Security & data handling
Security built for sensitive compliance workflows
AML/CTF records hold identity documents, risk decisions and, at times, suspicious matter reports. duely protects engagement data, keeps suspicious matter handling restricted, and keeps the compliance record intact over time.
Least-privilege access
Users see only what they need. Engagement-level scoping, role-based permissions and sensitive-data flags keep exposure to a minimum.
Role-based workflow separation
Sensitive workflows like suspicious matter handling are separated by architecture as well as by permissions.
Immutable audit history
Every compliance action is recorded in an append-only event stream. No edits or deletions are permitted.
Sensitive export controls
Default exports are built to protect privacy. A fuller sensitive pack needs explicit AMLCO authorisation.
Australian data residency
Engagement records and evidence are stored in Australia (BinaryLane, Sydney, and Microsoft Azure, Australia East). Identity document and biometric verification (Didit, EU) and screening (dilisense, Switzerland) are performed outside Australia, with the resulting evidence stored in Australia.
The same engagement, seen by two roles
Access is set by role. A suspicious matter report is the clearest case: telling the customer about one is an offence (tipping off, s123), so staff see no sign that a report exists.
How suspicious matters are isolatedOne engagement, two views
Illustrative
- Risk rating Staff see: Medium The AMLCO sees: Medium
- Unusual activity report Staff see: Submitted The AMLCO sees: Escalated
- Suspicious matter case Staff see: Nothing shown The AMLCO sees: Open
- Lodgement deadline Staff see: Nothing shown The AMLCO sees: 3 business days
- Evidence pack Staff see: No SMR data The AMLCO sees: No SMR data
How duely protects compliance data
Access control, evidence integrity, suspicious matter isolation and data residency, built into every layer of the product.
Role-Based Access Control
Each user's role decides which workflows they can open. Suspicious matter handling is restricted to AMLCO-authorised users. Standard users see no suspicious matter indicators on shared engagement screens, notifications or exports.
- Engagement access scoped to your firm, with AMLCO and Approver policies controlling sensitive actions
- Admin and AMLCO role overrides with full audit logging
- Granular permission flags for sensitive data access
- Role assignments managed at the firm level
Sensitive Data Handling
duely protects data in transit and at rest, limits who can see it, and keeps evidence linked to the right engagement record. Sensitive documents and workflow records are governed by access controls and export rules suited to the context.
- Data protected in transit and at rest
- Separate permission flags control access to sensitive information
- Configurable export rules for different contexts
- Evidence linked to the correct engagement record
Evidence Integrity
Evidence packs are versioned and integrity-hashed, so firms can verify that an exported record has not been altered since it was generated. The audit history and export details make later review easier.
- SHA-256 hashing applied to every evidence pack version
- Tamper detection through hash comparison on access
- Integrity verification available at any future audit date
- Each version is independently SHA-256 hashed for per-version tamper detection
Suspicious Matter Isolation: Layered Controls
duely prevents tipping off with layered controls, each enforced at a different read or write path, as well as policy. They are: a separate shadow case object, AMLCO-only role-based access, redaction of unusual activity reports (UARs) for staff who raise them, no suspicious matter report (SMR) indicators on shared screens, evidence pack redaction, notification isolation, and filtered reads of the audit log. The controls are independent, so a mistake at any one of them should not expose SMR data on its own.
- Shadow case stored as a separate record, not a flag on the engagement
- AMLCO-only policy enforced at every SMR API endpoint
- UAR submitters never see whether their flag became an SMR
- Zero SMR indicators on dashboards, lists, exports, or notifications
- Evidence packs (both Standard and AMLCO-only Sensitive) never include SMR data
- Notification queue rejects SMR templates from non-AMLCO callers
- Audit events stay in the same immutable stream but filtered from non-AMLCO reads
Immutable Audit Trail
An append-only event stream records every action taken on every engagement. Entries cannot be edited or deleted, so the record holds up to regulatory review.
- Append-only event stream: no edits or deletions permitted
- Every engagement action recorded with timestamp, actor and detail
- Forensic-grade record of all compliance decisions and changes
- Suitable for regulatory review and internal audit processes
Encryption
All data is encrypted at rest and in transit. Secrets are kept apart from application code, so credentials never appear in source, configuration or logs.
- Data encrypted at rest using industry-standard encryption
- TLS 1.2 or higher for all data in transit, with TLS 1.3 preferred
- Secrets isolated from application code and excluded from logs
- Production credentials are not visible to engineers in day-to-day workflows
Single Sign-On (OIDC)
duely supports OIDC single sign-on, so your firm can manage access through its existing identity provider. Staff are added and removed the way your IT team already onboards and offboards them.
- OIDC SSO with standard OAuth 2.0 / OpenID Connect flows
- Centralised access control through your firm's identity provider
- Supports staff onboarding and offboarding workflows
- Multi-firm membership: one identity can belong to multiple firms with active firm context tracked per session
Self-Enforcing Approver Controls
An approver can approve only while their own personnel due diligence (PDD) is current. If their AML training and screening are not current, duely refuses the approval.
- Engagement approval is refused when the approver's PDD is not current
- A 14-day grace period applies before a lapse blocks approval
- Logged warnings when blocked actions are attempted
- AML decisions only flow through staff whose compliance posture is current
Multi-Channel Notification Isolation
Notifications go out by SMS, email and in-app message. On every channel, only AMLCO-authorised users receive messages that relate to an SMR.
- SMS, email, and in-app delivery: choose the right channel per template
- SMR-restricted templates blocked at the queueing layer for non-AMLCO callers
- AMLCO-targeted publishers fan out only to AMLCO recipients
- Daily digest options to reduce notification noise
Australian Data Residency
Engagement records, documents and evidence packs are stored in Australia (BinaryLane, Sydney, and Microsoft Azure, Australia East). Identity document and biometric verification is performed by Didit (EU) on a process-and-purge basis, and sanctions/PEP/adverse-media screening by dilisense (Switzerland); the resulting evidence is stored in Australia.
- Engagement, document and evidence data hosted in Australian data centres
- Identity document and biometric verification processed by Didit (EU) and purged after the result is returned; screening by dilisense (Switzerland); evidence stored in Australia
- Didit is GDPR-compliant and ISO 27001 / SOC 2 (Type I) certified
Retention and Record-Keeping
Engagement records and evidence are retained in line with the firm's compliance obligations and internal controls. duely tracks the retention anchor date and its reason for each engagement.
- 7-year retention period (a legal requirement) tracked from the anchor date set when an engagement is concluded
- The anchor is set once; reopening an engagement clears it, and the audit log keeps the history
- Anchor reason documented for each engagement's retention period
- Supports AML/CTF Act record-keeping obligations
Data residency and retention
duely stores your compliance records in Australia and tracks how long each must be kept under the AML/CTF Act. Retain engagement records and evidence in line with your firm's obligations and internal controls.
- Engagement, document and evidence data hosted in Australian data centres
- Identity document and biometric verification processed by Didit (EU) on a process-and-purge basis; sanctions, PEP and adverse-media screening by dilisense (Switzerland); evidence stored in Australia
- 7-year retention period tracked from each engagement's anchor date
- Retention anchor reasons documented for every engagement
More detail for your internal review
This page is the public overview. Contact us if your firm needs more detail on the product or its security.