Trust
Trust
Last updated: 30 September 2026
We sell security. Our own posture should be inspectable, not asserted.
This page is the short version of how RG Labs is built and how we handle your data. The detail sits in our Privacy Policy and our Security & Data Handling Overview, which we provide on request and attach to every proposal.
The architecture, in one paragraph
The Security Posture Assessment platform runs entirely on Cloudflare: Pages for the site and portal, Workers for application logic, D1 for the database, Access for internal authorisation. The scanning engines do not run on it. They run on an RG Labs operator workstation in Australia, and the credentials they use never reach the hosted platform.
Your credentials never touch our platform
This is the design decision we would most like you to check.
Prowler and Maester execute on an operator workstation, not in our cloud. The platform receives assessment results only. It has no ability to authenticate to your environment, connect to it, or act against it — not with a valid session, and not if the platform itself were compromised.
Cloud access is read-only in every environment, without exception. It is provisioned as a time-bound, read-only application registration rather than a user account, so you can see exactly what we hold and revoke it yourself at any moment. At engagement close it is revoked and local scanner output is destroyed.
The workstation is full-disk encrypted, runs endpoint detection and response, and holds engagement credentials in an encrypted vault for the duration of the work only.
Where your data lives
| Database | Cloudflare D1, Oceania region |
|---|---|
| Read replication | Disabled — one copy, it does not leave the region |
| Backups | Encrypted, same region, expire at 30 days |
| Scanners | Operator workstation, Australia |
| Credentials on platform | None |
Stated precisely: Cloudflare D1 offers a jurisdiction setting that contractually binds a database to a legal region, but it currently supports the European Union and US FedRAMP only. There is no Australian option. Our database is in Oceania by regional placement, not by contractual jurisdiction lock.
We could describe this as "Australian data residency". It would sell better and it would overstate what the underlying service provides. If you have a binding residency obligation, raise it at scoping and we will deal with it directly.
Separately, specific data elements go to named third parties, some of them offshore. Both facts are true and both are listed in our Privacy Policy.
How long we keep it
- One-off reports: 12 months from delivery, then deleted
- Clients on an Annual Re-assessment: life of the arrangement plus 12 months
- Longer, if you want it: opt in and specify the period
- Delete on request: live systems within 5 business days, backups and recovery history within 30 days, no reason required
Most vendors in this market retain indefinitely and do not tell you. We chose a defined schedule because a permanent, structured record of where every client is weakest is not an asset we want to be holding.
AI in your report
Report narrative is generated with a large language model. Every identifier is tokenised before anything is sent — names, email addresses, tenant and account identifiers, resource names, hostnames, IP addresses. The mapping stays in our Australian database. Real values are substituted back in when your report renders, so you lose no detail and the model receives none.
Findings are passed to the model as delimited untrusted input with explicit instructions never to treat their content as instructions, which defends against a prompt injection planted in your environment.
You can turn AI narrative off in your portal settings. The findings are produced by the scanning engines and are unaffected either way.
We do not use your data to train models, ours or anyone else's.
Who else touches your data
Cloudflare (hosting, database, access control), Anthropic and Cloudflare Workers AI (report narrative, tokenised only), Resend (transactional email), Stripe (payments), Shodan InternetDB (exposed service lookup), SSLMate certspotter and crt.sh (certificate transparency), Google Analytics (rglabs.com.au only).
Full table with roles, data received and jurisdictions is in our Privacy Policy.
Our own domain
We run the controls we sell, on ourselves:
- DNSSEC enabled
- DMARC, with aggregate reporting
- MTA-STS with a published policy, and TLS-RPT
- CAA records restricting which certificate authorities may issue for our domains
You are welcome to verify any of it. That is rather the point — we are a reasonable first target for anyone who wants to test whether we practise what we sell.
Reporting a vulnerability
We publish a vulnerability disclosure policy and a security.txt at /.well-known/security.txt.
Report to security@rglabs.com.au. We acknowledge within 5 business days and we will not pursue researchers acting in good faith within the stated scope.
What we don't hold
Being straight about this matters more than the alternative.
- We are not certified. RG Labs does not hold ISO 27001, SOC 2 or any equivalent certification. We are not pursuing one at present. If a certification is a hard requirement for your procurement, we are not the right supplier yet and we will tell you so early.
- We do not issue certification either. We assess and engineer controls. We do not certify you, and no scan we run makes you compliant with anything.
- We do not claim parity across clouds we have not scoped. Framework and control coverage varies by cloud platform. We confirm exactly what applies to your environment before you buy.
- We are a small business. The engineer who scopes the work delivers it. There is no account-manager layer and no offshore handoff, which is deliberate — but it also means our delivery capacity is finite, and we would rather tell you that than take work we cannot do well.
Continuity
If RG Labs ceases trading, clients get 30 days to retrieve their reports and data from the portal, after which all client data is deleted. Backups are encrypted and expire on the same schedule as live data.
Business details
RG Labs · ABN 26 465 879 682 · registered for GST
Privacy: privacy@rglabs.com.au · Security: security@rglabs.com.au · General: hello@rglabs.com.au