Security & Trust

Security at MindLedger

Where client data is stored, what the AI models receive, who can access it, and how we manage security at MindLedger.

Sydney, Australia
Client data stored and backed up only in Australia
AES-256 + TLS
Encrypted at rest and in transit, with application-level encryption on identifiers
Zero training
Client data never trains an AI model — contractual with every provider, no carve-outs
PI + cyber
Our own professional indemnity and cyber insurance — certificates of currency at onboarding
Your Obligations

Your professional obligations still apply. Here’s how we support them.

Using MindLedger doesn’t change your duties under the Privacy Act, the TPB Code, or TASA. Four questions cover them — here is our answer to each.

“Am I taking reasonable steps to secure client information?”

APP 11, Privacy Act 1988 — reasonable steps against misuse, loss, and unauthorised access.

Our answer

Australian data residency, encryption in transit and at rest, least-privilege access, and a breach response plan aligned to the Notifiable Data Breaches scheme. The full specification is below.

“Am I keeping client information confidential?”

TPB Code of Professional Conduct item 6; APES 110 s114 — no disclosure without permission, surviving the engagement itself.

Our answer

Firm data segregated per customer, access role-based and logged, nothing sold or shared — and those terms survive any sale or change of control of MindLedger.

“Can I demonstrate reasonable care over work I didn’t prepare?”

TASA s30-10 — supervision and reasonable care sit with the registered agent, always.

Our answer

MindLedger works under your supervision — we are never the registered agent. Every work packet is built to evidence substantive review: figures traced to source, assumptions ranked by risk, and what the agent didn’t do stated on every job.

“Have I told my clients?”

TPB disclosure obligations for outsourced and offshore arrangements — your clients get a say.

Our answer

We help firms meet their disclosure obligations, with template wording for engagement letters and plain-English client communications — ask us at [email protected].

The Data Journey

Where your clients’ data goes — the whole path

Most security pages tell you where data is stored and go quiet about where it’s processed. Here is every step.

You send the job

Your firm sends the work and its source documents over an encrypted connection. Agents receive the job in front of them — never your client base.

Stored in Australia

Client records, documents, and work products are stored in Sydney, encrypted at rest, with encrypted backups retained in Australia. Storage never leaves the country.

Identifiers stripped, onshore

Before any AI model sees the job, tax file numbers, dates of birth, and bank account numbers are detected and replaced with tokens — on Australian systems. The models never receive them.

Processed, not retained

The job is processed by commercial AI models in the United States under contractual no-training, no-retention terms. Processing copies are deleted under contract when the job ends.

Returned, on the record

The completed work packet comes back to your firm — every figure traced to source, every decision logged with its reasoning — and is stored in Australia.

Our Commitments

Our commitment to you in three statements

01

Your client data never trains an AI model — ours or anyone’s. There is no “de-identified improvement” carve-out.

02

We never sell or share client information. Our revenue is fees for completed work — not your data.

03

No firm’s data is pooled with, visible to, or used for the benefit of any other firm.

The Specification

The controls, row by row

In the form your reviewer’s checklist wants it. What this table doesn’t cover, the due-diligence pack addresses — ask us.

In transit
All connections into the platform are TLS-encrypted.
At rest
AES-256 across databases, documents, and backups, in Australia.
Identifiers & TFNs
Identifiers carry an additional layer of application-level encryption and are tokenised before any AI processing. TFNs are restricted data under the Privacy (TFN) Rule 2015: never used as identifiers, used only for the work you commission.
Key management
Encryption keys are held in a dedicated secrets vault, separated from the data they protect and from application code.
Access
Least-privilege, role-based access with per-firm segregation, and multi-factor authentication for firm logins and our own staff. Staff access to client data is limited to what a job requires, logged, and revoked on role change.
Agent containment
Agents prepare; they cannot lodge, send, or sign. We hold no lodgement credentials — lodgement happens in your own tax software, under your firm’s own access. Client documents are treated as data, not instructions, and we design and test against prompt-injection attacks.
Your connection
Your practice software is connected by scoped, revocable authorisation your firm grants directly — we never see or store your passwords, and you can cut the connection at any time.
Monitoring
Access and changes are logged end-to-end, and every agent decision is recorded with its reasoning, sources, and the rules it applied.
Backups
Automated, encrypted, retained in Australia, with point-in-time recovery.
Retention & ownership
Your client data belongs to your firm — using MindLedger grants us a licence to do the work you commission, nothing more. Working data is kept for the engagement; on offboarding, everything is exported to you, then deleted — confirmed in writing.
Common Questions

The questions your practice manager will ask

Is our client data used to train AI models?

+
No. Not ours, not our providers’, not anyone’s — and there is no “de-identified improvement” carve-out. The prohibition on training and retention is contractual with every AI model provider we use.

Where is our client data stored — and does anything leave Australia?

+
Client records, documents, and work packets are stored and backed up only in Australia, encrypted at rest. One step leaves, and we disclose it plainly: after tax file numbers, dates of birth, and bank account numbers are stripped and tokenised on Australian systems, the job is processed by commercial AI models in the United States under contractual no-training, no-retention terms. The full path is published on this page.

Can MindLedger staff see our clients’ data?

+
Staff access is limited to what a job requires, role-based, and logged end-to-end. Production access is restricted to authorised engineers and revoked on role change. Firm data is segregated per customer — your data is never visible to another firm.

What if the AI gets something wrong?

+
Like any AI system, our models can make mistakes. When we become aware of a defect, we patch it, fix what it affected, and improve the system. That’s why nothing goes to a tax authority without sign-off: every job runs on an individual accountant’s tax and compliance licence, and your accountant must review and sign off all work the system produces before it is submitted. That licence obligation stays with the accountant — it can’t transfer to MindLedger. MindLedger is a tool that helps accountants get work done more accurately and more efficiently; the professional judgment, and the responsibility that comes with it, remain with the accountant.

What happens if you have a data breach?

+
You hear from us within 72 hours with what we then know, and the detail your Notifiable Data Breaches assessment needs follows as the investigation confirms it. Affected clients are told too — your firm controls how, and by whom.

What if we leave — or you’re acquired or shut down?

+
Your data is continuously exportable in usable formats — working papers, source documents, audit trails — at any time, not just at exit. On offboarding we delete your firm’s data after export and confirm it in writing. If MindLedger is ever sold or winds down, your data comes out first, and these commitments survive any change of control.

Put us through your due diligence

Send us your vendor security questionnaire — typically answered within five business days — or request the documentation pack. We’d rather earn trust in writing than ask for it in a demo.

Request the security pack