Trust and security

Data Security Summary

Last updated 3 August 2026 · Proposed summary for the marketing-site scope.

This proposed summary describes the intended boundaries of the ClientSupply marketing website. It is not a certification, audit report or claim that internet systems are risk-free.

ClientSupply is operated by Leveriano Habiyambere, ABN 99 286 419 439.

Website and JobDesk boundary

The production candidate does not expose public product registration, login, customer dashboards, hosted database writes, checkout, subscriptions, billing controls or payment webhooks.

The website now also provides self-service JobDesk registration. Registering creates an organisation workspace and an owner account, requires email verification before sign-in, and grants time-limited evaluation access. No payment is taken and no live billing is enabled in this phase.

Passwords are stored only as one-way hashes. Session, verification, password-reset and invitation tokens are stored only as one-way hashes. Organisation data is separated per organisation and re-authorised on every request.

Enquiry handling

The request-access page does not contain a form, send data to ClientSupply or store enquiry content. Its email link asks the visitor’s own email app to open a pre-addressed draft. The visitor decides whether to send that message.

Email delivery

The initial marketing release includes no server-side email function. Access requests and customer-service enquiries use the governance email shown on the website and are sent only through the visitor’s chosen email service.

Payment information

The marketing website does not request or collect card numbers, security codes, bank details or payment-provider credentials. No public payment path is included in the proposed production artifact.

Published surface

The production artifact is generated from an explicit allowlist. Retired campaign pages and related functions, internal interfaces, owner tools, preview pages, synthetic harnesses, billing functions and scheduled monitoring functions are excluded from that artifact.

Transport and browser controls

The proposed deployment uses HTTPS through the hosting provider and includes restrictive browser security headers, a same-origin content policy, clickjacking protection and limited browser permissions.

Operational limits

Security depends on correct configuration, provider controls and ongoing maintenance. This summary does not claim formal certification, guaranteed availability, complete immunity from attack or production readiness of internal JobDesk application functions.

Report a concern

Send security or privacy concerns to leveriano@clientsupply.com.au. Do not include passwords, authentication secrets or payment information.