Sydney core hosting
The core application and PostgreSQL database services are hosted in Sydney, Australia.
Opening Workshop HQ
Loading your workspace…
Workshop records contain personal information, vehicle history, customer decisions and commercial data. Here is the current Workshop HQ control set, its hosting position and a practical way to verify each statement.
The core application and PostgreSQL database services are hosted in Sydney, Australia.
Individual accounts, workshop and role boundaries, MFA controls and narrow customer access protect the platform.
Important changes create timeline or audit records, and migration workflows preserve review and rollback context.
Current controls
These are implementation statements, not a substitute for your own risk review. We do not claim an external security certification on this page.
Workshop users sign in with an individual account tied to a workshop and role. Owner, reception, advisor and technician workflows are permission-aware.
How to verify: Use representative roles to test settings, financial information, repair orders, inspections and technician assignments.
Passwords are stored as one-way hashes. Failed-login lockout settings are configurable, live requests recheck account status and session version, and disabling or materially changing an account invalidates its previous session authority.
How to verify: Trigger the configured failed-login threshold in a controlled account, then disable or change that user and confirm an earlier signed-in session is no longer accepted.
Workshop HQ supports authenticator-code MFA and workshop policies requiring MFA for owners or management roles. Enrolment and security-state changes invalidate earlier session authority.
How to verify: Require MFA for a controlled role, enrol an account and confirm the account cannot complete a new sign-in without the second factor.
MFA seeds and protected integration fields use authenticated application-level encryption. Production requires a dedicated encryption secret separate from the login-session secret, and protected values are not returned in normal settings or data exports.
How to verify: Save a controlled secret, inspect the ordinary settings and tenant export paths, and confirm they expose only configured-state or redacted metadata rather than the stored credential.
Core business records carry a workshop tenant boundary and protected operations validate the signed-in workshop before accessing data.
How to verify: Run authorised cross-workshop access tests against customers, vehicles, jobs, inspections, invoices and media.
Photos, videos and documents use private object storage with signed upload and read links. Media routes apply role, workshop and assignment checks before issuing access.
How to verify: Confirm the storage bucket cannot be listed publicly and that an expired, unauthorised or unassigned media request is rejected.
Customer portal links use dedicated hashed, expiring tokens and workshop/customer boundaries. They expose the intended customer's portal records rather than a staff account or the full workshop dataset.
How to verify: Open a portal link in a private browser, inspect its customer and workshop scope, then confirm invalid, expired or cross-workshop access is rejected.
Important operational, customer-decision and account events are written to repair-order timelines or platform audit records.
How to verify: Perform a controlled job change, customer decision and account action, then reconcile the resulting event history.
Imports support analysis, preview, issue tracking, audit context and rollback boundaries. Workshop data can also be exported through an authenticated, tenant-scoped workflow.
How to verify: Trial a representative import and export in a controlled account before committing to a production migration.
Data location
Workshop HQ's core application and database services run in Sydney. That is the location statement we can support publicly today.
Some supporting providers may process limited information outside Australia. Transactional email handled through Resend is the current disclosed example. Workshops should review the privacy policy and any connected provider arrangements for their own residency requirements.
Read the privacy policyAustralian guidance
OAIC and Cyber.gov.au guidance treats security as a layered, whole-of-lifecycle responsibility. Our evidence guide maps those principles to workshop accounts, customer links, inspection media, hosting, exports, recovery and incident readiness.
Read the complete security guideOffice of the Australian Information Commissioner
Current OAIC guidance explaining the $3 million small-business threshold, important exceptions, the coverage checklist and the recommendation to protect personal information as good practice even where the Act does not apply.
Open official sourceOffice of the Australian Information Commissioner
OAIC guidance on privacy practices, procedures and systems, a clearly expressed and current privacy policy, complaint handling and public availability of that policy.
Open official sourceOffice of the Australian Information Commissioner
OAIC guidance on overseas recipients, contractors, accountability and the distinction between data location, use, disclosure and unauthorised access.
Open official sourceOffice of the Australian Information Commissioner
Updated OAIC guidance on reasonable technical and organisational measures, layered security, the complete information lifecycle, retention, destruction and de-identification.
Open official sourceOffice of the Australian Information Commissioner
Official OAIC guidance on suspected and eligible data breaches, the likely-serious-harm threshold, assessment and notification of affected individuals and the Commissioner.
Open official sourceAustralian Signals Directorate's Australian Cyber Security Centre
Australian small-business guidance covering personal-data registers, collection limits, deletion, access controls, encryption, backups, logging, personal devices and breach reporting.
Open official sourceWorkshop HQ's core application and PostgreSQL database services are hosted in Sydney, Australia. Some supporting providers may process limited information overseas; the current privacy policy explains the known exception for transactional email processing.
Yes. Workshop HQ supports authenticator-code MFA and workshop security policies that can require it for owners and management roles.
No. Access is role and assignment aware. The technician experience is focused on assigned workshop work and does not expose every owner, office or platform control.
No. Workshop HQ stores media privately. Staff and customer requests must pass the applicable workshop, role, assignment, repair-order and customer-visibility checks before a five-minute signed read URL is issued.
No. OAIC says most small businesses with annual turnover of $3 million or less are not covered, but important exceptions apply and a business can opt in. Workshops should use the OAIC checklist or obtain advice about their own entity and activities.
No certification is claimed on this page. The published statements describe implemented controls that can be tested. Workshops with formal assurance requirements should ask Workshop HQ to confirm the current scope before purchasing.
Put the controls into your buying test.
Compare roles, customer access, media, audit history, exports and hosting alongside the workshop workflow.