Security

How your data is protected

Mustr holds personal details, compliance certificates, rosters and pay information for people working in demanding environments, across sites that must never see each other's data.

The short version

  • Hosted in an Australian data centre certified to ISO 27001, on hardware we manage directly. Data stays onshore.
  • Two-factor authentication on every login, no exceptions and no opt-out.
  • Every organisation's data is isolated at the database level, not just in the application code above it.
  • Accounts are created deliberately by an administrator. There is no public signup into a live workspace.
  • Encrypted in transit and at rest, with the most sensitive personal details encrypted individually on top.
  • A fresh two-factor check before payroll details are revealed, and every reveal is recorded.
  • Daily encrypted backups held offsite in Australia, with a tested restore.
  • Regular patching and monitoring, plus a quarterly security review.

Access control

Every account is created deliberately by an administrator, and every login needs a password plus a rotating six-digit code from an authenticator app. New users set their own password through a one-time link that expires, so passwords are never sent by email in plain text. People get access only to what their role needs, and suspending someone cuts their access, not just their menu options. When a password is reset, any existing sessions end so an old device cannot stay signed in.

Tenant isolation

Mustr is multi-tenant, and each organisation's rows are separated by policies enforced inside the database engine on every query. A worker sees their own records, a client login sees its own site, an organisation sees only itself. Those boundaries hold even if a browser or API client misbehaves, because the database refuses the query rather than trusting the application to filter it.

Encryption

All traffic between you and Mustr runs over HTTPS, so it is encrypted the moment it leaves your device. The servers are fully encrypted at rest, and the most sensitive personal details, such as tax file numbers and bank and superannuation details, are encrypted individually on top of that, so they are never stored in readable form.

Those fields also stay hidden in the interface until whoever is looking passes a fresh two-factor check: Face ID, a fingerprint or a code, at the moment of viewing rather than at sign-in hours earlier. Every reveal is written to the audit log with who did it and when.

Free trial workspaces

A trial is a separate workspace seeded with sample crews, sites and rosters. It is not connected to any live organisation's data, it uses a work email address to keep throwaway signups out, and it expires on its own. Real workforce data belongs in an account we set up with you, not in a trial.

How we keep the code honest

The framework and dependencies are kept current, with published advisories cleared as they appear rather than at some future review. Static security scanning runs as part of the normal development workflow, so a whole class of mistakes is caught before it reaches a server, and the platform gets a security review every quarter.

Hosting and data residency

Mustr runs on dedicated, hardened servers we manage directly, not a shared public cloud account. They sit in an Australian data centre certified to ISO 27001, the international standard for information security management. Your data stays in Australia. That ISO 27001 certification is held by the data centre that hosts Mustr, not by Mustr as a company.

Backups and continuity

Backups run daily, encrypted before they leave the server, and are held offsite in Australia. We keep a rolling history of daily, weekly and monthly backups, and the restore process has been tested.

If something goes wrong

If we become aware of a data breach likely to cause serious harm, we notify the affected people and the regulator in line with Australia's Notifiable Data Breaches scheme, and we tell our customers what happened in plain language.

Reporting a vulnerability

If you believe you've found a security issue in Mustr or this website, we want to hear about it privately first: security@usemustr.com.au. Include enough detail to reproduce the issue. We'll acknowledge your report within a few business days, keep you informed while we fix it, and credit you if you'd like. Please don't access data that isn't yours, degrade the service, or disclose publicly before we've had a reasonable chance to remediate. A machine-readable version of this contact lives at /.well-known/security.txt.

Related

How we handle personal information is covered by the privacy policy. Questions welcome at contact@usemustr.com.au.

Bring one roster to the demo. We'll show you Mustr running it.

Book a 20-minute demo