Security, privacy, and ownership.
Reschematic takes your privacy and data security seriously and is Essential Eight compliant. Read on to better understand how we use and protect your data on our platform.
Data Security & Privacy
Trust as default.
Trust is inherent in everything we do at Reschematic. Your data stays within Australia meaning you can also be confident it is compliant for data residency and security.
- Australian hosting. Our infrastructure is in Australia (Sydney).
- You own your models. Content you create remains your IP.
- Private by default. Unless you share a unique model link.
- No AI training. Our AI API does not train on your data or IP.
- Encryption as standard. TLS in transit; secure at rest.
- Regular backups. Your data is backed up in 5-minute intervals.
Cybersecurity
Australian Essential Eight Compliance
Reschematic's cybersecurity framework is right-sized to align with Australia's Essential Eight cybersecurity framework at Maturity Level 1. Explore how we meet each control and what that means in practice.
Read more: ACSC Essential Eight Maturity Model
Patch applicationsView details
Apply security patches to internet-facing services, browsers and plugins within ML1 timeframes; remove unsupported apps.
Regular dependency updates, weekly patch cadence, prompt remediation of critical issues, and deprecation of unsupported packages.
Patch operating systemsView details
Apply OS security patches within ML1 timeframes; remove unsupported OS versions.
Unattended-upgrades enabled; weekly OS patch window plus out-of-band for critical fixes.
Multi-factor authenticationView details
Use MFA for remote/privileged access and important systems and services.
MFA enforced on cloud provider, CI/CD, database consoles and other privileged systems; customer MFA at signup and for available for sensitive information where applicable.
Restrict administrative privilegesView details
Limit admin privileges to those who need them, use separate admin accounts, and review regularly.
Least-privilege across environments; just-in-time access for sensitive actions with auditing; no standing production database admin sessions.
Application controlView details
Implement application control to prevent execution of unapproved/malicious executables, scripts and libraries.
Only approved services and processes run on our hosts and restricts executive of executables, software libraries, scripts, compiled HTML, HTML applications and control panel applets.
Rescritct Office macro settingsView details
Block macros from the internet and only allow vetted macros; prevent untrusted macro execution.
We do not use Office macros in any systems; customer documents are never executed; internal policy blocks internet-sourced macros.
User application hardeningView details
Disable or remove Internet Explorer 11, no java or web advertisements from the internet, users cannot change web security settings.
Our workstations run Apple MacOS and do not include Internet Explorer. We do not run Java. We run adblockers in all browsers, and only admin can change web security settings.
Regular backupsView details
Perform regular backups, protect them from compromise, and test restoration.
Postgres backups every 5 minutes with point-in-time recovery; AU-region storage; and periodic restore tests.
Trust FAQ
Your compliance questions answered:
You do. Content you create remains your IP; Reschematic provides the platform for you to generate and access them.
Models are private by default. Only you and people you send a unique model link to can access them. Operational access is restricted and logged.
All Reschematic data is stored in Australia (Sydney). If your procurement requires another region, talk to us.
We adhere to Essential 8 ML1: TLS in transit, secured at rest, hardened infrastructure, backups in Australia data centres, and least-privilege access.
No. Data processed via the AI APIs we use do not train third party AI models. But we do constantly refine our own modelling algorithms based on your feedback.
Yes. Contact us and we’ll supply our current pack or execute your standard terms where feasible.
Got any other questions? Reach us at hello@reschematic.com
Want to see it in action?
Book a demo and one of our modeling experts will give you a personalised tour of the platform.