LodgeyLodgey
Security

Compliant. Secure. Off your list.

The security of the software you use shouldn’t take up your attention. Lodgey is built to the bar your industry expects, Australian data residency, AES-256 encryption, and every action audited. So you can spend your attention on your clients.

Security controls

How we deliver on that.

The technical and operational controls behind every Lodgey workspace.

Encrypted end-to-end.

  • AES-256 at rest via AWS KMS
  • Per-agency keys, per-applicant data keys
  • TLS 1.3 in transit, encrypted backups

Australia-only hosting.

  • AWS Sydney (ap-southeast-2)
  • No cross-border transfer, ever
  • Backups stay in Australia too

Every action, audited.

  • Every document, extraction, approval, export logged
  • Tamper-evident, HMAC-signed audit trail
  • Row-level isolation enforced by the database itself

Least-privilege by default.

  • Role-based permissions per team member
  • MFA available for every user
  • Add or remove staff access instantly
Privacy Act

Australian Privacy Principles, point by point.

How Lodgey aligns with each of the 13 Australian Privacy Principles. Full technical detail available on request.

APP 1
Open and transparent management
Lodgey publishes a privacy policy that sets out how personal information is collected, used, stored, and disclosed. See the privacy page. The policy is reviewed whenever practices change.
APP 2
Anonymity and pseudonymity
Lodgey processes identity documents for applications to government bodies that require verified identity. Anonymity and pseudonymity are not practicable for the core service, so the lawful-and-practicable exemption applies.
APP 3
Collection of solicited personal information
Lodgey only collects information the agent has asked the client to upload via their checklist. Nothing is collected passively.
APP 4
Unsolicited personal information
If a client uploads a document not requested by the agent's checklist, the agent can delete it directly in-app. Lodgey does not retain unsolicited material as part of the case record.
APP 5
Notification of collection
Clients see, on every upload, what's being collected, by whom, and the purpose. Collection notices are part of the upload flow.
APP 6
Use or disclosure
Client information is used only to deliver the service the agent has engaged Lodgey for, extraction, review, and form-fill against the agent's checklist. Lodgey does not sell, rent, or share client data, and never uses it to train AI models.
APP 7
Direct marketing
Lodgey does not market to the clients of agencies. Product communications go only to agency account holders, who can unsubscribe at any time.
APP 8
Cross-border disclosure
No cross-border transfer. Data is stored and processed exclusively in AWS Sydney (ap-southeast-2). Lodgey will not send client data offshore.
APP 9
Government-related identifiers
Lodgey handles documents containing government identifiers (passport, visa, Medicare numbers) but does not use them as the internal identifier for any client, application, or record. Lodgey's primary keys are UUIDs.
APP 10
Quality of personal information
Every AI-extracted field is reviewable side-by-side with the source document. If a field reads wrong or confidence is low, the agent rejects the document and the client re-uploads a clearer copy; extraction re-runs against the new file. Nothing is submitted until the agent has approved each document.
APP 11
Security of personal information
AES-256 at rest with per-agency keys, TLS 1.3 in transit, MFA available for every user, role-based permissions, and a tamper-evident audit trail of every action.
APP 12
Access to personal information
Agents manage their clients' data directly in the workspace and can export a full copy of any client's record in one click. Data subjects requesting access should contact the agency that engaged them.
APP 13
Correction of personal information
If extracted data is wrong, the agent rejects the document and the client re-uploads a corrected version; the field set re-derives from the new file. Data subjects requesting correction or deletion contact the agency directly, the agency makes the change in Lodgey. Deletion is immediate at the encryption layer, the per-applicant key is destroyed, so any residual ciphertext in encrypted backups is permanently unreadable.