Skip to main content
Create Free Account

Security

Certified Since 2019. Hosted in Australia. Read-Only to AI.

Every record hosted in Australia and encrypted at rest and in transit. Inside the product, a new staff user sees nothing until you say so. Outside it, every token and every AI assistant can read, and only read.

  • ISO 27001 certified ISO 27001Certified since 2019
  • AWS Qualified Software AWS Qualified SoftwareSince 2023
  • GDPR, General Data Protection Regulation GDPRSince 2020
  • IT & Security
  • Procurement
  • Legal & Risk
  • Safety & HSE
  • HR
All data hosted within Australia, encrypted at rest and in transit

What Security in ComplyFlow Means.

Security in ComplyFlow is a certification you can check, data that stays in Australia, and a permission model that starts from nothing. ISO 27001 since 2019, AWS Qualified Software, encrypted at rest and in transit, MFA through your identity provider, and an outer edge for tokens and AI that can only read.

  • Certified, hosted here, encrypted. ISO 27001 since 2019, AWS Qualified Software since 2023, GDPR since 2020, all data in Australian data centres, encrypted at rest and in transit.
  • Your identity provider signs people in. Microsoft or Okta through OAuth 2.0, short-lived tokens, no password stored; your MFA and conditional access policies apply. Two-factor for staff and Workers without SSO.
  • Nobody sees anything by default. A permission scheme grants access by module and by site, with a separate gate on personal information.
  • Everything outside the product can only read. Tokens carry read scopes only, expire within a year, and inherit the user’s permissions. The AI assistant cannot change a thing.
An IT security lead at a desk in an Australian corporate office working through a printed vendor security questionnaire beside a laptop, a pen in hand

The Model

Five Rings Around Every Person. Reads Go Through. Writes Do Not.

Read it from the outside in: what has to be true before anyone, or any assistant, sees a record.

  1. 1 Certified, hosted in Australia, encryptedISO 27001 since 2019, AWS Qualified Software since 2023, all data within Australia, encrypted at rest and in transit.
  2. 2 One organisation, one boundaryA login or a token belongs to one organisation and cannot cross to another.
  3. 3 The permission schemeNo access by default; read or read and write per module, admin on forms, incidents, and inspections, applied from a named scheme.
  4. 4 Assigned sites onlyA toggle per module limits a user, and any token they make, to the sites they work at.
  5. 5 The HR gateNext of kin, allergies, and CVs behind a separate permission most staff never hold.

Tokens and the MCP server are read-only by design. Inside the product a person with the right scheme makes every change, and the record says who and when.

1 2 3 4 5 The person Read: in, and back out Write: turned away

What It Covers

The Whole Model, Not the Highlights.

Everything below is documented in the Help Centre or on the record, and nothing here is a claim we cannot show you.

Certification & Hosting

Who Sees What

Identity & the Outer Edge

Where the Help Centre documents an item, its name links to the article.

How It Works

Four Screens That Carry the Model.

A user’s permissions, the tokens outside the product, the approval that is on the record, and the assistant that can only read.

The User Who Sees Only Their Sites.

A site safety lead is given the Site Safety Lead scheme: read and write on Workers and inspections, admin on incidents, read on the risk register, every one limited to her two assigned sites. Staff records she cannot see at all.

  • No access, R, or RW per module; Admin on forms, incidents, inspections
  • Entire organisation or assigned sites only
  • Update the scheme, tick once, everyone on it moves

The Tokens, and What Each May Read.

Every tool outside the product holds a personal token named for what it is. Each carries only read scopes, expires within a year, and inherits the permissions of the user who made it. The value is shown once.

  • Read scopes only, per module
  • Expiry from 7 days to one year
  • Revoked on confirmation; up to 10 per user

The Approval That Is on the Record.

A Worker’s licence is approved by a named staff member on a dated day, with the expiry read from the document and the reason if it is rejected. Documents are visible only to the roles you name.

  • Who approved, when, against what
  • Visibility by role, per document category
  • AI recommends; a person decides

The Assistant That Can Only Read.

A safety manager asks their assistant which sites reported incidents this month. Through MCP it reads the register with the scopes on their token and their own site permissions. There is no tool for creating, changing, or deleting.

  • Four layers: token, scopes, permissions, isolation
  • Claude, Claude Code, and GitHub Copilot
  • Read-only by design, not by policy

Who It Is For

What the Security Model Means for Me.

Find your job. The three lines under it are what the model changes for you.

ComplyFlow Is Already Trusted.

Security teams at property, transport, resources, manufacturing, government sites, and more have already reviewed ComplyFlow.

  • Toll
  • National Intermodal
  • BlueScope
  • ISPT
  • Maersk
  • NSW Planning, Industry and Environment

Book a Demo

Bring Your Security Questionnaire. We Will Answer It Live.

A 30-minute call with someone who has been through procurement reviews for terminals, towers, and government sites: the certificate, the policy, the permission model, and your questions, answered on the spot or in writing afterwards.

  • A permission scheme built for one of your roles, limited to its sites
  • A read-only token created, scoped, and revoked in front of you
  • Your questionnaire answered line by line, in writing afterwards where needed
Talk to Us Instead

No slides, no hard sell. A working session on your own set-up.

Book Your Demo

Thirty minutes, on your own requirements.

Book Demo

The form loads from HubSpot. If it does not appear, the button takes you to the demo request page.

An open filing cabinet drawer of contractor personnel files in a site office, manila folders with handwritten tabs, a medical form half pulled out, everything too soft to read

How It Stacks Up

Where Compliance Data Usually Lives, and What Each Misses.

Most compliance data lives on a shared drive and a spreadsheet, in a generic forms tool, or in a point solution with one login for everyone.

Shared drive and spreadsheetEveryone with the link sees everything, including next of kinA generic forms toolPermissions by form, not by site or by kind of dataA point solution, one loginSecure at the door; little between users once inside ComplyFlowOne record, your standard
ISO 27001 certified, hosted in Australia Not therePartlyPartly Certified since 2019; AWS Qualified Software; all data within Australia
Encrypted at rest and in transit PartlyBuilt inBuilt in Every record and every connection
MFA through your identity provider PartlyPartlyPartly Microsoft and Okta SSO; two-factor without SSO
No access by default for a new user Not therePartlyNot there Nothing until a scheme is applied
Access limited to assigned sites, per module Not thereNot therePartly A toggle per module; recommended by the Help Centre
External tools and AI read-only, scoped, expiring Not therePartlyPartly cf_pat_ tokens; MCP cannot write

This compares kinds of approach, by how they are sold, not named vendors. Named comparisons, with dates and sources, live on the comparison pages.

Getting Started

We Set It Up With You. We Stay With You.

You are not handed a superuser login and left to it. Our onboarding team turns your roles into schemes, connects your identity provider, and stays on hand once your people are in.

  • Mitch Bourne, ComplyFlow
  • Jessica Morgan, ComplyFlow
  • Sam Bourne, ComplyFlow
  • Phil Wallach, ComplyFlow
  • John McCann, ComplyFlow
  1. 1 We Answer Your Security Review

    The ISO 27001 certificate, the Information Security Policy, where your data lives, and written answers to your questionnaire.

  2. 2 We Build Your Schemes

    Your roles become named permission schemes, each limited to the modules and sites the role needs.

  3. 3 We Connect Identity

    Single sign-on from Microsoft or Okta with your MFA, SSO-only where you want it, two-factor for everyone else, and scoped tokens for your tools.

  4. 4 You Go Live, We Stay Close

    Training for your administrators, a Help Centre for everyone, and a support team that picks up the phone.

Questions

Questions Security Teams Ask Before a Demo.

Is ComplyFlow ISO 27001 certified?

Yes. Comply Flow Pty Ltd has held ISO/IEC 27001 certification since 2019, and AWS Qualified Software status since 2023. Ask for the certificate as part of your review and we will provide it, with its issue date and certifying body.

Where is our data hosted, and how is it protected?

In Australian data centres, on Amazon Web Services, as AWS Qualified Software, encrypted at rest and in transit. The service has been GDPR compliant since 2020. Backup, recovery, and testing arrangements are set out in the Information Security Policy, which we send on request.

Do you support single sign-on and multi-factor authentication?

Yes. Microsoft sign-on uses OAuth 2.0 with short-lived tokens and no password stored, and your MFA and conditional access policies apply to ComplyFlow. Okta is supported. Staff without SSO can use two-factor authentication, and it can be enforced for Workers. A per-user setting allows login through sign-on links only.

How do you stop a staff user seeing another site’s data?

Every module has an Entire Organisation or Assigned Sites Only setting. With Assigned Sites Only, a user sees Workers, inspections, incidents, and the rest only for the sites they are assigned to, and a new user has no access at all until a scheme is applied.

Who can see personal information like next of kin or medical details?

Only staff holding the HR permission. Next of kin, allergies, CVs, and HR attributes sit behind it and are hidden from everyone else. Incidents carry their own security groups, and document categories are visible only to the roles you name.

What can an AI assistant do with our data through MCP?

Read it, within limits. A personal token carries only read scopes for named modules, expires within a year, inherits the permissions and site assignments of the user who created it, and belongs to one organisation. The assistant can look up and summarise; it cannot create, change, or delete.

See the Model on Your Own Terms.

Book a 30-minute demo and bring your security lead. We will build a permission scheme for one of your roles live, create and revoke a token, and answer the questionnaire questions on the spot. No slides, no hard sell.

  • ISO 27001
  • Hosted on AWS
  • Microsoft & Okta SSO
  • API & MCP
  • Data in Australia

Compliance you can prove, instantly.