Security & compliance

Built to survive the audit before it’s scheduled.

You handle passports, medicals, and money you don’t own. We architected ImmiPro the way we’d architect our own practice.

Data sovereignty
100% hosted in Australia (AWS Sydney, ap-southeast-2). No data leaves the country at rest.
Encryption
TLS 1.3 in transit. AES-256 at rest. Field-level encryption for sensitive PII (passport, MRZ, medical).
Access control
MFA mandatory for staff. Fine-grained RBAC across seven roles. Immutable audit log for every admin action.
Compliance
ISO 27001:2022 controls. OMARA Code aligned. NSW Law Society trust. Australian Privacy Principles + NDB scheme.
Auditability
Append-only event log for financial and lodgement actions. 7-year retention. Auditor-ready exports.
Breach preparedness
Detection, playbook, and 72-hour Notifiable Data Breach workflow baked in. Quarterly pen-tests.
Compliance map

Every regulation that touches a practice — mapped to product controls.

Migration Agents Code of Conduct Regulations 2021
OMARA Sanction Schedule
Australian Privacy Act 1988 + APPs
Notifiable Data Breaches scheme
NSW Law Society Trust Account Regulations
AUSTRAC AML/CTF (Tranche-2 ready)
Electronic Transactions Act 1999