Australian owned & operated
Trust & Security

Built to be the most trusted name in construction payment verification.

The fundamentals - security, privacy, and how our CDR-accredited data provider works - that let contractors, tradies, and homeowners share data with confidence.

Bank-grade verification

ProjectFund uses Fiskil, an Australian Consumer Data Right (CDR) accredited Open Banking provider. We will never see, store, save, or hold your client's banking credentials — clients authenticate directly with their bank.

Encryption in transit & at rest

All traffic is protected with TLS 1.3. Sensitive fields, tokens and verification artefacts are encrypted at rest using AES-256. Database backups are encrypted and access is restricted to on-call engineering.

Multi-factor authentication

Contractor accounts support MFA. Suspicious sign-ins trigger an additional check, and all sessions can be revoked from your profile.

Australian data residency

Customer data is hosted in Australia and processed under Australian privacy law. We are designed for the Privacy Act 1988 and follow OAIC guidance for breach notification.

Minimum data, by design

ProjectFund V1 is a verification platform - we do not hold or move funds. We retain only what is necessary to evidence that a verification took place, and clients can revoke access at any time.

Open Banking & the CDR

Bank data is retrieved by Fiskil, a third party accredited under Australia's Consumer Data Right. ProjectFund is not itself a CDR accredited person - we rely on our accredited provider for the regulated data-sharing step. All other information you give us is handled under general privacy principles, including the Australian Privacy Principles.

Point-in-time verification only

A verification confirms whether the required funds appeared to be available at the moment of the check. It is not a payment guarantee, an escrow arrangement, or a substitute for a written contract and your own security-of-payment measures.

Responsible disclosure

If you believe you've found a vulnerability, email security@projectfund.com.au. We aim to acknowledge reports within 2 business days.

Privacy: Read our Privacy Policy for what we collect, why, and how to access, correct or delete it. Questions? Use /contact.

Compliance roadmap: SOC 2 Type I in scope for the V2 trust-accounts release.