Security & governance
How Platfirm handles customer data, sub‑processors and hosting.
This page summarises Platfirm AI’s security posture across the corporate site and its operated products. Full product‑specific detail for CabRank lives at cabrank.legal/security ↗.
Sub‑processors
Third‑party services Platfirm uses to operate the corporate site and its products. This list is maintained as a single source of truth across the platfirm.ai / cabrank.legal / legal‑hotline.com properties.
| Provider | Purpose | Region | Data class | Applies to |
|---|---|---|---|---|
| Cloudways (DigitalOcean) | Application hosting | AU · Sydney | Site content + product data | All sites |
| Cloudflare | DNS · CDN · WAF | Global edge | Request metadata only | All sites |
| Postmark | Transactional email | US | Email content + addresses | CabRank, GTC |
| Platfirm AI | Voice AI receptionist | AU · Sydney | Voice transcripts | CabRank AI Partner tier |
| Stripe | Billing & payments | AU + Global | Payment metadata | CabRank |
| Sentry | Error monitoring | EU | Application errors (PII scrubbed) | All sites |
| Plausible | Analytics (cookieless) | EU | Aggregated page hits | platfirm.ai |
Practices
Engineering practices
- Access control SSO + 2FA on all production tooling. Least‑privilege role model.
- Backups Daily encrypted off‑site backups, 30‑day retention.
- Disclosure Coordinated disclosure via security@platfirm.ai. 48‑hour acknowledgement target.
- Incident response Customer notification within 72 hours of confirmed material incident.
- Dependency hygiene Composer/npm audit on every build; security advisories patched within 7 days.
Contact
Reporting & enquiries
Security disclosure
security@platfirm.ai
Partner reviews
admin@platfirm.ai
Full product detail
cabrank.legal/security ↗
Last reviewed 12 May 2026. Next review due Q3 2026.