Security and data

Know what the system reads, sends and can change.

Security starts with a small job and the least access needed to do it. The final data flow and permissions are reviewed before a customer build.

Public website

What happens before you become a customer.

These are the current public-site data flows. A customer build gets its own written scope because every integration is different.

01

Bot finder

Your job description and answers are sent to the OceanaClaw recommendation service and, when available, an AI provider. The public form should not contain personal or sensitive information.

02

Build deposits

Stripe hosts the payment page and handles card details. OceanaClaw receives the payment status, selected bot family and customer details made available through Stripe, but not your full card number.

03

Contact enquiries

The contact button opens NadirStack’s enquiry form. NadirStack uses the submitted details to respond and scope the requested work.

04

Site traffic

Cloudflare protects and measures the public site. Basic request and security data may be processed to deliver the service, prevent abuse and understand site performance.

Build principles

Controls are agreed before integrations are connected.

  • Least access required for the named job
  • Approved inputs and destinations
  • Rate limits and bounded usage
  • Human review and stop conditions
  • Account ownership and handover agreed

Third-party services

Providers remain part of the risk.

Hosting, AI models, chat platforms, payment services and integrations can process information outside Australia and can change their own terms, availability, retention and security controls.

OceanaClaw does not claim that every system is risk-free or suitable for sensitive, regulated or safety-critical work. Those uses require a separate review and may be declined.

Read the privacy notice

Before a build

Ask for the proposed permissions and data flow.

Ask a question