Security First

Your trust is our highest priority

We use bank-grade encryption, secure cloud infrastructure, and strict access controls to ensure your financial data remains private and protected.

Infrastructure

Auravest is hosted on Amazon Web Services (AWS), utilizing their Sydney region for data sovereignty. Our infrastructure is protected by Cloudflare's enterprise-grade DDoS protection and Web Application Firewall (WAF).

  • AWS Sydney Region Data Residency
  • Automated Daily Backups
  • VPC Isolation per Environment

Data Protection

All sensitive data is encrypted at rest using AES-256 and in transit via TLS 1.3. We do not store your consolidated banking credentials; we use read-only tokens provided by our integration partners.

  • AES-256 Encryption at Rest
  • TLS 1.3 Encryption in Transit
  • Minimal Data Retention Policy

Access Control

We employ strict Role-Based Access Control (RBAC) across our internal systems. Multi-Factor Authentication (MFA) is enforced for all administrative access.

  • Mandatory Internal MFA
  • Principle of Least Privilege
  • Regular Access Audits

Compliance

Auravest acts as a technology provider. While we provide financial insights, we are not a bank. We align with industry standards for data privacy and consumer data rights.

  • Privacy Act 1988 Compliance
  • Australian Privacy Principles (APPs)

Have security questions?

Our security team is available to answer any questions you may have about how we protect your information.