Skip to content
Adminest Sign up free

Adminest Trust Centre

Your most important documents,
protected like they should be.

Adminest holds some of the most sensitive paperwork in your life — passports, insurance, tenancy, medical and government letters. Here is exactly how we look after it, in plain language, with no claims we can’t back up.

TLS 1.2+ encryption AES-256-GCM at rest NZ Privacy Act 2020 Global Privacy Control honoured We never sell your data

Last reviewed 24 July 2026 · Security questions: security@adminest.com

01 — Data protection

Encryption

  • Encrypted in transit. Everything travels over TLS 1.2 or higher — older, weaker versions are disabled and can’t be turned on. HSTS is enforced for a full year, including subdomains.

  • Sensitive credentials encrypted at rest. Connected-account tokens (like your calendar) are encrypted with AES-256-GCM, using a unique value per record.

  • Storage encrypted at rest. Your documents and database are stored encrypted on Microsoft Azure and MongoDB Atlas.

  • Hardened browser security. Strict Content-Security-Policy, no framing and no MIME-type sniffing are applied to every response.

02 — Identity

Access & identity

  • Sign-in handled by Auth0 (an Okta company). We never see or store your password.

  • Every request is cryptographically verified. Access tokens are fully signature-verified — including real-time connections — never simply trusted.

  • Strict per-account isolation. Every record is fetched scoped to the signed-in owner, so no one can reach another person’s data.

  • Least-privilege internal access. Administrative access is limited to an exact, named allow-list — no broad matching, no shared logins.

03 — Engineering

Application security & testing

  • Security review on every change. An automated security gate reviews each code change and blocks the release if a high or critical issue is found.

  • Continuous automated scanning. OWASP ZAP dynamic testing, secret scanning, and dependency vulnerability audits run on our pipeline.

  • Regular internal security assessments. We run our own assessments across the OWASP Web, API and LLM Top 10; findings are tracked to closure and locked in with regression tests.

  • Responsible disclosure welcome. Found something? Email security@adminest.com — details at the bottom of this page.

04 — Privacy

Privacy & your control

  • Built to the New Zealand Privacy Act 2020. Aligned with GDPR and CCPA principles for anyone using Adminest from overseas.

  • We never sell your data. And we honour Global Privacy Control browser signals automatically.

  • Granular AI consent. Switch off document analysis, task extraction, the chat assistant or email summaries independently — any time, per feature.

  • Export or delete, on your terms. Download all your data, or permanently delete your account and everything in it — including stored files — whenever you choose.

05 — Artificial intelligence

AI you can trust

  • Enterprise AI infrastructure. Adminest is powered by Claude (Anthropic), run on Microsoft Azure AI Foundry rather than a public consumer endpoint.

  • Your documents are shielded from prompt-injection. Untrusted text from your files is safely fenced, so a document can’t hijack the assistant into doing something you didn’t ask.

  • We minimise what leaves the app. Our AI monitoring sees only structural metadata for reliability — never the contents of your documents.

  • Your content is not used to train AI models. Adminest runs on Microsoft Azure AI Foundry, whose data-handling terms mean your documents and messages are used only to answer you — never to train the underlying models, and never shared with other customers.

06 — Availability

Reliability & recovery

  • Monitored around the clock. Real-time telemetry and health checks watch the service continuously, with alerting when something needs attention.

  • Automated daily backups. A full backup of your data is taken every day and retained for 30 days, giving a recovery point of 24 hours or less.

  • Backups kept apart from live data. Daily backups are stored on entirely separate infrastructure — a different cloud provider and region from the live database — so a single failure can’t take out both.

Transparency

Where your data lives

Hosted on trusted global cloud infrastructure

Adminest’s application, encrypted file storage and AI processing run on Microsoft Azure in the United States (East US). Your account records are held in a MongoDB Atlas database on Google Cloud in Singapore, and sign-in is provided by Auth0 (US).

As a New Zealand business, we handle every cross-border transfer of your information in line with the Privacy Act 2020 — including Information Privacy Principle 12, which requires your data to be comparably protected wherever in the world it is held.

Who we work with

Sub-processors

The trusted providers that help run Adminest. Each is contractually bound to protect your data and only process it on our instructions.

ProviderWhat they doLocation
Microsoft AzureHosting, encrypted file storage, document text extraction, AI processing & telemetryUnited States
MongoDB AtlasPrimary database for your records (hosted on Google Cloud)Singapore
Auth0 (Okta)Authentication & identityUnited States
Anthropic — ClaudeAI analysis of documents, chat & email (via Azure AI Foundry)United States
PostmarkInbound & outbound emailUnited States
GoogleCalendar sync & email sending — only if you connect themUnited States
SlackInternal operational & support alertsUnited States

Straight answers

Our approach to compliance

We’d rather show you what we do than flash a badge we don’t hold.

Adminest is built to the SOC 2 Trust Services Criteria and we maintain internal security and privacy policies, a designated privacy contact, and records of how we process data. We are not currently SOC 2 certified, and we won’t claim to be.

Our security assessments are conducted internally rather than by an independent third party. Everything on this page reflects controls that are actually in place in our systems today — if that changes, this page changes with it.

Responsible disclosure

Found a security issue?

We welcome reports from security researchers and will work with you on any genuine vulnerability. Please give us a reasonable chance to fix it before disclosing publicly.

We use cookies to improve your experience. Essential cookies are always active. You can choose to enable analytics cookies to help us improve the service. Cookie Policy