Security & Compliance

How we protect you and your clients' data.

Encryption

Traffic is encrypted in transit over TLS. Tax file numbers and stored integration credentials are encrypted at rest with AES-256-GCM using a per-record derived key. This is not KMS envelope encryption, and automated key rotation is on our roadmap rather than in place today.

Australian Data Storage

Documents and audit archives are stored in the AWS Sydney region (ap-southeast-2), enforced in production. Where you enable AI features, the content sent to the model provider is de-identified first and may be processed outside Australia — that disclosure is described in our privacy terms.

Built for ASIC Obligations

Built-in guardrails to help you meet Section 961B Best Interest Duty requirements, with a tamper-evident audit trail behind advice decisions.

Ongoing Security Review

We run an internal code audit programme against the platform and automated dependency vulnerability scanning on every build. We have not yet commissioned a third-party penetration test.

Australian Financial Services Standards

FinPlanPro is designed specifically for the Australian regulatory environment, and we run a standing internal compliance review programme against the platform. We hold no external certification or attestation, and nothing here is a substitute for your own licensee's obligations.

Designed to the APPs
Built for ASIC RG 175 / RG 256