworkx.com.au. Say what you found, how to see it again and how to reach you.
Please do not open, change or delete information that is not yours, and do not slow or interrupt the service, to show a problem. Give us a reasonable time to put it right before telling anyone else. We will confirm we have your report and keep you told what we are doing about it.
The same address is in /.well-known/security.txt, the usual place to find it.
More detail
- Data handling: what document reading sends, where and for how long.
- Privacy policy: the personal information we hold, why, and how long we keep it.
- Terms of use: your data, what we may do with it, and closing an account.
- Companies reviewing TworkX for security or procurement can ask us for our answers to the usual questions at team@tworkx.com.au.
Updated 7 October 2026.