Security
Your data, protected
Biloh is built on Australian infrastructure with append-only audit trails, tenant isolation, and transparent operational commitments.
Data residency
All data is stored in Sydney, Australia (Supabase ap-southeast-2, Vercel syd1). Your data never leaves Australian jurisdiction.
Backups
Daily automated backups with 7-day retention. Managed by Supabase with point-in-time recovery available on supported tiers.
Audit trail retention
Audit logs are append-only (enforced by database triggers) with a minimum 7-year retention policy. Every action records the actor, timestamp, and entity affected.
Support
Email support with next-business-day response on all tiers. Same-business-day priority response for Enterprise and Custom plans.
Infrastructure
Biloh runs on Vercel (Sydney edge) and Supabase (Sydney). No uptime SLA is published below the Custom tier — we are transparent about what we can guarantee rather than publishing numbers we cannot back.
Tenant isolation
Every business table in Biloh carries row-level security (RLS) policies enforced at the database layer. Your data is invisible to other tenants — this is not application-level filtering, it is PostgreSQL RLS. MCP connections carry per-tenant identity with misroute safety guards on every write.