What this site is (for network and filter reviewers)
Poachd is an Australian-operated business platform for skilled trades workforce capability - licensed tradespeople publish a verified capability profile, and contractors building data centre, energy and industrial infrastructure find and engage them. The appropriate content category is business, employment or professional services. There is no adult, gambling, file-sharing, streaming or user-uploaded public content on the domain. Uploads are limited to a signed-in user's own licence and identity documents, stored privately and never served publicly.
The site is a single-domain web application served over HTTPS from www.poachd.co, with payments handled by Stripe's hosted checkout. Our machine-readable security contact is published at /.well-known/security.txt. If your organisation's web filter has blocked or miscategorised this domain, email hello@poachd.co with the words "domain categorisation" in the subject line and we will supply whatever your security team needs to review it.
Access controls
Every table in our database enforces row-level access rules, so an account can only read the records it is entitled to: your own profile, your own roles, and the matches you are part of. Privileged actions such as credential verification are restricted to Poachd staff accounts and executed server-side, never trusted from the browser.
Documents and storage
Licence, ticket and identity uploads go into private storage that is not publicly addressable. Verification staff open them through short-lived, expiring links. Contractors see the verification outcome on a profile, never the underlying document.
Payments
Card details are collected by Stripe in their hosted checkout and never touch Poachd servers or our database. We store the fee record, the amount and the payment status. Fee amounts are calculated server-side from the engagement details, so pricing cannot be altered by a client.
Authentication
Sign-in uses email with a verified address, or Google. Sessions are managed by our authentication provider, and password handling never happens in application code. Access to internal consoles is role-gated on the server.
Data in transit and at rest
All traffic to poachd.co is served over HTTPS. Our hosting and database providers encrypt data at rest and take automated backups as part of their managed service.
Enterprise workspaces, roles and audit
A company runs one shared workspace. Admins invite colleagues as admin, member or viewer; viewers are read-only and suit finance and executive sponsors. Team changes, billing-term changes and mobilisation actions are written to an immutable audit log that workspace admins can read at any time. Two-factor authentication is available to every user, and SAML single sign-on (Okta, Microsoft Entra ID, Google Workspace) is configured on request for enterprise workspaces.
Data processing agreement and sub-processors
Poachd acts as a processor for the workforce and project data a contractor or asset owner enters, and as a controller for account data. Our standard Data Processing Agreement, including Standard Contractual Clauses for transfers, is available to any customer on request and is incorporated into enterprise agreements. Current sub-processors: our managed database and authentication provider, our edge hosting provider, Stripe (payments), our transactional email provider (notify.poachd.co) and our AI inference gateway (used only for document reading and assistant features; no training on customer data). We give 30 days' notice before adding a sub-processor.
Data residency and retention
Production data is stored in a single managed region with encrypted automated backups. Enterprise customers in Australia, Singapore or the UAE who require in-region hosting should raise it during procurement; regional instances are scoped per agreement. Identity documents are retained only as long as needed to verify a credential and are deleted on request; workforce and project records are deleted within 30 days of an account or workspace being closed.
Service levels and support
Target availability for the application is 99.5% measured monthly, excluding announced maintenance. Enterprise workspaces receive a named contact, a one-business-day response target for support and a 72-hour notification commitment for any confirmed security incident affecting their data. Formal SLA credits, uptime reporting and an MSA replacing the standard terms are agreed per enterprise contract.
Procurement pack
For security questionnaires (SIG Lite, CAIQ, or a customer's own), vendor onboarding forms, insurance certificates, W-9 / W-8BEN-E or ABN details and invoice-with-PO billing on net terms, email hello@poachd.co with "procurement" in the subject line. Billing terms, purchase-order numbers and accounts-payable contacts can also be set by a workspace admin under Team & procurement inside the app.
Reporting a vulnerability
If you believe you have found a security issue, email hello@poachd.co with the words "security report" in the subject line, along with the steps to reproduce it. Please give us a reasonable window to respond before disclosing publicly, and avoid accessing other users' data, degrading the service or running automated scans against production. We will acknowledge legitimate reports and keep you updated on the fix.
What we do not claim
Poachd is an early-stage platform. We do not currently hold a third-party security certification such as SOC 2 or ISO 27001, and we publish this page so you can judge our practices on their substance rather than a badge. A SOC 2 Type I readiness programme is planned; enterprise customers will be notified when the report is available.
Questions about this page?
The Poachd team is here to help. Email hello@poachd.co and we'll come back to you.