Sydney core hosting
The core application and PostgreSQL database services are hosted in Sydney, Australia.
Opening Workshop HQ
Loading your workspace…
Workshop records contain personal information, vehicle history, customer decisions and commercial data. Here is the current Workshop HQ control set, its hosting position and a practical way to verify each statement.
The core application and PostgreSQL database services are hosted in Sydney, Australia.
Individual accounts, workshop and role boundaries, MFA controls and narrow customer access protect the platform.
Important changes create timeline or audit records, and migration workflows preserve review and rollback context.
Current controls
These are implementation statements, not a substitute for your own risk review. We do not claim an external security certification on this page.
Workshop users sign in with an individual account tied to a workshop and role. Owner, reception, advisor and technician workflows are permission-aware.
How to verify: Use representative roles to test settings, financial information, repair orders, inspections and technician assignments.
Workshop HQ supports authenticator-code MFA, workshop policies requiring MFA for owners or managers, and configurable failed-login lockout controls.
How to verify: Require MFA for a controlled role, enrol an account and confirm the account cannot complete a new sign-in without the second factor.
Core business records carry a workshop tenant boundary and protected operations validate the signed-in workshop before accessing data.
How to verify: Run authorised cross-workshop access tests against customers, vehicles, jobs, inspections, invoices and media.
Photos, videos and documents use private object storage with signed upload and read links. Media routes apply role, workshop and assignment checks before issuing access.
How to verify: Confirm the storage bucket cannot be listed publicly and that an expired, unauthorised or unassigned media request is rejected.
Customer portal links use dedicated hashed, expiring tokens and workshop/customer boundaries. They expose the intended customer's portal records rather than a staff account or the full workshop dataset.
How to verify: Open a portal link in a private browser, inspect its customer and workshop scope, then confirm invalid, expired or cross-workshop access is rejected.
Important operational, customer-decision and account events are written to repair-order timelines or platform audit records.
How to verify: Perform a controlled job change, customer decision and account action, then reconcile the resulting event history.
Imports support analysis, preview, issue tracking, audit context and rollback boundaries. Workshop data can also be exported through an authenticated, tenant-scoped workflow.
How to verify: Trial a representative import and export in a controlled account before committing to a production migration.
Data location
Workshop HQ's core application and database services run in Sydney. That is the location statement we can support publicly today.
Some supporting providers may process limited information outside Australia. Transactional email handled through Resend is the current disclosed example. Workshops should review the privacy policy and any connected provider arrangements for their own residency requirements.
Read the privacy policyWorkshop HQ's core application and PostgreSQL database services are hosted in Sydney, Australia. Some supporting providers may process limited information overseas; the current privacy policy explains the known exception for transactional email processing.
Yes. Workshop HQ supports authenticator-code MFA and workshop security policies that can require it for owners and management roles.
No. Access is role and assignment aware. The technician experience is focused on assigned workshop work and does not expose every owner, office or platform control.
No certification is claimed on this page. The published statements describe implemented controls that can be tested. Workshops with formal assurance requirements should ask Workshop HQ to confirm the current scope before purchasing.
Put the controls into your buying test.
Compare roles, customer access, media, audit history, exports and hosting alongside the workshop workflow.