Security
The platform
ThinkSafe runs on Microsoft Azure, Microsoft's enterprise cloud infrastructure, hosted in Australasian data centres. All traffic between your devices and ThinkSafe is encrypted (HTTPS/TLS). Data is backed up continuously with point-in-time recovery, and replicated across geographically separate data centres. Software changes are version-controlled, deployed to a staging environment first, and promoted to production only after verification.
ThinkSafe Go
Isolation enforced at the database. Every client's data is separated by row-level security inside the database itself — not just in application code. Even if application code contained a mistake, the database refuses to serve one client's records to another. Two independent layers, always.
Least-privilege by design. External connections run through dedicated database roles scoped to exactly the data they need and nothing more — no credentials, no documents, no form content.
Credentials are never stored in plain text. API keys are stored as cryptographic hashes. Nobody — including us — can read a key back after it's issued.
Instant revocation. Any access key can be shut off in minutes, without a software release, without downtime.
Ongoing security review. Structured security sessions across the whole platform — every data-access path audited, findings fixed before new capability ships.
The ThinkSafe Go API
Your data belongs to you, and your other systems can use it. The API gives your scheduling, rostering, payroll or reporting tools live access to your workers, sites, training and licence records, and activity metadata.
- Scoped per key. Keys are issued read-only by default and access your organisation's data only. Write access is separately scoped, fully audited, and revocable instantly.
- Built for sync. Every record carries a reliable last-updated timestamp, so your systems pull only what's changed.
- Versioned and stable. Once published, an API version only ever gains fields — nothing removed or renamed.
- Documented. Plain one-page documentation covering every endpoint, field and parameter.
Getting connected. Contact the team for an API key and documentation — most integrations are pulling data the same day.
ThinkSafe Pro
Tenant isolation on every record. Every record carries a persistent client identifier, required by all application code for every read and write, with an automated testing regime protecting against cross-client regressions.
Disaster recovery, tested. Deployed across paired data centres with a tested recovery programme.
Encrypted throughout. 256-bit TLS on all app, browser and API traffic; stored passwords encrypted with AES-256; automatic local data wipe when a user account is deactivated.
Integration-ready. REST APIs with secure key-token authentication for connecting Pro to your other business systems.
Continuous monitoring. Intrusion detection, regular security audits, and logs reviewed on daily, weekly and monthly cycles.
Detailed documentation
Detailed security and infrastructure documentation for either product is available on request — useful for tender responses and IT due diligence. Contact us on 0800 600 004 or info@thinksafe.co.nz.

Freephone: 0800 600 004
E-Mail: info@thinksafe.co.nz

