Security

How we protect
your data

VenueScan is built on the principle that venue data belongs to the venue. Here's how we keep it safe.

AES-256 encryption

All stored data is encrypted at rest using AES-256, the same encryption standard used by financial institutions and defence organisations.

TLS 1.3

Every connection between your devices and VenueScan is encrypted with TLS 1.3, the latest and most secure transport protocol.

AWS Sydney region

All data is hosted on Amazon Web Services in the Sydney (ap-southeast-2) region. Your data never leaves Australian soil.

ISO 27001 certified servers

Our infrastructure runs on AWS's ISO 27001 certified platform, independently audited for information security management.

Data export

Export your full dataset at any time, in any format. If you ever leave VenueScan, your data leaves with you. Learn more in our data export guide.

Data isolation

VenueScan staff cannot access your venue's entry records. Your data is logically isolated and accessible only to your authorised users.

Australian Privacy Principles

Personal information is handled in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth).

On-device processing

ID scanning and data extraction happens entirely on the terminal. Raw ID images are never transmitted to our servers.

Minimal data collection

We don't store driver licence numbers, card numbers, or raw ID images. Your sign-in records contain only the essentials. See exactly what we collect in our data collection reference.

3-year retention

Sign-in records are retained for 3 years. Venues can export their data at any time.

Role-based access

Assign roles to staff members to control who can view entry records, manage settings, or administer the account.

Multi-factor authentication

Enforce MFA across all user accounts for an additional layer of security at every login.

User management

Add, remove, and manage staff accounts from a central dashboard. Deactivated users lose access immediately. Learn more in our team access guide.

Audit logs

Track every change across your venue: settings updates, entry modifications, ban activity, and more. Audit logs are retained for 30 days. See our audit logs guide.

Daily backups

Automated daily backups retained for 7 days, stored within AWS's Sydney region.

Offline resilience

Terminals continue operating during internet outages. Records are stored locally and synced automatically when connectivity is restored. Learn more in our offline mode guide.

Status page

Real-time system monitoring publicly available at status.venuescan.com.au

Proactive monitoring

We monitor your systems around the clock and resolve issues before they reach your front door.

Questions about security?

Our team is happy to walk through our security practices in detail and answer any questions your venue may have.

Terminal

A dedicated sign-in kiosk that scans IDs in under 2 seconds, with offline mode and automatic sync.

Explore Terminal

QR Code

Visitor self-service sign-in via printed QR codes. No hardware needed. Just print and place.

Explore QR Code