Security at Dinopix

You trust us with your customers' reviews, messages and contact details, and with access to the accounts they live in. This page explains how we look after them, in plain terms.

Isolated by design

Every account’s data is walled off at the database, and production is checked for gaps in that wall every day.

Encrypted throughout

TLS in transit, encryption at rest, and an extra layer of AES-256-GCM on your platform access tokens.

Support only with consent

Our team cannot see your workspace unless you approve it. Access is read-only and expires in 24 hours.

Infrastructure

Dinopix runs on established cloud providers rather than servers we manage ourselves. Your data is stored in Supabase on AWS in Singapore, background syncing runs on Railway in Singapore, and our website and app are served by Netlify and Cloudflare. Each provider, what it does and where it operates is listed on our sub-processors page.

Keeping each account's data separate

Dinopix is a shared platform, so the most important guarantee is that one customer can never see another's data. We enforce that in the database itself, with row-level security on every table that holds customer data, rather than relying on the app to remember to filter.

  • Every request is checked against your account membership before any row is returned.
  • An automated check inspects the live database every day for anything that could weaken that separation, such as a table without access rules, and alerts us if it finds one.
  • We also test it directly, by replaying cross-account access attempts and confirming every one is refused.
  • Background jobs that need wider access are written to scope every query to a single account, and are reviewed specifically for that.

Encryption

  • In transit: all traffic to Dinopix, and between Dinopix and the platforms it connects to, uses TLS.
  • At rest: the database, file storage and backups are encrypted by our infrastructure provider.
  • Platform access tokens: the tokens that let Dinopix read and reply on Google, Facebook, Instagram and other platforms get a second layer of AES-256-GCM encryption in our own code. They are never sent to your browser, and there is no unencrypted copy in the database.

Access and permissions

Within your account, each person has a role (owner, admin, member or client) that controls what they can see and do. The same rules are enforced in the database, the server and the app, so hiding a button is never the only thing standing in the way. Sign-up and sign-in are protected against automated abuse.

On the Enterprise plan, an audit log records who changed what in your account, and you can connect your own systems through our API and webhooks.

Support access is your decision

Dinopix staff cannot open your workspace by default. If we need to look at something to help you, we send a request that the account owner can approve or decline in Settings. Approved access is read-only, never signs anyone in as you, ends automatically after 24 hours, can be revoked at any time, and is recorded.

AI features

AI-drafted replies and sentiment analysis are provided by Anthropic through its commercial API. We send only what is needed to draft or classify the review in front of you. Under Anthropic's commercial terms, that content is not used to train its models.

Secure development

  • Code changes are scanned automatically for security issues before they are merged, and the whole codebase is rescanned weekly, using Semgrep and CodeQL with rules written for the mistakes that matter most in a multi-account product.
  • Our live website and app are scanned weekly for common web vulnerabilities.
  • A strict Content Security Policy limits what can run in your browser on our app.

Backups and deletion

Your data is backed up daily, encrypted, and kept on a rolling 7-day window. When you delete your account or ask us to, we remove your data from the live service within 30 days, and it ages out of backups after that. Full details are in our Data Processing Agreement.

If something goes wrong

If a breach affects personal information we hold for you, we will tell you without undue delay and within 72 hours of becoming aware of it, with what happened, what was affected and what we are doing about it. We will also help you meet your own obligations under the Notifiable Data Breaches scheme and the GDPR.

Privacy and compliance

We handle personal information in line with the Australian Privacy Principles and the GDPR. Our Data Processing Agreement applies automatically to every paid subscription, includes the EU Standard Contractual Clauses for international transfers, and commits us to 30 days' notice before adding a sub-processor. See also our Privacy Policy.

Certifications

Dinopix is not currently SOC 2 or ISO 27001 certified. We would rather tell you that than show a badge we have not earned. If your organisation needs a vendor security review, we are happy to complete your questionnaire and walk your team through how the platform works.

Reporting a vulnerability

If you believe you have found a security issue in Dinopix, please tell us through our contact page before disclosing it publicly. We will acknowledge your report, keep you updated while we investigate, and will not take action against good-faith research that avoids accessing other customers' data or disrupting the service.

Last updated October 2026. No system is perfectly secure. These measures reduce risk; they do not eliminate it, and we do not claim otherwise.