Menu

Security

Security

How TworkX looks after the information you put into it, who else handles it, and how to tell us about a security problem.

In short

Hosted in Australia
The application runs in Vercel's Sydney region and its database is Neon Postgres in Sydney. Document reading, where a company switches it on, is processed in Sydney or Melbourne.
Encrypted
Every connection to the application uses HTTPS. The database provider encrypts the data it stores and its backups.
Signing in
Passwords are kept only as salted one way hashes, never as the password. Two step sign in with an authenticator app can be turned on in Settings, with backup codes for a lost phone. A session ends after 14 days without use.
Each account sees only its own
Every page, export and action checks the signed in account on the server, so an account reaches only its own projects, briefs and files.
Your data stays yours
Each brief exports to Word, PDF, DXF and JSON at any time. Download all my data in Settings gives everything an account holds as one file, and Delete my account removes the account and everything in it. We do not sell your data or use it to train AI models.
AI under your control
Document reading is off until a company switches it on, sends only the pages an author picks, and keeps only the values the author accepts, never the document. The rules that check a brief never use AI, and every brief can be completed without it.
Payments through Stripe
Card details are entered on Stripe's own pages and never reach TworkX.

How documents are handled sets out what document reading sends, where it goes and how long anything is kept.

Who else handles your data

TworkX runs on these services. Each handles only what its part of the service needs.

  • Vercel

    Hosts the application and the website. Every request passes through the application, which runs in Vercel's Sydney region. Vercel keeps short lived request logs (the page asked for, the browser and the response) and the application's settings.

    Where: The application runs in Sydney (syd1). Vercel's points of presence around the world take each connection and pass it to Sydney, and Vercel's primary processing facilities are in the United States.

    Vercel Data Processing Addendum
  • Neon

    The database. Accounts and settings, projects and their site data, briefs, attachments, the usage log and the log of AI use, with its backups.

    Where: Sydney, Australia (AWS Asia Pacific, ap-southeast-2).

    Neon security
  • Stripe

    Payments, invoices, receipts and the billing portal. The subscriber's name, email, billing address, card details and, if given, business name and ABN; the subscription and its invoices. Card details never reach TworkX.

    Where: The United States and other countries where Stripe and its service providers operate.

    Once billing is switched on.

    Stripe Data Processing Agreement
  • Resend

    Sends the application's email. The address, the subject and the text of each email the application sends: password reset links, website enquiries passed to the business address and the weekly feedback summary.

    Where: The United States, where Resend's primary processing takes place.

    Resend Data Processing Addendum
  • Google Workspace

    The business email. Enquiries sent on from the website's forms and correspondence.

    Where: Any country where Google or its subprocessors have facilities.

    Google Cloud Data Processing Addendum
  • Amazon Web Services (Amazon Bedrock)

    Reads the document pages an author chooses to send. Only the pages chosen, for the time it takes to read them. TworkX keeps the values the author accepts and their page references, never the pages.

    Where: Sydney or Melbourne, Australia, through the Australian inference profile.

    Only where document reading is switched on for the account.

    Amazon Bedrock data protection
  • Anthropic

    Writes the AI explanations of the library's questions. The question's text from the library, with the brief's state or territory and, for a formwork brief, the design standard selected. No other project data and no personal information.

    Where: Outside Australia, including the United States.

    Where AI explanations are set up.

    Anthropic Commercial Terms

Report a security problem

If you think you have found a security problem in TworkX, please tell us at team@tworkx.com.au. Say what you found, how to see it again and how to reach you.

Please do not open, change or delete information that is not yours, and do not slow or interrupt the service, to show a problem. Give us a reasonable time to put it right before telling anyone else. We will confirm we have your report and keep you told what we are doing about it.

The same address is in /.well-known/security.txt, the usual place to find it.

More detail

  • Data handling: what document reading sends, where and for how long.
  • Privacy policy: the personal information we hold, why, and how long we keep it.
  • Terms of use: your data, what we may do with it, and closing an account.
  • Companies reviewing TworkX for security or procurement can ask us for our answers to the usual questions at team@tworkx.com.au.

Updated 7 October 2026.