Bank-grade verification
ProjectFund uses Fiskil, an Australian Consumer Data Right (CDR) accredited Open Banking provider. We will never see, store, save, or hold your client's banking credentials — clients authenticate directly with their bank.
The fundamentals - security, privacy, and how our CDR-accredited data provider works - that let contractors, tradies, and homeowners share data with confidence.
ProjectFund uses Fiskil, an Australian Consumer Data Right (CDR) accredited Open Banking provider. We will never see, store, save, or hold your client's banking credentials — clients authenticate directly with their bank.
All traffic is protected with TLS 1.3. Sensitive fields, tokens and verification artefacts are encrypted at rest using AES-256. Database backups are encrypted and access is restricted to on-call engineering.
Contractor accounts support MFA. Suspicious sign-ins trigger an additional check, and all sessions can be revoked from your profile.
Customer data is hosted in Australia and processed under Australian privacy law. We are designed for the Privacy Act 1988 and follow OAIC guidance for breach notification.
ProjectFund V1 is a verification platform - we do not hold or move funds. We retain only what is necessary to evidence that a verification took place, and clients can revoke access at any time.
Bank data is retrieved by Fiskil, a third party accredited under Australia's Consumer Data Right. ProjectFund is not itself a CDR accredited person - we rely on our accredited provider for the regulated data-sharing step. All other information you give us is handled under general privacy principles, including the Australian Privacy Principles.
A verification confirms whether the required funds appeared to be available at the moment of the check. It is not a payment guarantee, an escrow arrangement, or a substitute for a written contract and your own security-of-payment measures.
If you believe you've found a vulnerability, email security@projectfund.com.au. We aim to acknowledge reports within 2 business days.
Privacy: Read our Privacy Policy for what we collect, why, and how to access, correct or delete it. Questions? Use /contact.
Compliance roadmap: SOC 2 Type I in scope for the V2 trust-accounts release.