← Back to website
SecurityComplianceDeployment

Security & Compliance

CloudBooth combines application security, private media delivery, audited administrative controls and flexible deployment options. This page describes the control model and the standards it can support; it does not claim certifications that have not been independently awarded.

Current platform position · 21 August 2026

Identity & access

Role-based tenant isolation, MFA/passkeys, step-up authentication and auditable privileged actions.

Private media

Authenticated Cloudflare object storage with private objects and controlled signed-media delivery.

Resilience

PostgreSQL recovery points, isolated test releases, rollback controls and monitored storage/media paths.

Deployment choice

Supported regional arrangements and Customer-controlled deployment options can be assessed where required.

1. Security architecture

CloudBooth separates organisations through tenant-aware application and data-access controls. Users are authorised by role and permission, with stronger step-up authentication for sensitive administrative operations. Security and operational events are recorded to support troubleshooting and audit review.

  • Individual user accounts, role-based permissions and explicit organisation/workspace context.
  • Passkeys and authenticator-based MFA, with step-up checks for privileged administration.
  • Encryption & secure transport: HTTPS/TLS transport, signed sessions, bounded browser diagnostics and server-side secret handling.
  • Private internal service paths, controlled reverse-proxy ingress and production/test environment separation.
  • Release validation, test-before-production promotion and rollback/recovery controls.

2. Media storage, access and data location

Live event images are stored in private Cloudflare R2 object storage after capture. Media objects are authenticated and are not published as public bucket assets. CloudBooth uses application authorisation and signed-media delivery so a raw storage object does not become a permanent public URL.

Cloudflare operates a globally distributed network and storage platform. Placement and delivery depend on the configured bucket/storage location and Cloudflare capabilities. Where a customer requires a particular geography, CloudBooth can assist with supported location hints, jurisdictional restrictions or dedicated deployment arrangements as appropriate. Requirements should be confirmed during solution design rather than inferred from a visitor's current edge location.

Enterprise option: on-premises storage or a broader customer-controlled deployment can be arranged on request, subject to architecture, support, security and commercial assessment.

3. Data protection and privacy controls

CloudBooth is designed around data minimisation, access control and purpose-limited processing. Event organisers choose guest fields and are responsible for notices, consent and marketing choices. The platform provides private media delivery, configurable retention, audit records, access/deletion workflows and diagnostic redaction to support those obligations. The detailed handling of personal information is described in the Privacy Policy.

4. Global standards and assurance alignment

CloudBooth security controls can be mapped to widely used security and privacy frameworks for customer assurance and procurement. These are control and evidence alignments, not automatic certifications. Certification or assessment status depends on the specific organisation, deployment boundary, assessor and contract.

International

  • ISO/IEC 27001 information-security control themes.
  • NIST Cybersecurity Framework governance, identify, protect, detect, respond and recover outcomes.
  • OWASP application-security practices for web/API risk management.
  • Privacy principles relevant to GDPR and comparable data-protection regimes.

Australia

  • Privacy Act 1988 and Australian Privacy Principles where applicable.
  • Australian Government Information Security Manual control themes.
  • Essential Eight mitigation strategies where applicable to the deployment boundary.
  • Protective Security Policy Framework (PSPF) considerations for government workloads.

CloudBooth does not claim that CloudBooth itself is IRAP assessed unless a specific assessment has been completed and evidence is provided for the relevant deployment. The current certification boundary should always be confirmed in procurement or security review documentation.

5. Operational security and monitoring

CloudBooth records platform health and security-relevant operational evidence without exposing infrastructure secrets to normal users. Public status information is deliberately sanitised. Administrative diagnostics can correlate release, organisation, user and request information while excluding cookies, request bodies and obvious secrets from browser telemetry.

  • Five-minute platform and media-path health snapshots with explicit on-demand refresh where supported.
  • Signed-media checks, private object-storage round trips and service readiness monitoring.
  • Error Diagnostics with bounded/redacted client context and durable support references.
  • Audit records for sensitive administrative actions and release operations.

6. Software delivery and change control

CloudBooth releases are validated as complete packages before production promotion. The supported workflow validates the package, deploys the exact SHA-256 candidate to TEST, performs automated and user acceptance checks, and only then promotes the same candidate to production. Database changes are designed to remain backward-compatible with rollback.

7. Customer assurance and regulated deployments

Enterprise and regulated customers can request architecture information, deployment constraints, data-location options, security-control evidence and support for customer-specific assurance questionnaires. Where requirements include a dedicated region, sovereign boundary, customer-managed infrastructure or on-premises storage, CloudBooth can assess a deployment pattern that keeps those requirements explicit and testable.

8. Shared responsibility

CloudBooth secures the platform and its supported infrastructure; customers remain responsible for appropriate user access, booth-device security, event notices/consent, endpoint management, local networks, exported data and any third-party services or custom integrations they configure.

9. Reporting security concerns

Security concerns should be reported to [email protected] with enough information to investigate the issue without including credentials or unnecessary personal information.