AuditHQ trust center
Security posture, privacy practices, sub-processor list, compliance status, and data residency - kept current as AuditHQ evolves. The trust center is the canonical answer to "is AuditHQ safe to use".
Evidence-first audit architecture
AuditHQ records website observations and named external-source results before AI narrative. The engine produces the underlying outcomes and AI explains them in plain English.
Subprocessors
AuditHQ uses Supabase, Vercel, Stripe, Resend, and Anthropic to operate the service. The Trust Center lists the purpose, data involved, and known hosting region for each provider.
Vendor review resources
Customers can review the Security page, Privacy Policy, Terms of Service, AI Policy, status page, and DPA request path from the Trust Center.
AI governance and compliance status
AI use is governed by the AuditHQ AI Policy, a responsible AI policy that maps our practices to the NIST AI RMF functions (govern, map, measure, manage). AuditHQ is not ISO/IEC 42001 or SOC 2 certified today - the trust center states current posture plainly rather than implying certifications that do not exist. Formal certification will be assessed as the team grows.
Data residency and transfer posture
AuditHQ's primary Supabase database is hosted in Australia (ap-southeast-2). Other disclosed subprocessors are provider-managed and may process request, billing, email, delivery, or AI-report context outside Australia. AuditHQ does not describe the entire service as Australian-hosted.
Scope and limits
AuditHQ reviews public website and external signals. It cannot see private internal systems, staff capability, authenticated security controls, contracts, or legal-compliance evidence that is not publicly exposed. Security is not a penetration test, privacy is not legal advice, and readiness suites state their public-signal scope.
Corrections
Customers can challenge a finding through support. AuditHQ reviews the recorded evidence, corrects reports where warranted, and fixes the check when the problem is systemic.
Incident and status communication
Operational incidents are communicated through status and support channels. Security or privacy concerns should be raised through the published contact paths so they can be triaged and answered. This gives procurement, customers, and auditors a clearer path than relying on private messages or informal support threads.