Data residency
Where NestWise runs your data
Compute pinned to Sydney. Database in Supabase. A small number of auxiliary services (payments, AI features, email) run in the US — listed here honestly rather than glossed over. Accountants recommending the app to clients can verify each component below.
Where your data primarily lives
Application compute
via Vercel
All page renders + API routes + serverless functions + cron jobs. Every calculation NestWise performs runs on Vercel.
Region: Sydney (syd1)
Pinned via vercel.json regions field. Verifiable in the response headers (x-vercel-id / x-vercel-execution-region).
Database + Auth
via Supabase (PostgreSQL)
Your family profile, children, bank transactions, cashflow plans, bills, entitlement claims, super balances, everything you type into NestWise.
Region: Sydney (ap-southeast-2)
AWS Sydney region via Supabase. All application database queries + auth token verification hit this region. Documented in the Privacy policy at /privacy.
Static assets (CSS / JS / images)
via Vercel Edge CDN
Serving public files — the HTML shell, JavaScript bundles, images. Nothing user-specific.
Region: Global edge — cached in the nearest Vercel edge node to the visitor
Public files only; no private data flows here. Normal CDN behaviour — required to make the app fast worldwide.
Bill / letter forwarding inbox
via Cloudflare Email Workers
When you forward a bill or letter to your NestWise inbox address, the Cloudflare Worker parses it + posts a signed webhook to Vercel. The parsed content lands in your Supabase inbox_letters row.
Region: Cloudflare edge (global) — worker executes at the nearest edge to the sending mail server
Email itself is inherently multi-region — sender → mail-transfer-agent → Cloudflare edge. Parsed content lands in Supabase (AU-region if your Supabase is AU).
Payment processing
via Stripe
$20/yr subscription billing. You never enter card details into NestWise directly — Stripe hosts the checkout form.
Region: US (Stripe primary) + AU (local card acquiring)
Standard for AU SaaS. Stripe holds card data + charge history; NestWise holds only the customer id + subscription status. Stripe is PCI Level 1 certified globally.
AI features (chatbot, categorisation prompts)
via Anthropic (Claude) — used sparingly
When present, only for feature suggestions or categorisation hints. No calculation runs through AI — every entitlement/tax/cashflow number comes from local Australian rate tables in code.
Region: US (Anthropic API)
Any AI request necessarily leaves AU. NestWise minimises this — the app runs primarily on deterministic code, not AI inference. If you want the fully-no-AI path, all deductions + entitlements + cashflow features work without any AI enabled.
Email notifications (welcome, alerts, digests)
via Provider varies — check your account for specifics
Weekly digest, alert emails, sign-up confirmation. Body content is minimal + never contains dollar figures.
Region: Depends on provider — most transactional mail providers have US primary infrastructure
Email is fundamentally multi-region — your inbox provider (Gmail / Outlook / etc) receives the message via SMTP relay chains that span continents. No PII beyond your email address + first name appears in outbound mail.
Data controller
Adelante Technologies Pty Ltd
ABN 19 678 163 490. Based in Sydney, Australia. Bound by the Australian Privacy Act 1988 + Notifiable Data Breaches scheme. Chartered-accountant built. Feedback + data-access requests direct to hello@nestwise.net.au.
How we watch for problems
Every deploy runs through automated security tooling before + after it goes live. If something breaks, we hear about it fast.
- Sentry — runtime error monitoring on every user session. Uncaught exceptions, failed API calls, and auth issues get captured with enough context to fix them without needing to reproduce.
- Dependabot — GitHub's weekly npm + GitHub-Actions dependency scanner. New CVEs affecting our installed versions open a PR automatically. Patch + minor bumps auto-merge after CI passes; anything major goes through a human review.
- Snyk — deeper dependency + container scans on every push. Flags CVEs Dependabot doesn't catch (transitive dep chains, license issues, Docker layer vulnerabilities). Findings surface in our internal admin dashboard within minutes.
- Semgrep — static analysis on every pull request. Catches missing auth checks on API routes, hardcoded secrets, SQL-injection patterns, and other structural issues BEFORE the code merges.
- Supabase Security Advisor — weekly scan of every database table + storage bucket for RLS gaps, missing policies, and public-access mistakes. Findings flow into our own internal /admin/security-check which we review with a daily cron.
- Independent penetration testing — external testing is scheduled ahead of paid-user growth milestones. Our pen-test readiness doc + baseline security headers (CSP, HSTS, X-Frame-Options, Permissions-Policy) are already shipped.
No monitoring stack catches everything. If you spot something we haven't, disclosure details are in SECURITY.md or email hello@nestwise.net.au — we respond within 48h.
What we deliberately don’t store
- Full bank credentials. NestWise uses CSV import — you upload a bank statement file. No open-banking token, no bank login on our side.
- Card details. Stripe hosts checkout; we only see the last-4 + expiry via Stripe metadata.
- Full IP addresses. Access logs (accountant share views, partner intake) hash the IP with a per-app salt before storing — enough entropy to detect repeat visits, not enough to identify a person.
- PII in outbound analytics. Event tracking never sends dollar amounts or names to third-party analytics. Only feature-usage counts.
Last updated 2026-08-15. If any component listed above is inaccurate for your session (region change, provider swap), let us know.