Adminest Trust Centre
Your most important documents,
protected like they should be.
Adminest holds some of the most sensitive paperwork in your life — passports, insurance, tenancy, medical and government letters. Here is exactly how we look after it, in plain language, with no claims we can’t back up.
Last reviewed 24 July 2026 · Security questions: security@adminest.com
At a glance
Six areas we take seriously
The short version. Tap any area to see the specific controls behind it.
01 — Data protection
Encryption
Encrypted in transit. Everything travels over TLS 1.2 or higher — older, weaker versions are disabled and can’t be turned on. HSTS is enforced for a full year, including subdomains.
Sensitive credentials encrypted at rest. Connected-account tokens (like your calendar) are encrypted with AES-256-GCM, using a unique value per record.
Storage encrypted at rest. Your documents and database are stored encrypted on Microsoft Azure and MongoDB Atlas.
Hardened browser security. Strict Content-Security-Policy, no framing and no MIME-type sniffing are applied to every response.
02 — Identity
Access & identity
Sign-in handled by Auth0 (an Okta company). We never see or store your password.
Every request is cryptographically verified. Access tokens are fully signature-verified — including real-time connections — never simply trusted.
Strict per-account isolation. Every record is fetched scoped to the signed-in owner, so no one can reach another person’s data.
Least-privilege internal access. Administrative access is limited to an exact, named allow-list — no broad matching, no shared logins.
03 — Engineering
Application security & testing
Security review on every change. An automated security gate reviews each code change and blocks the release if a high or critical issue is found.
Continuous automated scanning. OWASP ZAP dynamic testing, secret scanning, and dependency vulnerability audits run on our pipeline.
Regular internal security assessments. We run our own assessments across the OWASP Web, API and LLM Top 10; findings are tracked to closure and locked in with regression tests.
Responsible disclosure welcome. Found something? Email security@adminest.com — details at the bottom of this page.
04 — Privacy
Privacy & your control
Built to the New Zealand Privacy Act 2020. Aligned with GDPR and CCPA principles for anyone using Adminest from overseas.
We never sell your data. And we honour Global Privacy Control browser signals automatically.
Granular AI consent. Switch off document analysis, task extraction, the chat assistant or email summaries independently — any time, per feature.
Export or delete, on your terms. Download all your data, or permanently delete your account and everything in it — including stored files — whenever you choose.
05 — Artificial intelligence
AI you can trust
Enterprise AI infrastructure. Adminest is powered by Claude (Anthropic), run on Microsoft Azure AI Foundry rather than a public consumer endpoint.
Your documents are shielded from prompt-injection. Untrusted text from your files is safely fenced, so a document can’t hijack the assistant into doing something you didn’t ask.
We minimise what leaves the app. Our AI monitoring sees only structural metadata for reliability — never the contents of your documents.
Your content is not used to train AI models. Adminest runs on Microsoft Azure AI Foundry, whose data-handling terms mean your documents and messages are used only to answer you — never to train the underlying models, and never shared with other customers.
06 — Availability
Reliability & recovery
Monitored around the clock. Real-time telemetry and health checks watch the service continuously, with alerting when something needs attention.
Automated daily backups. A full backup of your data is taken every day and retained for 30 days, giving a recovery point of 24 hours or less.
Backups kept apart from live data. Daily backups are stored on entirely separate infrastructure — a different cloud provider and region from the live database — so a single failure can’t take out both.
Transparency
Where your data lives
Hosted on trusted global cloud infrastructure
Adminest’s application, encrypted file storage and AI processing run on Microsoft Azure in the United States (East US). Your account records are held in a MongoDB Atlas database on Google Cloud in Singapore, and sign-in is provided by Auth0 (US).
As a New Zealand business, we handle every cross-border transfer of your information in line with the Privacy Act 2020 — including Information Privacy Principle 12, which requires your data to be comparably protected wherever in the world it is held.
Who we work with
Sub-processors
The trusted providers that help run Adminest. Each is contractually bound to protect your data and only process it on our instructions.
| Provider | What they do | Location |
|---|---|---|
| Microsoft Azure | Hosting, encrypted file storage, document text extraction, AI processing & telemetry | United States |
| MongoDB Atlas | Primary database for your records (hosted on Google Cloud) | Singapore |
| Auth0 (Okta) | Authentication & identity | United States |
| Anthropic — Claude | AI analysis of documents, chat & email (via Azure AI Foundry) | United States |
| Postmark | Inbound & outbound email | United States |
| Calendar sync & email sending — only if you connect them | United States | |
| Slack | Internal operational & support alerts | United States |
Straight answers
Our approach to compliance
We’d rather show you what we do than flash a badge we don’t hold.
Adminest is built to the SOC 2 Trust Services Criteria and we maintain internal security and privacy policies, a designated privacy contact, and records of how we process data. We are not currently SOC 2 certified, and we won’t claim to be.
Our security assessments are conducted internally rather than by an independent third party. Everything on this page reflects controls that are actually in place in our systems today — if that changes, this page changes with it.
Responsible disclosure
Found a security issue?
We welcome reports from security researchers and will work with you on any genuine vulnerability. Please give us a reasonable chance to fix it before disclosing publicly.