Trust & procurement

What you need for a vendor-risk check.

A plain summary of who we are, how data is handled on this website and in client work, which providers we use and where, and how to request a security questionnaire or NDA. The legal detail is in our Privacy Policy and AI Use Notice.

Last updated 11 October 2026.

At a glance

Business
S Farsoodeh Saligheh & A Montazami, trading as Melora Digital
ABN
68 158 833 095
Location
Melbourne, Victoria, Australia — delivery in Australia and internationally
Established
2025
Security and privacy contact
Support@meloradigital.com

Assurance status — stated plainly

We don’t currently hold formal certifications such as ISO/IEC 27001 or SOC 2, and we don’t claim panel membership or government approval. We will answer your security questionnaire honestly, tell you exactly which controls apply to your engagement, and agree data-handling terms in writing before any work with your information begins.

Client engagements: how your data is handled

  • Your data stays yours. We use client information only to deliver the engagement, and return or delete it at the end on request.
  • No client data in AI tools by default. We don’t put your confidential or personal information into AI tools unless you’ve agreed to it in the engagement terms and the tool’s terms prevent it being used for training.
  • Residency assessed per engagement. Where data must stay in Australia or inside your environment, we design for that — for example Australian-region cloud services or private/local models. See Security & deployment.
  • Least privilege. We ask only for the access the work needs, use your accounts and approval processes where possible, and remove access when the work ends.
  • People stay accountable. Every solution we design has named human approval points for decisions that matter.

This website and the AI consultation: providers and locations

ProviderWhat they doData involvedLocation
HostingerWebsite hosting, application, MySQL database, email, daily backupsWebsite enquiries, assessment reports, consultation transcripts and summariesHostinger data centres (may be outside Australia)
Cloudflare (Turnstile)Bot protection on formsTechnical browser signals only; no tracking cookiesGlobal network
Surplus IntelligenceRoutes AI requests to model and voice providers; per its policy it does not store request content or use it for trainingConsultation text (contact details removed first), short voice clips in some browsers, reply text for speechUSA
Amazon Bedrock (via Surplus)Runs the primary language model (DeepSeek)Consultation textUSA and other regions
OpenAI (via Surplus)Fallback language model if the primary is unavailableConsultation textUSA
xAI and ElevenLabs voices (via Surplus)Turn the consultant’s replies into speechReply text onlyUSA and other regions
Your browser maker (Google, Apple or Microsoft)Speech recognition in Chrome, Safari and Edge, under their own termsYour voice, in the browser; we receive only the textVaries

Before any text reaches an AI model we automatically remove names, email addresses and phone numbers we can detect. Providers outside Australia handle data under their own terms — see “Overseas disclosure” in our Privacy Policy.

Data lifecycle

InformationWhere it’s heldHow long
Contact enquiries and report requestsDatabase and Support@ mailbox24 months after last contact, then deleted
AI consultation transcript and summaryDatabase (encrypted at rest); summary PDF emailed to Support@180 days, then the transcript is deleted
Consultation audioNot recorded or stored by MeloraNot retained
Assessment answersYour browser; an anonymous score summary is storedAnonymous scores kept for comparison (no personal data)
Fair-use checksOne-way keyed hashes of email and phone12 months
BackupsHostinger daily backupsRolled over on Hostinger’s backup cycle

You can ask us to access, correct or delete your information at any time by emailing Support@meloradigital.com. Deletion covers our database and mailbox; copies in Hostinger’s rolling backups expire on their normal cycle.

Security practices

  • HTTPS everywhere with HSTS, a strict Content Security Policy, and protection against framing, sniffing and cross-site requests.
  • Consultation transcripts and summaries encrypted at rest; secrets kept out of source code.
  • Admin access limited to named Melora staff through single-use sign-in links, with an audit trail of admin actions.
  • Bot protection, rate limits and spend caps on all public forms and AI features.
  • Daily backups by our hosting provider.

Security contact and incidents

If you think you’ve found a security issue, email Support@meloradigital.com (see also security.txt). Please act in good faith: don’t access data that isn’t yours or disrupt the service, and give us a reasonable chance to fix the issue before disclosing it. If a data breach is likely to cause serious harm, we will notify affected people and the OAIC under the Notifiable Data Breaches scheme.

Request a security questionnaire, NDA or data terms

Tell us what your process needs — a security or AI questionnaire, an NDA before sharing details, or data-processing terms — and we’ll respond with what applies to your engagement. Please don’t include confidential information in the first message.

Request procurement information →

Related: Privacy Policy · AI Use Notice · Terms of Use · Cookie Notice · Security & deployment