Skip to main content

Trust & compliance

Compliance isn't a department here. It's code.

Every contact window, frequency cap, hardship hold and disclosure requirement is enforced by the platform itself — automatically, per account, per channel, per timezone. People can forget rules. Software doesn't.

Regulatory framework

Built around Australian law, not retrofitted to it.

ACCC / ASIC Debt Collection Guideline (RG 96)

Contact-hour windows, weekly and monthly frequency caps, workplace-contact restrictions and channel opt-outs enforced automatically. Attempts outside the rules are blocked before they happen.

Privacy Act 1988 & the APPs

Identity verified before any debt is discussed. Field-level encryption for sensitive identifiers, strict retention schedules, and a rehearsed notifiable-data-breach workflow.

Financial hardship obligations

A hardship notice instantly holds all collection activity pending assessment, with structured workflows, written outcomes and no default listing while under consideration.

Dispute & complaint handling (RG 271-aligned)

Disputes auto-hold the account. Complaints enter a register with mandated acknowledgement and resolution timeframes, and AFCA-ready case files where applicable.

Spam Act 2003

Sender identification and functional unsubscribe on every electronic message, with universal suppression handling — because it's the law, and it's also just good manners.

State compliance & limitation periods

Operating in compliance with state-specific debt collection regulations across every state where we contact customers. Statute-of-limitations tracking per state is built into the ledger itself.

Security & data

Collections data is among the most sensitive there is. We treat it that way.

Close-up of server hardware in a data-centre rack, network cabling lit against the chassis.

Australian data residency

All customer PII stored and processed in AWS Sydney (ap-southeast-2), multi-AZ.

Encryption everywhere

TLS 1.2+ in transit, KMS-managed encryption at rest, field-level encryption for sensitive identifiers.

Zero-trust access

SSO and MFA everywhere, least-privilege IAM, just-in-time production access with session recording.

Immutable audit trail

Who saw what, who changed what, when — logged immutably. Audit requests are routine; so are our answers.

PCI DSS SAQ-A

Card data never touches our platform — tokenised at the gateway, keeping the strictest possible scope.

Certification roadmap

ISO 27001 and SOC 2 Type II audits underway, targeted within our first 18 months of operation.

Responsible AI

Automation with a conscience — and an audit log.

Machine learning decides when and how to reach out. It never gets to improvise the facts, hide that it's a machine, or stand between a vulnerable person and a human.

AI never invents facts about a debt

Every statement about an account comes from ledger data via retrieval — generation is for tone, never for truth.

Automation always identifies itself

Automated messages are labelled where required, voice AI discloses it's automated, and a human is always one step away.

Vulnerability overrides automation

Hardship, domestic violence and self-harm indicators immediately suppress automation and route to trained specialists. We test this like a safety system, because it is one.

Every decision is explainable

Send, hold, offer or response — each automated decision is logged with inputs, model version and rationale, reproducible on demand. Strategy models are reviewed quarterly for proxy discrimination.

Ask us the hard questions.

Due-diligence pack, security overview and compliance documentation available under NDA.