ACCC / ASIC Debt Collection Guideline (RG 96)
Contact-hour windows, weekly and monthly frequency caps, workplace-contact restrictions and channel opt-outs enforced automatically. Attempts outside the rules are blocked before they happen.
Trust & compliance
Every contact window, frequency cap, hardship hold and disclosure requirement is enforced by the platform itself — automatically, per account, per channel, per timezone. People can forget rules. Software doesn't.
Regulatory framework
Contact-hour windows, weekly and monthly frequency caps, workplace-contact restrictions and channel opt-outs enforced automatically. Attempts outside the rules are blocked before they happen.
Identity verified before any debt is discussed. Field-level encryption for sensitive identifiers, strict retention schedules, and a rehearsed notifiable-data-breach workflow.
A hardship notice instantly holds all collection activity pending assessment, with structured workflows, written outcomes and no default listing while under consideration.
Disputes auto-hold the account. Complaints enter a register with mandated acknowledgement and resolution timeframes, and AFCA-ready case files where applicable.
Sender identification and functional unsubscribe on every electronic message, with universal suppression handling — because it's the law, and it's also just good manners.
Operating in compliance with state-specific debt collection regulations across every state where we contact customers. Statute-of-limitations tracking per state is built into the ledger itself.
Security & data

All customer PII stored and processed in AWS Sydney (ap-southeast-2), multi-AZ.
TLS 1.2+ in transit, KMS-managed encryption at rest, field-level encryption for sensitive identifiers.
SSO and MFA everywhere, least-privilege IAM, just-in-time production access with session recording.
Who saw what, who changed what, when — logged immutably. Audit requests are routine; so are our answers.
Card data never touches our platform — tokenised at the gateway, keeping the strictest possible scope.
ISO 27001 and SOC 2 Type II audits underway, targeted within our first 18 months of operation.
Responsible AI
Machine learning decides when and how to reach out. It never gets to improvise the facts, hide that it's a machine, or stand between a vulnerable person and a human.
Every statement about an account comes from ledger data via retrieval — generation is for tone, never for truth.
Automated messages are labelled where required, voice AI discloses it's automated, and a human is always one step away.
Hardship, domestic violence and self-harm indicators immediately suppress automation and route to trained specialists. We test this like a safety system, because it is one.
Send, hold, offer or response — each automated decision is logged with inputs, model version and rationale, reproducible on demand. Strategy models are reviewed quarterly for proxy discrimination.
Due-diligence pack, security overview and compliance documentation available under NDA.