At Cheku, security is foundational — not an afterthought. As a practice management platform handling sensitive audit and accounting data, we take the protection of your information seriously. This page describes how we safeguard your data.
Infrastructure
Cloud Hosting
Cheku is hosted on Supabase, which runs on Amazon Web Services (AWS) infrastructure in the EU-WEST-2 (London, UK) region. This means your data is stored in the United Kingdom, within AWS data centres that meet the highest industry standards for physical and environmental security.
AWS data centres hold certifications including ISO 27001, SOC 1/2/3, and PCI DSS Level 1. For details, see AWS Security.
Data Isolation
Each firm's data is logically isolated using row-level security (RLS) enforced at the database level. This means one firm's data is never accessible to another firm, even though the underlying infrastructure is shared. Data isolation is enforced at the database layer — not just the application layer — providing defence in depth.
Encryption
In Transit
All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher. This includes all API calls, file uploads, and authentication requests. We enforce HTTPS on all endpoints — unencrypted HTTP connections are not accepted.
At Rest
All data stored in our database and file storage is encrypted at rest using AES-256 encryption, managed by AWS. Encryption keys are managed through AWS Key Management Service (KMS) and are never stored alongside the data they protect.
Authentication and Access Control
User Authentication
- Secure password-based authentication with enforcement of strong password requirements.
- Session management with secure, httpOnly cookies.
- Automatic session expiry and refresh token rotation.
Application Access Control
- Role-based access: The platform supports configurable permission levels for staff within a firm.
- Firm-level isolation: Row-level security policies ensure that database queries only return data belonging to the authenticated firm.
Internal Access
- Production database access is restricted to essential personnel only, following the principle of least privilege.
- All administrative access is logged and monitored.
AI Security
Cheku's AI features are powered by models hosted on Microsoft Azure under enterprise agreements.
- Customer Data sent to AI features is processed solely to fulfil your request and return a result.
- No model training: Your data is never used to train, fine-tune, or improve AI models.
- AI processing occurs within Azure's enterprise infrastructure, covered by Microsoft's Data Processing Addendum and security certifications (ISO 27001, SOC 2, etc.).
- Data sent to AI services is encrypted in transit and is not retained by the AI provider after processing.
Payment Security
When paid plans are introduced, all payment processing will be handled by Stripe, a PCI DSS Level 1 certified payment processor. Cheku will never see, store, or have access to your full credit card number or bank details. Payment information will be transmitted directly from your browser to Stripe's secure servers. No payment information is collected during the current beta period.
Data Backup and Recovery
- Automated backups: Our database is continuously backed up with point-in-time recovery capability.
- Backup encryption: All backups are encrypted at rest using AES-256.
- Recovery objective: In the event of data loss, we can restore from backup with minimal data loss (recovery point objective of minutes, not hours).
Incident Response
We maintain a security incident response process that includes:
- Detection — Automated monitoring and alerting for suspicious activity, unauthorised access attempts, and system anomalies.
- Containment — Immediate steps to contain and isolate any confirmed incident.
- Investigation — Root cause analysis to understand the scope and impact.
- Notification — We will notify affected customers within 72 hours of confirming a security incident involving their data, as required by UK GDPR.
- Remediation — Corrective actions to prevent recurrence.
Secure Development
- Code review: All code changes go through peer review before deployment.
- Dependency monitoring: We monitor third-party dependencies for known vulnerabilities and apply security patches promptly.
- Environment separation: Development, staging, and production environments are fully separated. Customer data is never used in development or testing.
Compliance
| Framework | Status |
|---|---|
| UK GDPR | Compliant. Data stored in EU-WEST-2 (London). DPA available for all customers. |
| Australian Privacy Act 1988 | Compliant. Australian Privacy Principles acknowledged in our Privacy Policy. |
| PCI DSS | Payment processing delegated to Stripe (PCI DSS Level 1 certified). |
Responsible Disclosure
If you discover a security vulnerability in Cheku, we ask that you report it responsibly. Please email support@cheku.ai with details of the vulnerability. We will:
- Acknowledge your report within 48 hours.
- Investigate and provide an initial assessment within 5 business days.
- Keep you informed of our progress toward a fix.
- Not take legal action against researchers who report vulnerabilities in good faith and do not exploit them.
Questions
For security-related questions or concerns, contact us at:
DKY Technologies Ltd
Flat 12, 134 Hatfield Road
St Albans, AL1 4HY
United Kingdom
Email: support@cheku.ai