Security & Data Residency

Your client data stays in Australia.
And only your firm can see it.

Trail Guardian holds the audit trail principals are personally liable for. We treat it like the regulator already has subpoena access - because functionally, they do. Here's exactly where your data lives, how it's protected, and what we promise never to do with it.

How we protect the data

Six controls, written in plain English so your compliance officer doesn't need a translator.

Hosted in Australia

Client records, audit metadata and uploaded documents are stored exclusively in AWS Asia Pacific (Sydney) - ap-southeast-2. Data never leaves Australian soil for storage or backup.

Encrypted end-to-end

TLS 1.3 in transit. AES-256 at rest via AWS-managed keys (SSE-KMS). Database connections use mutual TLS. Secrets are stored in an isolated vault, never in code or config files.

Tamper-evident audit vault

AFCA defence packs and audit exports are written with S3 Object Lock (Governance mode). Once stored, files cannot be modified or deleted by anyone - including us - until the retention window expires.

Versioned + backed up

Every object is versioned on write. Daily snapshots of the relational database are retained for 30 days with point-in-time recovery to any second in the last 7 days. Backups stay in Sydney.

Row-level access control

Every database read enforces row-level security tied to the signed-in user's firm. An adviser at firm A cannot see firm B's data, even with a leaked URL or session token.

Least-privilege infrastructure

Our application servers hold scoped IAM credentials that can read and write only your firm's prefix in S3. No standing access to all customer data - even for our engineers.

Regulatory alignment

Built for the frameworks Australian advice firms already operate under.

CPS 234

Information-security alignment for APRA-regulated entities and their third parties - encryption, access control, incident response and supplier oversight.

Australian Privacy Act 1988 / APPs

We handle personal information as an APP entity. Collection is limited, retention is bounded, and overseas disclosure is restricted to the Australian region.

Corporations Act record-keeping

Advice records, file notes and audit exports are retained for the statutory 7-year minimum, then transitioned to immutable cold storage.

AFCA defence-ready

30-second export of a tamper-evident audit pack for any policy holder, any date range, including the cryptographic hash chain that proves it has not been altered.

Trail Guardian is not a certifying body. We align our controls to these frameworks and provide evidence on request, but firms remain responsible for their own regulatory obligations.

Our written commitments

Four promises we'll put in writing in your master agreement.

  1. 01We will never sell, share or use your client data for marketing, model training or analytics outside your own firm's workspace.
  2. 02We will notify affected firms within 24 hours of confirming any unauthorised access to customer data, well inside the Notifiable Data Breaches scheme's 30-day window.
  3. 03We will give you a full export of every record, audit log and document on request within 5 business days - no exit tax, no proprietary format lock-in.
  4. 04We will publish material changes to this page with a dated changelog. The current version is effective from the date below.

Want our security questionnaire response?

We keep a current SIG-Lite and CAIQ on file, plus penetration-test attestations and our incident-response runbook. Email us and we'll send the pack within one business day.

This page effective from 7 August 2026.