Skip to content

Security & data handling

Security built for sensitive compliance workflows

AML/CTF records hold identity documents, risk decisions and, at times, suspicious matter reports. duely protects engagement data, keeps suspicious matter handling restricted, and keeps the compliance record intact over time.

Least-privilege access

Users see only what they need. Engagement-level scoping, role-based permissions and sensitive-data flags keep exposure to a minimum.

Role-based workflow separation

Sensitive workflows like suspicious matter handling are separated by architecture as well as by permissions.

Immutable audit history

Every compliance action is recorded in an append-only event stream. No edits or deletions are permitted.

Sensitive export controls

Default exports are built to protect privacy. A fuller sensitive pack needs explicit AMLCO authorisation.

Australian data residency

Engagement records and evidence are stored in Australia (BinaryLane, Sydney, and Microsoft Azure, Australia East). Identity document and biometric verification (Didit, EU) and screening (dilisense, Switzerland) are performed outside Australia, with the resulting evidence stored in Australia.

The same engagement, seen by two roles

Access is set by role. A suspicious matter report is the clearest case: telling the customer about one is an offence (tipping off, s123), so staff see no sign that a report exists.

How suspicious matters are isolated

One engagement, two views

Illustrative

  • Risk rating Staff see: Medium The AMLCO sees: Medium
  • Unusual activity report Staff see: Submitted The AMLCO sees: Escalated
  • Suspicious matter case Staff see: Nothing shown The AMLCO sees: Open
  • Lodgement deadline Staff see: Nothing shown The AMLCO sees: 3 business days
  • Evidence pack Staff see: No SMR data The AMLCO sees: No SMR data
Suspicious matter records are kept apart from the engagement. Staff get no sign that one exists.

How duely protects compliance data

Access control, evidence integrity, suspicious matter isolation and data residency, built into every layer of the product.

Role-Based Access Control

Each user's role decides which workflows they can open. Suspicious matter handling is restricted to AMLCO-authorised users. Standard users see no suspicious matter indicators on shared engagement screens, notifications or exports.

  • Engagement access scoped to your firm, with AMLCO and Approver policies controlling sensitive actions
  • Admin and AMLCO role overrides with full audit logging
  • Granular permission flags for sensitive data access
  • Role assignments managed at the firm level

Sensitive Data Handling

duely protects data in transit and at rest, limits who can see it, and keeps evidence linked to the right engagement record. Sensitive documents and workflow records are governed by access controls and export rules suited to the context.

  • Data protected in transit and at rest
  • Separate permission flags control access to sensitive information
  • Configurable export rules for different contexts
  • Evidence linked to the correct engagement record

Evidence Integrity

Evidence packs are versioned and integrity-hashed, so firms can verify that an exported record has not been altered since it was generated. The audit history and export details make later review easier.

  • SHA-256 hashing applied to every evidence pack version
  • Tamper detection through hash comparison on access
  • Integrity verification available at any future audit date
  • Each version is independently SHA-256 hashed for per-version tamper detection

Suspicious Matter Isolation: Layered Controls

duely prevents tipping off with layered controls, each enforced at a different read or write path, as well as policy. They are: a separate shadow case object, AMLCO-only role-based access, redaction of unusual activity reports (UARs) for staff who raise them, no suspicious matter report (SMR) indicators on shared screens, evidence pack redaction, notification isolation, and filtered reads of the audit log. The controls are independent, so a mistake at any one of them should not expose SMR data on its own.

  • Shadow case stored as a separate record, not a flag on the engagement
  • AMLCO-only policy enforced at every SMR API endpoint
  • UAR submitters never see whether their flag became an SMR
  • Zero SMR indicators on dashboards, lists, exports, or notifications
  • Evidence packs (both Standard and AMLCO-only Sensitive) never include SMR data
  • Notification queue rejects SMR templates from non-AMLCO callers
  • Audit events stay in the same immutable stream but filtered from non-AMLCO reads

Immutable Audit Trail

An append-only event stream records every action taken on every engagement. Entries cannot be edited or deleted, so the record holds up to regulatory review.

  • Append-only event stream: no edits or deletions permitted
  • Every engagement action recorded with timestamp, actor and detail
  • Forensic-grade record of all compliance decisions and changes
  • Suitable for regulatory review and internal audit processes

Encryption

All data is encrypted at rest and in transit. Secrets are kept apart from application code, so credentials never appear in source, configuration or logs.

  • Data encrypted at rest using industry-standard encryption
  • TLS 1.2 or higher for all data in transit, with TLS 1.3 preferred
  • Secrets isolated from application code and excluded from logs
  • Production credentials are not visible to engineers in day-to-day workflows

Single Sign-On (OIDC)

duely supports OIDC single sign-on, so your firm can manage access through its existing identity provider. Staff are added and removed the way your IT team already onboards and offboards them.

  • OIDC SSO with standard OAuth 2.0 / OpenID Connect flows
  • Centralised access control through your firm's identity provider
  • Supports staff onboarding and offboarding workflows
  • Multi-firm membership: one identity can belong to multiple firms with active firm context tracked per session

Self-Enforcing Approver Controls

An approver can approve only while their own personnel due diligence (PDD) is current. If their AML training and screening are not current, duely refuses the approval.

  • Engagement approval is refused when the approver's PDD is not current
  • A 14-day grace period applies before a lapse blocks approval
  • Logged warnings when blocked actions are attempted
  • AML decisions only flow through staff whose compliance posture is current

Multi-Channel Notification Isolation

Notifications go out by SMS, email and in-app message. On every channel, only AMLCO-authorised users receive messages that relate to an SMR.

  • SMS, email, and in-app delivery: choose the right channel per template
  • SMR-restricted templates blocked at the queueing layer for non-AMLCO callers
  • AMLCO-targeted publishers fan out only to AMLCO recipients
  • Daily digest options to reduce notification noise

Australian Data Residency

Engagement records, documents and evidence packs are stored in Australia (BinaryLane, Sydney, and Microsoft Azure, Australia East). Identity document and biometric verification is performed by Didit (EU) on a process-and-purge basis, and sanctions/PEP/adverse-media screening by dilisense (Switzerland); the resulting evidence is stored in Australia.

  • Engagement, document and evidence data hosted in Australian data centres
  • Identity document and biometric verification processed by Didit (EU) and purged after the result is returned; screening by dilisense (Switzerland); evidence stored in Australia
  • Didit is GDPR-compliant and ISO 27001 / SOC 2 (Type I) certified

Retention and Record-Keeping

Engagement records and evidence are retained in line with the firm's compliance obligations and internal controls. duely tracks the retention anchor date and its reason for each engagement.

  • 7-year retention period (a legal requirement) tracked from the anchor date set when an engagement is concluded
  • The anchor is set once; reopening an engagement clears it, and the audit log keeps the history
  • Anchor reason documented for each engagement's retention period
  • Supports AML/CTF Act record-keeping obligations

Data residency and retention

duely stores your compliance records in Australia and tracks how long each must be kept under the AML/CTF Act. Retain engagement records and evidence in line with your firm's obligations and internal controls.

  • Engagement, document and evidence data hosted in Australian data centres
  • Identity document and biometric verification processed by Didit (EU) on a process-and-purge basis; sanctions, PEP and adverse-media screening by dilisense (Switzerland); evidence stored in Australia
  • 7-year retention period tracked from each engagement's anchor date
  • Retention anchor reasons documented for every engagement

More detail for your internal review

This page is the public overview. Contact us if your firm needs more detail on the product or its security.