We take the security of your fundraising data seriously. This page is our public, plain-English snapshot of how Signal protects your information and where we're heading. For legal terms see our Privacy Policy and Terms.
Current security controls
Encryption in transit
httpOnly, Secure, SameSite.Encryption at rest
Password security
Brute-force protection
Multi-tenant isolation
organisation_id. No customer can read or write another customer's data — enforced at the API layer on every request.Authentication
Two-factor authentication (TOTP)
Audit log
Session timeout
Data residency
Signal is currently hosted on Google Cloud Platform infrastructure in the United States (us-central). EBBE is actively working with our hosting provider to migrate the production environment to an Australian region (australia-southeast1, Sydney). We will publish the migration date on this page once confirmed. Cross-border disclosure is conducted under APP 8 of the Privacy Act 1988.
Compliance & standards
EBBE aligns Signal with the following Australian and international standards:
Responsible disclosure
If you believe you've found a security vulnerability in Signal, please email security@ebbe.com.au with details and steps to reproduce. We commit to:
- Acknowledging your report within 2 business days.
- Providing a remediation timeline within 10 business days.
- Crediting you publicly (with your consent) once the vulnerability is patched.
Please do not publicly disclose vulnerabilities before we've had a chance to remediate.
Backups & disaster recovery
Production data is backed up daily. Our target Recovery Point Objective (RPO) is 24 hours and Recovery Time Objective (RTO) is 4 hours. Backups are retained for 30 days and stored encrypted in the same cloud region as production.
Contact
Security enquiries: security@ebbe.com.au
Privacy enquiries: privacy@ebbe.com.au
General enquiries: hello@ebbe.com.au
