Software Studio · Adelaide
Security
Security & Data Residency
How PearWise, BoardHive, and PearScribe handle your data
Last updated: 27 August 2026

We built PearWise's infrastructure on the assumption that our clients' data — board minutes, client records, session notes — deserves the same care we'd want for our own. This page is a plain account of what's in place, not a marketing claim: everything below is independently checkable.

1

Data residency

PearWise, BoardHive, and PearScribe (including client and admin portals) are hosted on AWS in Sydney (ap-southeast-2). Our core application and AI infrastructure runs in Australian cloud regions: primarily AWS Sydney, with Firestore hosted in Google Cloud's australia-southeast1 (Sydney) region.

BoardHive's default transcription route prioritises speed and cost. For organisations that need it, we've built an Australian-residency configuration that keeps that processing within Australia end to end — ask us to enable it for your organisation. A small number of non-client-facing internal tools are still being migrated as we go.

2

Independent checks

Rather than ask you to take our word for it, here are live, independently-run scans — click through and check the date yourself:

Additional security controls

Alongside the independent scans above, all three domains publish /.well-known/security.txt (RFC 9116) with a direct contact for security researchers, and enforce DMARC (p=quarantine) on outbound mail — controls we operate ourselves, not third-party verified.

3

Access control & authentication

  • Multi-factor authentication (SMS) is required for every BoardHive account — enforced at first login and again server-side, not just in the browser.
  • Cloud infrastructure access is scoped per product: each service uses its own restricted credentials rather than one shared key, so a compromise in one product can't cascade into another.
  • The circle of people and systems with server access is kept deliberately small.
4

Patching & backups

  • Security updates for our servers are applied automatically.
  • Application data is backed up twice weekly, with integrity checks on each run.

We follow the Australian Signals Directorate's Essential Eight framework as a practical self-assessment baseline (Maturity Level 1) rather than pursuing paid certification badges we don't yet need. Ask us for the full checklist if you're evaluating PearWise for procurement.

5

Staying ahead of AI-driven threats

In August 2026 the Australian Signals Directorate and the Australian Institute of Company Directors published joint guidance on frontier AI cyber threats for boards — noting that modern AI models are compressing attack timelines and lowering the skill bar for attackers. We track this guidance and treat it as a standing input to our own security decisions, not a one-off checklist.

Where it's already reflected in what's on this page: per-product scoped credentials (rather than one shared key), automatic patching, MFA on every BoardHive account, and the Essential Eight baseline above. As the threat picture evolves we'll keep updating this page rather than making a static compliance claim — there's no formal certification against this guidance to hold, and we'd rather be accurate than impressive.

6

Questions

If Australian data residency is part of your procurement, governance, or privacy requirements, contact us and we'll provide the relevant architecture and data-flow information for the PearWise product you're assessing.