Security
What protects a desk holding other companies' customer correspondence, described precisely enough to check. Last updated 19 September 2026.
A support desk holds the most sensitive thing a business owns after its accounts: what its customers actually said, in their own words, with whatever they attached. Everything below is a property of the running system, not an aspiration, and the last section is the list of things we do not have — because a security page without one is marketing.
Published here for the same reason our comparison pages carry a section on where the competitor is better: you will find out anyway, and it is worth more coming from us.
Email supportandgo@support.myandgo.com.au with enough detail to reproduce it. We will acknowledge you, tell you what we found, and tell you when it is fixed. We will not take action against anyone who reports a genuine issue in good faith and does not access or alter other people's data while finding it.
No. Every ticket, message and file is scoped to a desk in the storage path itself, so a query from one desk has nowhere to reach another, and the database refuses writes from browsers entirely. The isolation tests that prove it run on every deploy, and a deploy stops if they fail.
No. Sign-in is through your MyAndGo account using Google, Microsoft or Apple. We never see or store a password.
No, and we would rather say so here than let you find out in a procurement questionnaire. We have no third-party penetration test yet either. What we can show you is the architecture, the audit log, the deletion certificate and the region every component runs in.
If a breach is likely to cause serious harm we notify you and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires.