Legal
Security
Bury Digital · ABN 31 850 554 300 · Last updated: August 2026
Security matters as much for a build as for a product. This page describes how we protect your data and your accounts while designing, building, and handing over a Project, in line with Australian Privacy Principle 11 (Security of personal information).
Built in your own accounts
- Your data stays with you. Wherever possible, we build directly in your own tools and accounts. Your data — and your customers' data — lives in the platforms you already control, not on our infrastructure.
- Encrypted in transit. Communication with the platforms and APIs we work with uses TLS.
- You keep ownership. On handover, the Deliverables and their data remain in your accounts, so you retain full control.
Access and credentials
- Least privilege. We request only the access a Project actually needs, and prefer scoped, revocable access over full admin where the platform allows it.
- Credentials handled carefully. Where we hold API keys or credentials to build a Project, we store them in a secrets manager, never in plain text, and never share them across clients.
- Access removed on completion. When an engagement ends, we return or revoke our access to your accounts. If you take a Retainer, we keep the minimum access needed to maintain the build.
AI processing
- No training on your data. We do not use your data, or your customers' data, to train artificial intelligence models.
- API-only AI. Where a build uses AI, it runs via the provider's API (for example the Anthropic API), which under its commercial terms does not retain or train on inbound API data.
Our own systems
- We keep our working devices up to date and protected, and use strong, unique credentials with multi-factor authentication where supported.
- Any project data we hold temporarily (for testing or migration) is protected with reasonable measures and deleted when no longer needed.
Incident response
- If we become aware of a data breach involving information we handle for you that is likely to cause serious harm, we will notify you without undue delay — targeting within 72 hours of forming a reasonable belief that a breach has occurred.
- We will assist you to meet your obligations under the Notifiable Data Breaches scheme, and will notify the Office of the Australian Information Commissioner (OAIC) where we are required to.
What we ask of you
- Grant us the minimum access a Project needs, and revoke it when the engagement ends.
- Use strong, unique passwords and multi-factor authentication on the accounts we work in.
- Tell us promptly if you suspect any unauthorised access.
Reporting a vulnerability
If you believe you have found a security issue in something we built or in our website, email oscar@bury.com.au. We commit to acknowledging your report within 3 business days, investigating promptly, and not pursuing legal action against good-faith researchers who follow responsible disclosure.
Contact
Questions about security? Email oscar@bury.com.au.