SECURITY & DATA HANDLING
Your client's data stays in Australia.
You're about to put your clients' identity documents, contracts and financial details into someone else's software. That deserves a straight answer about where it goes and who can reach it. This page is that answer, in plain English.
Stored, processed and backed up in Sydney.
Not Singapore, not Ireland, not Virginia. Your deal files, your client records and your CDD documents sit on Australian soil, and the servers that read them are in the same city. This was a deliberate choice, made before we had a customer who would ask.
Three things we will never do.
Most of this page describes what we've built. This part describes what we've chosen not to build, which matters more.
We don't train on your data.
Your deal history, your file notes, the judgement your firm has built over years — none of it is used to train a model. What your agency knows stays your competitive advantage, not something a rival benefits from because you both use Trace.
We don't sell or share it.
No data brokers, no advertising networks, no "anonymised market insights" product built on your clients' transactions. Our subprocessors are limited to what's needed to run the service, and we'll name them on request.
We don't send an AI's opinion to your client.
Nothing reaches a client until you've reviewed and approved it. The traffic light, the risk rating and the client summary are always set by a person. Trace will not file a conclusion an AI reached on its own.
Your records are yours to take.
Export the full file for any deal, any time, in a format you can read without us. If you ever stop using Trace, we bundle your records — including the seven-year AML set — and hand them back. Custodianship is written into our terms, not left to goodwill.
Export on demand
Every finding, document, risk and audit entry for a deal, exported as a portable file. No support ticket, no fee, no waiting period.
Handover if you leave
Off-boarding includes a complete handover of your organisation's records. You're never in a position where leaving means losing your compliance history.
How the system is protected.
Described by what it guarantees rather than what it's built from — the specifics of our infrastructure aren't a useful thing to publish.
- Isolation between agencies
- One agency can never see another's deals, clients or documents. The boundary is enforced in the database itself, not only in the application — so a bug in one layer can't expose another firm's file.
- Access within your agency
- Members see what their role allows. Client-facing portals are scoped to a single deal and gated behind a PIN — a link on its own opens nothing.
- Encryption
- Encrypted in transit and at rest, everywhere. Identity documents collected for customer due diligence are held under separate key management from ordinary deal files.
- Tamper-evident audit trail
- Every access and every change is recorded, and each record is cryptographically linked to the one before it. Altering history breaks the chain visibly rather than silently.
- Backups & recovery
- Continuous backups with point-in-time recovery, held in the same Australian region as the live data. Restores are tested, not just enabled.
- Ongoing review
- Automated security review runs against every change before it ships, and dependencies are monitored for known vulnerabilities. Independent review is commissioned for the areas that handle identity data.
How long we keep things — and when we can't delete.
You can delete a deal, a document or a client record, and we'll remove it. There is one honest exception, and you should know about it before you start rather than after.
The exception
Records collected to meet AML/CTF customer due diligence obligations must be retained for approximately seven years. Where that applies, the retention requirement overrides a deletion request — for you and for us. We'll tell you which records are affected, and they're included in any handover if you leave. This is a legal obligation on reporting entities, not a Trace policy, and it's worth confirming how it applies to your business with your own adviser.
Found something?
If you believe you've found a security issue in Trace, we want to hear about it directly and we won't pursue researchers who report in good faith. Tell us what you found and how to reproduce it, and give us a reasonable window to fix it before publishing.