Logo
  • Solutions
    ParentsSchoolsUniversitiesWorkplacesIntegrators/
    Platform Partners
  • Features
  • Pricing
    Parent PricingSchool PricingUniversity PricingWorkplace Pricing
  • Learn More
    Start-Up GuideFAQBlogOur StoryContact us
  • Health Check
  • Sign InSign Up

Security & Compliance

Chatstat Pty Ltd (ABN 72 651 491 637, ACN 651 491 637)

Last updated: July 15, 2026

Chatstat exists to help protect people, so protecting their data is a design requirement, not an afterthought. This page summarizes how we secure the service. Detailed documentation, including our Data Processing Addendum and completed security questionnaires, is available to enterprise customers under NDA.

Architecture and enforcement

  • Encryption. Data is encrypted in transit and at rest.
  • Hosting. Primary application infrastructure and data storage in Australia (Sydney), with AI processing through Microsoft's Azure OpenAI Service in the United States.
  • Database-layer enforcement. Customer separation and child-protection rules are enforced with row-level security in our database, not only in application code. The rule that raw content of any person under 18 is never available to a third-party AI agent is enforced at this layer and cannot be overridden by configuration.
  • Data minimization. We collect month and year of birth only for monitored young people, never exact dates, and our integrations default to structured metadata (Tier 1) with no names, handles, or content.
  • Authentication. Enterprise API and MCP access uses OAuth 2.0 with customer-scoped tokens. Access is least-privilege and role-based across the company.
  • Audit logging. Integration and administrative access is logged and retained for 12 months.
  • Redaction. Where redacted excerpts (Tier 2) are enabled, personal identifiers are removed server-side before any data leaves Chatstat.
  • No-training commitments. Our AI providers are contractually restricted from training their models on Chatstat data.
  • Deletion and retention. Retention periods are published in our Privacy Policy and enforced in code, with deletion propagated across systems and backups held on a 35-day rolling cycle.
  • Abuse resistance. Rate limiting, prompt-injection defenses, and region-aware routing are built into our integration layer.

Certification program

  • ISO/IEC 27001. Chatstat is implementing an ISO/IEC 27001 information security management system. Certification through an accredited certification body is in progress.
  • SOC 2 Type II. Scheduled to follow ISO 27001 certification.

We publish certification status accurately and update this page as milestones are reached. We do not claim certifications we do not yet hold.

Privacy governance

Chatstat Pty Ltd is the data controller for the service. Our appointed Data Protection Officer is Nicola Cook of DPO Solutions for Schools. Our Privacy Policy, Sub-processor List, and AI and Notification Disclaimer describe how data is handled, and a Data Processing Addendum is available to customers that require one.

Reporting a vulnerability

If you believe you have found a security vulnerability in a Chatstat service, email security@chatstat.com with enough detail for us to reproduce the issue. We ask that you give us a reasonable opportunity to remediate before public disclosure, and we will not pursue good-faith research conducted within these guidelines.

Contact

security@chatstat.com

About
Our StoryCareers
Contact

Chatstat Pty Ltd (ABN 72 651 491 637)

Support: support@chatstat.comAustralia +61 7 3778 2602USA +1 650 388 9589UK +44 20 4630 0298
Legal
Privacy PolicyCookie PolicyTerms of ServiceAcceptable Use PolicyAI DisclaimerSub-processor ListLegal NoticeSecurityCookie settings