Security & data residency

Your data, hosted in Ireland

Your firm’s AML records are among the most sensitive data you hold. This page sets out plainly where that data lives, how it is protected, who processes it, and what happens when the retention clock runs out. No vague assurances — just the specifics EU buyers are right to ask for.

EU data residency

Hosted in the EU, from the database up

CompliDesk Ireland runs on its own EU infrastructure, fully separate from our Australian deployment. Your customer and KYC data resides in the EU.

Supabase · AWS eu-west-1 (Dublin)

Database & storage

Your client files, CDD records and screening evidence live in Supabase, hosted on AWS eu-west-1 in Dublin. Database and file storage sit in the same EU region.

Vercel

Website delivery

The website and application are delivered through Vercel. Hosting is configured for the Ireland deployment as its own isolated project and environment.

Ireland deployment · EU region

EU-resident by design

CompliDesk Ireland customer data stays in the EU. That is an architectural decision — a separate EU deployment — not a checkbox on a shared system.

How we protect it

Concrete measures, honestly stated

These are the controls actually in place — not aspirations.

Encryption in transit

All traffic between your browser and CompliDesk is encrypted with TLS. There is no unencrypted access to the platform.

Encryption at rest

The database and file storage holding your client records are encrypted at rest.

Row-level security

Access control is enforced inside the database itself. Row-level security policies mean one firm’s records are never queryable by another firm.

Role-based access

Access within your firm is governed by roles, so staff see what their role requires — and your audit trail records who did what.

Least-privilege service keys

Backend services run on scoped, least-privilege keys. No component holds broader access to your data than its job requires.

No scripts without consent

No analytics or marketing scripts load until you consent. Non-essential cookies are blocked by default, with granular preferences.

What we don’t claim

We do not currently hold SOC 2 or ISO 27001 certification, and we won’t pretend otherwise. What you get instead is this page: a specific, truthful account of our controls. If your firm runs vendor security questionnaires, we’ll answer them directly — admin@complidesk.com.au.

GDPR

Clear roles, written down

GDPR compliance starts with knowing who is responsible for what. Here is how the roles fall.

You are the controller. We are the processor.

For personal data your firm holds on the platform — client identities, CDD records, screening results — your firm is the controller and CompliDesk is the processor. An Article 28 Data Processing Agreement is available and forms part of our terms. Read the DPA.

Breach notification

If a personal data breach occurs, we notify affected customers without undue delay so you can meet your own obligations under Articles 33 and 34 GDPR — notification to the supervisory authority and, where required, to data subjects.

Data subject rights

Access, rectification, erasure and the other GDPR data subject rights are honoured. As processor, we support your firm in responding to requests from your clients. Details are in our Privacy Policy.

Sub-processors

Who processes data on our behalf

We keep the list short and public. Each provider is engaged under processor terms, and services marked for launch are engaged as the platform goes live.

Sub-processorRoleStatus / region
SupabaseDatabase and file storageEU region — AWS eu-west-1 (Dublin)
VercelWebsite and application hostingActive
StripePayment processingFrom paid launch
ResendTransactional emailFrom platform launch
DiditKYC / KYB identity verificationActive at platform launch
AnthropicAI analysis of screening resultsActive at platform launch
ZohoCRM and email campaignsActive
Retention & deletion

Keep for five years. Then delete.

Regulation (EU) 2024/1624 (AMLR) requires obliged entities to retain records for five years — and then delete them. Most software treats deletion as an afterthought. CompliDesk treats it as a feature: record retention with 5-years-then-delete is built into the product, so your firm can meet both halves of the duty without a manual clean-up exercise.

The same discipline serves GDPR storage limitation: data your firm no longer has a legal basis to hold shouldn’t sit in a database indefinitely.

How it works in the product

Retention periods tracked against each record

Deletion when the retention period ends

Audit trail of retention and deletion actions

Responsible disclosure

Found something? Tell us.

If you believe you’ve found a security vulnerability in CompliDesk, we want to hear about it. Email admin@complidesk.com.au with the details and we’ll investigate promptly, keep you informed, and credit good-faith reports if you’d like us to. Please give us reasonable time to fix an issue before disclosing it publicly.

Get AMLR-ready

Sensitive data deserves a straight answer

See how CompliDesk Ireland handles your firm’s AML data in practice — or join the waitlist for free early access ahead of the 10 July 2027 deadline.