Security Information
Australian Child Support Calculator
auschildsupport.com.au/security
Last updated: August 13, 2026
Purpose
This is an evidence-bounded summary for prospective Client Firms and procurement reviewers. It distinguishes application source-code controls from provider, operational, contractual, and independent-assurance evidence. It is not a security certification, independent assurance report, security schedule, or contract.
1. Scope
AusChildSupport's public site includes a child support calculator. Its codebase also contains firm-owned Contact Request and firm administration workflows. Those workflows have separate activation, legal, privacy, contractual, and operational requirements; their presence in source code does not state that they are deployed or available to a particular Client Firm.
This page covers only the application implementation described below. It does not determine a Client Firm's professional, privacy, security, records, or downstream handling obligations.
2. Evidence Boundary
Important: repository review and local tests can establish only how the current code is designed and tested. They do not establish production deployment, provider configuration, key custody, account access, data region, backup or deletion operation, monitoring, incident handling, user adoption, legal approval, or independent assurance.
3. Application Controls in Source
The current application source and focused tests include the following patterns. They are not statements about every historical record or a deployed environment.
- Current administrator password-handling code uses salted scrypt hashes.
- Current MFA code encrypts stored MFA secrets and hashes recovery codes.
- Contact Request persistence encrypts its defined payload and uses tenant-scoped HMAC values for exact contact lookup.
- Firm administration code applies authenticated role and tenant checks to the relevant workflows.
- Contact Request export code requires a Firm Admin password confirmation and uses a tenant- and actor-bound, time-limited download token stored as a hash.
4. Encryption Boundaries
The application source uses AES-256-GCM for the defined Contact Request payload and MFA secret formats. Password and recovery-code handling uses one-way hashes. These are field- and workflow-specific implementation details, not a claim that all data is encrypted, that all fields have the same protection, or that production keys and provider controls have been independently verified.
Important limitation: not every database field is separately encrypted by application code. This page does not make a claim about transport encryption, encryption at rest, database backups, storage, logs, support access, or deletion from provider backups.
5. Provider and Operational Boundaries
The Privacy Policy's subprocessor register records the repository's disclosed provider purposes and associated location and retention dependencies. It does not establish the configuration, contractual role, processing region, access controls, backup handling, or subprocessor chain of any live account.
AusChildSupport does not state on this page that processing is Australia-only, that active-record deletion removes backup copies on the same schedule, that recovery targets are contractual, or that monitoring and incident-response procedures have been operated or independently assured.
6. Procurement Review
A prospective Client Firm should assess the current evidence for its proposed scope, including the applicable privacy information, provider boundaries, product activation, and any intended data sharing or offboarding arrangement. This public summary is not evidence of ISO 27001, SOC 2, penetration testing, government approval, legal compliance certification, or a guaranteed security outcome.
Any firm-specific commitments can arise only from executed written terms that expressly cover them. This page does not represent that a security schedule, data-sharing agreement, questionnaire response, response time, or monitored security mailbox is available for a particular review.
7. Related Public Information
Privacy Policy — collection, disclosure, retention, provider and cross-border information.
Terms of Service — service scope and firm-specific terms where applicable.
