On this page, we endeavour to provide simple notes relating to the security of our platform and it’s relationship with the organisations we partner with.
This page is our attempt at total transparency with our users, as well as a historical archive of our technical notes relating to security.
We implement multiple layers of security to protect your information appropriately.
Please read about our current security measures below
Website security
moddy.io is hosted and registered in Australia, tied to our ABN
Our subdomains, where our application takes place – app.moddy.io is also hosted in Australia.
Both are protected by SSL encryption
Data Protection
Authentication
Organisation security
Secure development
Monitoring
Learn more about our infrastructure and certification inheritance below

RunCloud – Management Software
Certified to ISO/IEC 27001:2013
Cert. No. : ISMS 00405
CloudFlare – DNS Routing
ISO 27001:2022
ISO 27701:2019
ISO 27018:2019
FedRAMP Moderate
SOC 2 Type II
PCI DSS 4.0
Global CBPR
Global PRP
EU Cloud Code of Conduct
Cyber Essentials
C5:2020
ENS (Spain National Security Framework)
IRAP
BSI Qualification
ProcessUnity Global Risk Exchange
CSA STAR
1.1.1.1 Public DNS Resolver Privacy Examination
WCAG 2.1 AA and Section 508

Vultr – Servers
SOC 2+ (HIPAA)
PCI (Merchant)
CSA Star Level 1
ISO/IEC 20000-1:2018
ISO/IEC 27001:2022
ISO/IEC 27017:2015
ISO/IEC 27018:2019
Due to the minimal data requirements of our software and layers of security above Moddy, we have elected not to obtain individual certifications.
A high level overview of the purposes of Moddy
Name of application: Moddy
Name of vendor: Moddy Apps
Vendor website: moddy.io
Description of application: Cloud based Computer Aided Design (CAD) software that is used to draw home modifications/adaptations.
How the application is used: Users, who are typically Occupational Therapists, builders, home assessors and related staff use Moddy to design new housing plans and export their design to image files to be shared with stakeholders of that housing project.
Who it is hosted by: VUTR Servers
Location of the data: VUTR Global CDN
What data is captured: Name, Email, Company Name, Billing Information, Project Filenames, Internal Project Data
Will the application be used to store or process confidential or sensitive information?
Yes. The application stores and processes limited Personally Identifiable Information (PII), including user name, email address, and company name, which are required for account management and billing. It also stores billing information (e.g., subscription details) and project-related data such as project filenames and internal project content uploaded or created by users.
No special-category (sensitive) personal data under GDPR is collected (e.g., health, biometric, or racial data), and all information processed is limited to what is necessary for providing the service.
Will any PII be stored or processed by the application?
Yes. The application stores and processes standard Personally Identifiable Information (PII) required for user account management and billing. This includes:
No sensitive or special-category PII (such as health, biometric, or government ID data) is collected or processed.
Is PII stored or processed in a pseudo-anonymous manner?
No.
Moddy is supported and maintained by internal engineers.
We are responsive to incidents and maintain relevant security measures.
As browser-based software, we are typically agnostic to desktop level antivirus software.
Our application is used as a website, which may need to be unblocked by your organisation’s firewall.
As browser-based software, typically, there are no additonal priveledges needed to run Moddy.