Security
Security at Rand
How we protect your most sensitive business data
- Read-only integrations
- Database in Sydney
- Encrypted in transit and at rest
- Isolated per organisation
- Never used to train AI
- Key actions logged
Infrastructure
Integration credentials receive an additional layer of AES-256-GCM authenticated encryption before storage.
Our infrastructure is hosted on Vercel (application) and Supabase (database, Sydney region), which provide automatic HTTPS, TLS encryption in transit, edge network distribution, and DDoS protection.
Telemetry and session replays. We use Sentry (US) for error and performance monitoring and PostHog (EU region) for product analytics. Session replays are sampled (a small percentage of sessions) and configured to mask all input values and on-screen text before capture. Error reports strip access tokens from request logs.
Access control
Your data is isolated at the database level. Row-level security policies enforce tenant isolation on every table, ensuring one organisation’s queries cannot return another organisation’s rows.
- Role-based access controls with distinct permissions for owners, administrators, finance users, members, viewers, and expert reviewers.
- Expert reviewers can only access organisations they are explicitly assigned to.
- Connected tool integrations use fine-grained permissions where available. GitHub connects via a GitHub App with read-only access and no user OAuth tokens. Other integrations use read-only OAuth scopes with CSRF protection.
- Sign in with email, Google or Xero. Multi-factor authentication is on our roadmap.
- A small number of Rand staff have administrative access to support your account.
What we access from your tools
When you connect an integration, we access the minimum data needed to identify R&D activity:
- GitHub
- Connected via a GitHub App with read-only permissions. We access pull request titles, descriptions, commit messages and metadata, and each repository's README. We never read source code.
- Jira
- Issue fields, descriptions, changelog, worklogs, up to 20 recent comments, and attachment names. We never read attachment contents. Read-only access.
- Linear
- Issue titles, descriptions, status changes, comments, attachment links, and assignee and creator emails. Read-only access.
- Slack
- Messages in channels you explicitly connect. We do not access files, attachments, or DMs.
- Notion
- Page titles and text content from pages you grant access to. We do not access your entire workspace.
- Xero
- Employee and payroll records, plus bills, spend transactions, the chart of accounts, the profit and loss report and fixed assets, used to calculate R&D expenditure. Read-only access. We never write to Xero.
You can disconnect any integration at any time from Settings.
AI & data processing
- Your data is never used to train AI models. Rand uses commercial AI APIs that do not train models on your inputs. Your data is not accessible to the AI providers’ other customers, and is not retained beyond what is needed for the request and the provider’s standard safety-review window.
- All AI output is validated against strict schemas before being stored. Malformed responses are rejected.
- AI drafts are never auto-confirmed. Every AI-generated suggestion requires human approval before becoming part of your claim.
- Confidence scores and risk assessments are always visible so you can make informed decisions.
Audit trail
Key actions in Rand are recorded in an activity log. Your team cannot edit or delete its entries.
- Drafts, approvals, allocations and other key changes to your claim are logged with who made them and when.
- A copy of the activity log is available on request.
Human review
Every R&D Tax Incentive claim prepared through Rand is reviewed by an Expert Reviewer. AI assists with drafting, but humans make the final decisions.
- Expert reviewers are assigned to specific organisations; they cannot see data from other clients.
- You can see who your Expert Reviewer is in the app.
- AI suggestions stay proposals until a person approves them, and the Expert Reviewer approves the final claim.
Data lifecycle
- Disconnect and purge
- Disconnect any integration at any time from Settings, and optionally remove its imported evidence from draft years.
- Account deletion
- Self-service account deletion is available from Settings. It removes your login and profile, and activity log entries no longer link to you.
- Financial records
- We aim to keep financial records for at least 5 years, in line with ATO record-keeping requirements.
Questions?
If you have questions about how we handle your data, contact us:
Rand Advisory Pty Ltd (ABN 75 696 205 660)
Email: support@randadvisory.com.au
Melbourne, Victoria, Australia