How FairTest Protects Your Data
At FairTest, we understand that drug and alcohol testing data is highly sensitive. Protecting the privacy and security of this information is fundamental to everything we build.
Encryption
- In transit — All data transmitted between your browser or mobile device and our servers is encrypted using TLS (Transport Layer Security).
- At rest — All data stored in our database is encrypted at rest using AES-256 encryption.
Authentication and Access Control
- Secure authentication — User passwords are hashed and never stored in plain text. We support multi-factor authentication (MFA) for an additional layer of account security.
- Role-based access — The Platform enforces four permission levels — Owner, Admin, Manager, and Tester — so users only see and do what their role allows.
- Row-level security — Every database query is scoped to your organisation. Users cannot access data belonging to other organisations, enforced at the database level.
- Session management — Sessions are securely managed with automatic expiry. The mobile app supports biometric authentication (Face ID / fingerprint) with automatic locking after inactivity.
Infrastructure
- Hosting — The Platform is hosted on Vercel and Supabase, both of which maintain industry-standard security certifications including SOC 2 Type II.
- Database — Data is stored in a managed PostgreSQL database provided by Supabase, with automated backups and point-in-time recovery.
- Isolation — Each organisation’s data is logically isolated through row-level security policies. There is no shared access between organisations.
Payment Security
- All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor.
- FairTest does not store credit card numbers or payment card details on our servers.
AI Features
- The AI assistant processes queries through Anthropic’s API. Queries are scoped to your organisation’s data and subject to the same access controls as the rest of the Platform.
- Your data is not used to train AI models.
- AI conversations are stored per-user, per-organisation and are not accessible to other users or organisations.
Third-Party Integrations
- Integrations with external systems (e.g., UKG Ready) are configured and authorised by your organisation.
- Integration credentials are stored securely and encrypted.
- Data exchanged with third-party systems is transmitted over encrypted connections.
Organisational Controls
- Audit logging — Key actions within the Platform are logged for accountability and compliance.
- Team management — Organisation owners and admins can invite, remove, and manage team members and their roles at any time.
- Notification controls — Organisations control who receives notifications for selection events and test results.
Data Retention and Deletion
- Your organisation’s data is retained for as long as your subscription is active.
- Test records are retained in accordance with your organisation’s requirements and applicable workplace health and safety legislation.
- Upon account closure, you may request an export of your data. Data is deleted after a reasonable retrieval period unless legal retention obligations apply.
Incident Response
In the unlikely event of a data breach, we will:
- Investigate and contain the incident promptly
- Notify affected organisations and individuals as required under the Notifiable Data Breaches (NDB) scheme of the Privacy Act 1988 (Cth)
- Report to the Office of the Australian Information Commissioner (OAIC) where required
- Take steps to prevent recurrence
Responsible Disclosure
If you discover a security vulnerability in the FairTest platform, please report it to us. We take all reports seriously and will respond promptly.
Questions
If you have questions about our security practices, contact us at:
FairTest Pty Ltd
Email: contact@fairtest.com.au