AML/CTF obligations for Tranche 2 businesses are now in force. Since 1 July 2026 Get compliant

Security

How We Protect Your Data

AML Guard handles sensitive personal information as part of the compliance process. We take the security of this data seriously.

Current Controls

Data Hosting

AML Guard’s core compliance data (including CDD records, screening results, risk assessments, and vault evidence) is hosted on Amazon Web Services (AWS) in the Sydney region (ap-southeast-2). AWS Sydney holds IRAP PROTECTED certification and is used by Australian government agencies and financial institutions.

Limited operational data may be processed by carefully selected service providers outside Australia, such as our authentication and payment providers. Details are described in our Privacy Policy.

Encryption

Network Protection

Access Control

Authentication

Role-Based Access Control (RBAC)

AML Guard enforces role-based access control at both the application and API level. Compliance officers, administrators, and standard users have different permission sets. Sensitive actions: such as approving risk assessments, submitting suspicious matter reports, and accessing the evidence vault, require officer-level permissions.

Tenant Isolation

AML Guard is a multi-tenant platform. Each agency’s data is logically isolated at the database level. The platform is designed and controlled to prevent cross-tenant data access. All API requests are validated against the authenticated tenant context.

Compliance Evidence & Retention

All compliance actions are logged to an immutable audit trail: identity verifications, screening results, risk assessments, officer decisions, case status changes, and evidence submissions. The platform is designed to prevent modification or deletion of audit records, including by administrators.

Compliance evidence is stored in a dedicated encrypted vault with time-limited access controls. Evidence is retained for at least 7 years, as required by the AML/CTF Act.

From 1 July 2026, in line with OAIC guidance, AML Guard stores structured verification results rather than copies of original identification documents.

Resilience & Recovery

Infrastructure Resilience

AML Guard is built on managed serverless infrastructure where the underlying compute, database, and storage services are designed for high availability across multiple data centres within the Sydney region.

Web Application Firewall Hardening

Backup & Recovery

Third-Party Integrations

AML Guard integrates with third-party services for identity verification, sanctions screening, and company registry lookups. All third-party integrations use encrypted API connections. Data shared with third parties is limited to what is necessary for the specific compliance function. Our identity verification and screening services are powered by providers holding ISO 27001 and SOC 2 certifications.

Evidence Integrity & Record-Keeping

Regulatory enquiries often require agencies to show a complete, defensible record of compliance activity. AML Guard is designed to reduce that burden by continuously linking compliance activity with relevant records from connected systems such as email, CRM and accounting. The result is a clear chronology that helps compliance teams show when a party first made contact, what checks were performed, what financial context was available, and what decisions were taken along the way: from a single platform, with a defensible audit trail.

What underpins AML Guard's evidence integrity

Evidence integrity

Every evidence item is hashed with SHA-256 on upload. The hash is stored on the record and verified on download. Evidence snapshots are immutable: once written, they are never updated, preserving the exact state at the time of capture.

Tamper-evident audit trail

Every compliance action (identity checks, screening results, risk assessments, officer decisions, status changes) is logged with user identity and timestamp in a dedicated audit event store with 8-year retention.

Encrypted retention

All compliance evidence is encrypted at rest with AES-256 via AWS KMS and retained for at least 7 years with tiered storage (Standard, Infrequent Access, Glacier), as required by the AML/CTF Act.

Legal hold

Application-level hold prevents deletion of case evidence during active reviews or regulatory enquiries. Evidence under hold remains accessible but immutable until the hold is released by an authorised officer.

Evidence pack export

Case evidence can be exported as structured packs: ZIP bundles containing evidence items, audit trail, CDD completion reports, and SHA-256 integrity manifest, ready for AUSTRAC or external audit review.

Multi-source data ingestion

AML Guard connects to email, CRM, and accounting systems, continuously ingesting records that can be searched and correlated with compliance activity to support rapid regulatory response.

Case review workspace

Multi-layer timeline workspaces allow compliance teams to combine search results from different systems as colour-coded layers on a single chronology: with findings, activity logging, and export to structured evidence packs.

Review and sign-off workflow

Case reviews follow a structured cycle: draft, submitted for review, approved, supporting segregation of duties between the officer who builds the case and the manager who signs it off.

See all features →

Incident Response

AML Guard maintains incident response procedures for security events. In the event of a data breach affecting personal information, we will notify affected parties and the relevant authorities (including the OAIC) in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988.

Continuous Improvement

We regularly review and update our security controls. Our roadmap includes working towards SOC 2 Type II alignment and independent penetration testing.

For specific security questions or to request our security documentation:

[email protected]

See also: Privacy Policy · Terms of Service · About AML Guard