Security and your data
You are trusting an app with your business records, so here is exactly how that works. No jargon, no security theatre.
Where your data lives
All app data is stored in Australia, in Supabase's Sydney region. It does not leave the country for processing or backup.
Your bank details
Crestyn stores your own bank details for one purpose: printing them on your invoices so plan managers can pay you. They are encrypted at the application layer before they touch the database. No client money ever moves through Crestyn - we are not a payment platform and never hold funds.
Participant information
Invoices carry the minimum participant details an NDIS invoice needs. Access to your records is locked to your account at the database level (row level security), not just in the app code.
Export any time
Your invoices export as PDF and your records as CSV, on trial or paid, including after you cancel. Your data is yours; leaving should be easy or the trust means nothing.
Who is behind it
Crestyn is built and run by Mick Lutton, a support worker in Mandurah WA, who invoices plan managers with it too. More on the About page.
This website
This site sets no advertising trackers and shows no popups. Analytics, when enabled, are cookieless and aggregate only. The site serves over HTTPS with strict security headers.
Found a security issue? Email security@crestyn.au and it will be looked at fast.