Security
Admin Access & Privacy
How we protect your data โ from everyone, including ourselves
๐ Zero-Content Architecture
CoParentOS is engineered so that no administrator can read your private records. Not support staff. Not engineers. Not company directors. Your messages, evidence, parenting plans and financial data are cryptographically scoped to you.
What administrators can and cannot access
| Data category | Support team | Platform engineers | Directors |
|---|---|---|---|
| Your messages | No | No | No |
| Evidence & documents | No | No | No |
| Financial disclosures | No | No | No |
| Parenting plans | No | No | No |
| Handover check-ins | No | No | No |
| Support tickets you submit | Yes | Yes | Yes |
| Your subscription status | Yes | Yes | Yes |
| Aggregate user count | Yes | Yes | Yes |
* Emergency legal access under Australian court order is subject to two-party authorisation, full audit logging, and user notification. See our Privacy Policy for details.
How we enforce this technically
Row-Level Security
Every database row containing your private data is protected by a Row-Level Security policy. Only your authenticated account can read your records โ even if someone has database credentials, the database itself refuses to return your data.
Encryption at rest and in transit
All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Encryption keys are managed by our infrastructure providers and scoped to user sessions โ not accessible through administrative dashboards.
No content-read API routes
Our admin API provides access to operational metadata โ support tickets, subscription statuses, and aggregate counts. There is no API endpoint that returns user messages, documents, evidence, or parenting plan content. This is by design.
Audit logging
All administrative actions are logged with timestamps, action types, and affected resources. Audit logs are retained for a minimum of 7 years in accordance with Australian record-keeping requirements. Access logs are reviewed monthly.
Emergency legal access
In the event of a valid Australian court order or enforceable law enforcement warrant, a documented emergency access procedure exists. This requires:
- Two-party authorisation โ approval from two designated company officers
- Full audit trail โ who requested, who approved, when, what was accessed, and why
- User notification โ affected users are notified within 72 hours unless prohibited by the court order itself
- Time-limited scope โ access is automatically revoked after a maximum of 48 hours
This procedure is documented in our internal admin access policy and has never been activated.
Why this matters
Most co-parenting platforms can read your messages. Their support teams can view your evidence uploads. Their engineers can query your financial disclosures. This is standard industry practice โ and it's a liability for every co-parent whose records may end up in court.
CoParentOS takes the opposite approach: your private records are yourprivate records. We provide the tools. You control access. Even we can't look over your shoulder.
For a co-parent, that means your messages, evidence, and parenting plans can be submitted to court with confidence โ because no platform employee, engineer, or director has ever been able to read them.
This page describes the public-facing admin access model. For our full internal policy covering access tiers, personnel, audit procedures, and compliance mapping, contact security@coparentos.com.au.
