Data Residency

Your data stays in Australia.

Infrastructure hosted in Sydney. Documents, analysis results, and audit trails stored on Australian soil — encrypted, tenant-isolated, and retained for 7 years.

Infrastructure

Sydney-hosted. No exceptions.

Our backend API, database, and file storage all run on Sydney-region infrastructure. Your PDS documents, analysis results, client data, and audit logs never leave Australian data centres.

  • Backend API and database — Sydney, Australia (ap-southeast-2)
  • All storage AES-256 encrypted at rest
  • Frontend delivered via CloudFront CDN with ACM certificates
  • No US, EU, or third-country storage for customer content
Service
Function
Region
Backend API
REST endpoints
🇦🇺 Sydney
Database
PostgreSQL
🇦🇺 Sydney
File Storage
Document uploads
🇦🇺 Sydney
AI Processing
Anthropic Claude
Zero retention
Payments
Stripe
🇦🇺 AUD
CDN
CloudFront
🇦🇺 Edge
Data flow — PDS analysis
Your browser uploads PDS
TLS 1.3
Stored on backend — Sydney
AES-256
Sent to Claude API for analysis
TLS 1.3
Anthropic discards — zero retention
Not stored
Results stored — Sydney
7-year
AI Data Handling

Anthropic processes. Then discards.

Documents are sent to Anthropic's Claude API for processing. Anthropic does not store, retain, or train on your data. Processed in-memory and discarded immediately. Results stored by us — in Sydney.

  • Zero data retention by Anthropic — contractually enforced
  • Documents processed in-memory only — never written to Anthropic storage
  • Your data is never used for model training
  • Data Processing Agreement in place with Anthropic
  • All API calls encrypted via TLS 1.3
Compliance

Built for Australian regulatory requirements.

Data residency isn't just a hosting decision — it's a regulatory requirement for many Australian financial services firms.

Privacy Act — APP 8

Cross-border data disclosures documented transparently. Privacy policy names Anthropic as a subprocessor with zero-retention processing.

APRA CPS 234

Encryption at rest, tenant isolation, access controls, and incident logging aligned with APRA information security expectations.

7-Year Retention

Corporations Act record-keeping obligations. Every analysis, AI interaction, and audit event retained in Sydney for the full period.

Multi-Tenant Isolation

Every firm's data completely separated at the database level. Tenant-scoped queries enforced on every API request.

SOC 2 Infrastructure

Infrastructure providers maintain SOC 2 Type II compliance — independently audited for security, availability, and confidentiality.

Data Portability

Your data is yours. Export all documents, analyses, and audit logs at any time. Full data export and deletion on request.

Encryption

Encrypted at every layer. No exceptions.

Data is encrypted both in transit and at rest. There is no point in the system where your documents exist in an unencrypted state on persistent storage.

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for all data at rest
  • HTTPS enforced on all endpoints
  • Authentication tokens hashed — never stored in plaintext
Encryption standards
In Transit
TLS 1.3
All connections
At Rest
AES-256
All storage
Tokens
Hashed
bcrypt
Retention
7 Years
Sydney only
Contact

AI-powered insurance.
Coming soon.

We're here to answer your questions. We usually reply within one business day.

Prefer email? Write to hello@insuranceadvice.app