Skip to main content
Create Free Account

Company News

ComplyFlow and AWS: What It Means for Your Data

ComplyFlow runs on Amazon Web Services, and our Help Centre states all ComplyFlow data is hosted within Australia. AWS secures the cloud itself; we secure what we build in it, so AWS's certifications answer only half of a vendor security review. The half that is ours is where a buyer's real questions sit, and the five below are the ones worth putting to any software vendor, including us.

  • Published
  • Updated
  • 5 min read
A pixel-art landscape of blocky green hills and a river under a rising sun, with the AWS logo above the word DEVCRAFT in large blocky letters
The architecture work behind this announcement changed how ComplyFlow runs. It does not change what a buyer should accept on trust.

Most people landing on this page are not after a press release. They are part-way through a vendor security review, with a line in the questionnaire about where the data is hosted. Here is the announcement, then the part that helps you answer it.

What We Announced in October 2025.

On 2 October 2025 we announced that ComplyFlow had worked with AWS through its DevCraft program: an architecture design session with AWS Solutions Architects that redesigned the infrastructure behind our AI features to carry several parallel AI workloads instead of one. Out of it came the automatic document review and faster prequalification processing we launched that month, timed for the WHS Safety Conference.

That is the whole of the news. On its own it is an engineering story, not a reason to buy anything. The sentence underneath it is the one that follows you into procurement: ComplyFlow runs on AWS. Our Help Centre article on platform architecture and hosting states that ComplyFlow has been qualified under the AWS Foundational Technical Review since 2023,1 a review AWS describes as an assessment against Well-Architected best practice in security, reliability, and operational excellence, valid for two years.2

What AWS Secures, and What We Secure.

The most useful thing to understand about any vendor that runs on AWS is that AWS does not secure the vendor’s software.

AWS publishes this as its shared responsibility model, and the split is clean. AWS protects the infrastructure that runs its cloud services: the hardware, the software, the networking, and the facilities.3 The customer of AWS, which here is ComplyFlow, is responsible for what it puts in it. AWS’s wording on data privacy is blunt: you own your customer content, you choose the Region it is stored in, you choose how it is secured, and you manage access through users, groups, permissions, and credentials you control.4

The consequence for a buyer is direct. Every question in your questionnaire about encryption keys, password policy, role-based access, audit logs, tenancy separation, retention, and deletion is about ComplyFlow, not AWS. No AWS certificate answers one of them, and our security page is where the answers live.

Where the Data Lives, and What We Have Published.

Our Help Centre states that all ComplyFlow data is securely hosted within Australia,1 which answers the data sovereignty question most Australian procurement teams ask first.

It does not name the AWS Region, and I am not going to guess at one here: a Region name in a marketing page is exactly the detail that gets copied into a contract schedule and turns out to be wrong. If your review needs it named, ask us and we will put it in writing.

Region matters more than the word suggests. AWS commits that it will not move or replicate your content outside your chosen Regions without your agreement,4 so the Region is a decision your vendor takes on your behalf. It also sits behind Australian Privacy Principle 8, on the steps an entity must take before personal information is disclosed overseas, and Australian Privacy Principle 11, which requires reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access.5

What AWS’s Certifications Cover, and What They Do Not.

AWS holds a long list of certifications and attestations, and vendors like putting the logos on a page. Two lines from AWS’s own compliance material are worth more.

The first is on AWS’s compliance programs page, where it appears twice: AWS customers remain responsible for complying with applicable compliance laws, regulations, and privacy programs.6

The second is on AWS’s ISO/IEC 27001 FAQ page. AWS’s certification covers its security management process over a specified scope of its own services and facilities, and AWS states plainly that a business is not certified by association.7 Running on certified infrastructure does not make the software certified.

ComplyFlow holds its own ISO 27001 certification, which we announced when we first achieved it and which the Help Centre still lists.1 That is the certificate relevant to you. Ask for it, and ask what its scope covers, because a certificate can cover part of a business rather than all of it.

AWS’s own auditor-issued reports sit behind AWS Artifact, a self-service portal reached through an AWS account.8 If you do not hold one, do not chase them: they describe AWS, not the software running on it.

Five Questions to Ask Any Software Vendor About Hosting.

  1. Where is the data stored? Country and Region, named, and committed to in the contract.
  2. Who can access it? Which roles at the vendor can reach customer data, under what approval, and whether that access is logged.
  3. What happens on exit? In what format the data comes back, how long the vendor keeps it, and what evidence you get that it was deleted.
  4. What is the backup and recovery position? How often, where the copies sit, how long a restore takes, and when it was last tested.
  5. What does the certificate cover? The scope statement, not the logo, and whether that scope includes the service you are buying.

None of the five is answered by a hosting provider’s certificate. All five are answered by the vendor, or not at all.

Put the Five Questions to Every Vendor on the List.

If you hold the pen on this in compliance or legal, put the five questions to every vendor on your shortlist, not only to us. They sort a shortlist faster than a feature comparison does: most vendors can produce a feature, far fewer can produce a scope statement.

If you are the CFO signing it, press hardest on exit. It is the only one that gets more expensive after the signature.

If the questionnaire has a section on how ComplyFlow connects to the systems you already run, our integrations page covers it. Or book a demo and bring the questionnaire. We would rather answer it live than watch you guess.

Sources

  1. Platform Architecture and Hosting ComplyFlow Help Centre, 29 August 2025
  2. AWS Foundational Technical Review Amazon Web Services
  3. Shared Responsibility Model Amazon Web Services
  4. Data Privacy FAQ Amazon Web Services
  5. Australian Privacy Principles quick reference Office of the Australian Information Commissioner
  6. AWS Compliance Programs Amazon Web Services
  7. ISO/IEC 27001:2022 FAQs Amazon Web Services
  8. AWS Artifact Amazon Web Services
Rory McNeil

Written by

Rory McNeilHead of Marketing, ComplyFlow

Rory leads marketing at ComplyFlow. He writes about how safety and compliance teams find, judge, and buy software, and about the evidence behind the claims vendors make.

Writes about: Buying compliance software, Evidence and claims, ComplyFlow news

Questions

Questions People Ask About This.

Where is ComplyFlow data hosted?

ComplyFlow's Help Centre states that all ComplyFlow data is securely hosted within Australia, on AWS infrastructure. It does not name the specific AWS Region. If your security review needs the Region named, ask us and we will put it in the response in writing rather than leaving you to infer it from a marketing page.

Does ComplyFlow inherit AWS's certifications by running on AWS?

No. AWS says on its own ISO/IEC 27001 FAQ page that a business is not certified simply by association with AWS. AWS's certification covers AWS's security management process over a defined set of its own services and facilities. ComplyFlow holds its own ISO 27001 certification, and that is the one relevant to the software you are buying.

What is the AWS shared responsibility model?

It is AWS's published description of who secures what. AWS is responsible for protecting the infrastructure that runs its cloud services, which it calls security of the cloud. The customer of AWS, which in this case is ComplyFlow, is responsible for what it puts in that infrastructure: the data, the encryption options, the access controls, and the configuration. Questions about the second half go to us, not to AWS.

Can I see AWS's audit reports as part of my review of ComplyFlow?

AWS publishes its auditor-issued reports, certifications, and attestations through AWS Artifact, a self-service portal reached through an AWS account. If you do not hold one, there is little point chasing them. Those reports cover AWS, not the application running on it, so the documents that answer your questions about ComplyFlow have to come from ComplyFlow.

What should I ask a software vendor about hosting?

Five things, in writing: where the data is stored and in which Region, who at the vendor can access it and under what control, what happens to your data when the contract ends, what the backup and recovery position is, and whether the vendor's own certification covers the service you are buying or only part of the business.

See it against your own contractors, sites, and rules.

Book a 30-minute demo. We will show ComplyFlow working with your kind of sites, your kind of contractors, and your requirements. No slides, no hard sell.

  • ISO 27001
  • Hosted on AWS
  • Microsoft & Okta SSO
  • API & MCP
  • Data in Australia

Compliance you can prove, instantly.