Australian data sovereignty
All data stored in CompliDesk — including client identity documents, risk assessments, KYC records, and audit trails — is stored exclusively on Australian servers. We use AWS infrastructure in the Asia Pacific (Sydney) region.
Your data never leaves Australia. We do not use overseas data centres for storage or processing of client information.
Encryption
All data is encrypted using AES-256 encryption at rest and TLS 1.3 in transit — the same standard used by Australian banks. This means your clients' identity documents and personal information are unreadable even in the unlikely event of a server breach.
Privacy Act compliance
CompliDesk is built to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Key commitments include:
- We only collect information necessary to provide the service
- We never sell or share client data with third parties for marketing
- Clients have the right to access and correct their personal information
- We notify affected parties in the event of an eligible data breach under the Notifiable Data Breaches scheme
Tax File Number (TFN) handling
TFNs are subject to strict legislative protections under the Privacy Act 1988 and the Tax File Number Rule 2015. CompliDesk handles TFN data in strict accordance with these requirements. TFNs are encrypted separately, access-controlled, and never stored in plain text.
Access controls
Multi-factor authentication
MFA is mandatory for all CompliDesk accounts. No exceptions.
Role-based access
Staff only see client data relevant to their role. Partners, managers, and staff have different permission levels.
Audit logging
Every login, data access, and change is logged with a timestamp. Full audit trail for AUSTRAC inspection.
7-year retention
Records are retained for 7 years as required by AUSTRAC — then securely deleted.
Regular backups
Automated daily backups with point-in-time recovery. Your data is never lost.
SOC 2 alignment
Our security practices are designed to align with SOC 2 principles for availability, confidentiality, and integrity. We have not yet completed a formal SOC 2 audit.
Infrastructure & Availability
CompliDesk is built on enterprise-grade infrastructure designed for reliability and scale:
- Hosting: Vercel global edge network — auto-scales to handle any load with no single point of failure
- Database: Supabase on AWS ap-southeast-2 (Sydney) — managed PostgreSQL with automatic failover
- CDN: Vercel Edge Network — pages served from the closest data centre to your users
- Session security: Sessions expire after 30 minutes of inactivity
- Uptime target: 99.9% — both Vercel and Supabase publish live status at status.vercel.com and status.supabase.com
Your responsibilities
Security is a shared responsibility. As the account holder, you are responsible for:
- Keeping your login credentials confidential
- Enabling MFA on all staff accounts
- Removing access for staff who leave your firm promptly
- Reporting any suspected unauthorised access to us immediately
Questions about security
If you have specific security questions or concerns, please contact us at support@complidesk.com.au. We take security enquiries seriously and will respond within 1 business day.