
Safeguarding your client data with unmatched protection.
You hold passports, financial evidence and personal histories. Here is exactly how that data is encrypted, stored, logged and recovered, with no vague assurances.
Data encryption standards
All communications between client devices and servers are encrypted using TLS (Transport Layer Security).
Core system data is secured using AES (Advanced Encryption Standard), ensuring sensitive records remain protected within the database and storage systems.

Cloud storage & data sovereignty
The platform is hosted on Microsoft Azure infrastructure, deployed across multiple regions to meet SLA and redundancy requirements.
All primary storage and backup locations are within Australia-based data centres, supporting data sovereignty and compliance with Australian regulations.

Compliance with Australian privacy laws
The system aligns with the Australian Privacy Act 1988 (Cth) and MARA (Migration Agents Registration Authority) regulations.
Only information strictly required for system operations is collected and retained.

Audit logging & access controls
All user operations and administrative actions are captured, and activity can be traced back to individual users for audit support.
RBAC ensures users only have access to the data and modules necessary for their role, with custom security roles available.

Continuity, permissions and login security

Disaster recovery & backups
- Automated daily backups of databases and system data
- Shorter schedules (e.g. hourly) available for high-frequency operations
- Recovery supported by Azure high-availability and geo-redundancy

User permissions & security roles
- Granular role-based permissions across the platform
- Data segregation between staff, managers and administrators
- Custom security roles defined per organisation

Authentication & login security
- 2FA via Microsoft or Google Authenticator apps
- Organisations can enforce 2FA for all users
- Session and domain controls per organisation