Security

Altaris
Trust Centre

Your deal documents contain some of the most sensitive commercial information you'll handle. Here's exactly how we protect them.

🔒

AES-256 Encryption

All documents and data encrypted at rest using AES-256. Data in transit protected by TLS 1.3.

🇦🇺

Australian Data Residency

Your data is stored in AWS ap-southeast-2 (Sydney). Data does not leave Australia unless you explicitly use an overseas specialist.

🚫

No AI Training on Your Data

Your documents and deal data are never used to train or fine-tune AI models. Analysis is performed on-demand for your use only.

Security Controls

How we protect your data

Infrastructure

AWS Sydney region (ap-southeast-2)

All primary data storage in Australia. Compliant with Australian data sovereignty requirements.

Isolated per-account storage

Your documents stored in a separate, isolated bucket. No other user can access your data.

Automatic document deletion

Documents deleted 90 days after a deal is closed or archived, or immediately on your request.

Daily encrypted backups

All data backed up daily with 30-day retention in a separate AWS region.

Access & Authentication

Two-factor authentication (2FA)

Optional 2FA via authenticator app. Enforced on Concierge plan.

Password hashing (bcrypt)

Passwords never stored in plaintext. All passwords hashed using bcrypt with a per-user salt.

Session management

Sessions expire after 24 hours of inactivity. All sessions invalidated on password change.

Role-based access controls

Altaris staff have no access to your documents. Internal systems follow least-privilege principles.

Compliance

Regulatory compliance

Privacy Act 1988 (Cth)

We comply with the Australian Privacy Principles (APPs). Privacy Officer appointed. Users may request access to or deletion of personal information at any time.

Australian Consumer Law

Our Terms of Service are governed by Australian Consumer Law. Consumer guarantee rights are not excluded. ACL refund rights apply where services are not of acceptable quality.

Notifiable Data Breaches

We comply with the NDB scheme under Part IIIC of the Privacy Act. In the event of an eligible data breach, affected users and the OAIC will be notified within 30 days.

Report a Security Issue

If you discover a vulnerability in the Altaris platform, please report it responsibly. We commit to acknowledging reports within 48 hours.

security@altaris.app
Privacy Enquiries

For questions about how we handle your personal information, or to lodge a complaint with the OAIC, contact our Privacy Officer.

privacy@altaris.app