Legal
Privacy Policy
Last updated 21 July 2026
1. Who we are
Keystone is an IT risk and governance platform built and operated by Community Cyber (ABN 60 365 527 207). This policy explains how we collect, use, store, and protect personal information when you use Keystone, whether directly as a Community Cyber client, or through one of our partner IT service providers.
Keystone is used by IT consultants and managed service providers ("partners") to run cybersecurity assessments and produce governance reporting for their own clients. If your organisation's data appears in Keystone because a partner entered it on your behalf, see "Data entered by a partner" below.
2. Information we collect
We collect the following categories of personal information:
- Account information: name, email address, role, and organisation, when you register or are invited to Keystone.
- Client business information: company name, industry, and contact details entered by consultants for the businesses they assess.
- Assessment and risk data: responses to security questionnaires, maturity scores, risk register entries, and mitigation roadmap items.
- IT asset information: inventories of software, hardware, and cloud services, including where credentials for those systems are stored (Keystone does not store passwords or credentials themselves).
- Report content: consultant commentary and customer comments recorded on board reports.
- Uploaded files: client logos and supporting documents.
- Support and activity records: support ticket content and a log of actions taken within your account, kept for security and audit purposes.
3. Data entered by a partner
Where a Keystone partner (an IT consultancy or MSP) uses the platform to manage your organisation as their client, they (not you) control what information is entered about your business. Community Cyber holds that data on the partner's behalf. Requests to access, correct, or delete that data should generally go to the partner directly; we will assist them in fulfilling those requests, and you're welcome to contact us if you're unable to reach them.
4. How we use your information
We use personal information to:
- Provide and maintain the Keystone platform, including generating assessments, risk registers, and reports.
- Authenticate accounts and manage access permissions between organisations and their clients.
- Send account-related and operational notifications (e.g. approval notices, report availability).
- Respond to support requests.
- Maintain the security, integrity, and audit trail of the platform.
- Improve Keystone based on aggregated, de-identified usage patterns.
We do not sell personal information, and we do not use client assessment data to train any third-party AI models.
5. Who we share it with
We share personal information with a small number of service providers who help us operate Keystone, under contracts that require them to protect it:
- Supabase: database hosting, authentication, and file storage.
- Vercel: application hosting.
- Resend: transactional email delivery (e.g. notifications).
Within Keystone, data is only visible to authorised users at your organisation, your assigned consultant or partner, and Community Cyber staff who need it to operate the platform, enforced by role-based, per-client access controls at the database level.
Overseas disclosure: some of the providers above may store or process data on servers located outside Australia (including in the United States). Where this occurs, we take reasonable steps to ensure the provider offers a comparable standard of privacy protection to the Australian Privacy Principles.
We do not otherwise disclose personal information to third parties, except where required by law.
6. Data security
Data in transit is encrypted (HTTPS/TLS). Access to client data is restricted at the database level so that only authorised users of a given organisation, and where applicable their assigned partner, can read or write it. Account access can be further protected with passkeys. No system is completely immune to risk, and if we become aware of a data breach likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in line with the Notifiable Data Breaches scheme.
7. Data retention
We retain personal information for as long as your account, or your organisation's engagement with Community Cyber or a Keystone partner, remains active. Once an account is closed or an engagement ends, we retain the associated data for up to 12 months, after which it is securely deleted, unless we're required to keep it longer by law, or you ask us to delete it sooner.
8. Cookies
Keystone uses only the session cookies needed to keep you signed in. We do not use third-party analytics, advertising, or tracking cookies within the application.
9. Access, correction, and complaints
You can request access to, or correction of, the personal information we hold about you at any time by contacting us below. If you're not satisfied with how we've handled a privacy concern, you can lodge a complaint with the Office of the Australian Information Commissioner at oaic.gov.au.
10. Changes to this policy
We may update this policy from time to time as Keystone evolves. Material changes will be reflected by updating the "last updated" date at the top of this page.
11. Contact us
For any privacy question, access request, or complaint, contact Community Cyber at privacy@communitycyber.com.au.