Where client data is stored, what the AI models receive, who can access it, and how we manage security at MindLedger.
Using MindLedger doesn’t change your duties under the Privacy Act, the TPB Code, or TASA. Four questions cover them — here is our answer to each.
APP 11, Privacy Act 1988 — reasonable steps against misuse, loss, and unauthorised access.
Australian data residency, encryption in transit and at rest, least-privilege access, and a breach response plan aligned to the Notifiable Data Breaches scheme. The full specification is below.
TPB Code of Professional Conduct item 6; APES 110 s114 — no disclosure without permission, surviving the engagement itself.
Firm data segregated per customer, access role-based and logged, nothing sold or shared — and those terms survive any sale or change of control of MindLedger.
TASA s30-10 — supervision and reasonable care sit with the registered agent, always.
MindLedger works under your supervision — we are never the registered agent. Every work packet is built to evidence substantive review: figures traced to source, assumptions ranked by risk, and what the agent didn’t do stated on every job.
TPB disclosure obligations for outsourced and offshore arrangements — your clients get a say.
We help firms meet their disclosure obligations, with template wording for engagement letters and plain-English client communications — ask us at [email protected].
Most security pages tell you where data is stored and go quiet about where it’s processed. Here is every step.
Your firm sends the work and its source documents over an encrypted connection. Agents receive the job in front of them — never your client base.
Client records, documents, and work products are stored in Sydney, encrypted at rest, with encrypted backups retained in Australia. Storage never leaves the country.
Before any AI model sees the job, tax file numbers, dates of birth, and bank account numbers are detected and replaced with tokens — on Australian systems. The models never receive them.
The job is processed by commercial AI models in the United States under contractual no-training, no-retention terms. Processing copies are deleted under contract when the job ends.
The completed work packet comes back to your firm — every figure traced to source, every decision logged with its reasoning — and is stored in Australia.
Your client data never trains an AI model — ours or anyone’s. There is no “de-identified improvement” carve-out.
We never sell or share client information. Our revenue is fees for completed work — not your data.
No firm’s data is pooled with, visible to, or used for the benefit of any other firm.
In the form your reviewer’s checklist wants it. What this table doesn’t cover, the due-diligence pack addresses — ask us.
Send us your vendor security questionnaire — typically answered within five business days — or request the documentation pack. We’d rather earn trust in writing than ask for it in a demo.
Request the security pack →