When PearWise started, it was just an information resource — a place to read about what we were building. Where the server sat didn't matter much; nobody's business data was passing through it.

That's not true anymore. PearWise now runs three products for Australian organisations — BoardHive, PearWise Automate, and PearScribe — and each one handles real data: board minutes, client records, session notes. As that responsibility grew, so did our obligation to take data residency and security seriously.

So we did the work. Our core application and AI infrastructure runs in Australian cloud regions: primarily AWS Sydney (ap-southeast-2), with Firestore hosted in Google Cloud's australia-southeast1 (Sydney) region.

Not "close to Australia." In it.

What this means in practice

A small number of non-client-facing internal tools are still being migrated as we go.

Independent security checks

We'd rather you didn't just take our word for it. These are live, independently-run scans — click through and check the date yourself:

Additional security controls (operated by us, not third-party verified): security.txt published on all three domains per RFC 9116, and DMARC enforced (p=quarantine) on all outbound mail. Multi-factor authentication is required for every BoardHive account.

We follow the Australian Signals Directorate's Essential Eight framework as a practical self-assessment baseline, rather than pursuing paid certification badges we don't yet need.

Full details, live links, and our security page: pearwise.au/security.html.

If Australian data residency is part of your procurement, governance, or privacy requirements, contact us and we'll provide the relevant architecture and data-flow information for the PearWise product you're assessing.