days leftTranche 2 is live — Compliance Kickstart: 30% off for 6 months. Ends 31 July 2026.
AMLify logoAMLify

Security at AMLify

You're trusting us with sensitive compliance and customer identity data. We take that seriously — from how we protect data day to day, to publicly documenting our controls on an independent industry registry.

Listed on the CSA STAR Registry

Listed since 29 July 2026

The Cloud Security Alliance (CSA) Security, Trust, Assurance and Risk (STAR) Registry is a publicly available registry that documents the security and privacy controls of cloud services.Consultin AI Pty Ltd, the company behind AMLify, has completed a CSA STAR Level 1 self-assessment against the Cloud Controls Matrix (CCM) v4.1, using the CAIQ Lite questionnaire.

A Level 1 self-assessment means we have documented, in the CSA's own standardised format, how our practices map to the CCM's control objectives — it is a self-assessment, not an independent audit or certification. Our responses are publicly available on the registry for anyone to review.

View our listing on the CSA STAR Registry

How we protect your data

These are the practices we follow as a matter of course, alongside our CSA STAR Registry listing.

Encryption in transit and at rest

Data moving to and from AMLify is encrypted in transit (TLS). Stored data is encrypted at rest.

Access controls

Access to customer data is restricted on a least-privilege basis, and we run regular reviews of our security controls.

Australian data residency & privacy

Customer data is stored on Australian-hosted infrastructure and handled in line with the Australian Privacy Act 1988 (Cth).

Your data is never used to train AI models

Compliance data, customer records, and business information are used only to provide your service — never to train, fine-tune, or improve AI models, ours or anyone else's.

Vendor & supplier due diligence

Third-party providers who support our infrastructure and hosting are assessed before we rely on them and are held to confidentiality obligations.

Incident response

We maintain a process for identifying, containing, and notifying affected customers of security incidents in line with our legal obligations.

Our controls are documented publicly, not just claimed

Our CAIQ Lite responses for the CSA STAR Registry are public. We would rather you read them directly than take our word for it — they set out, control by control, how our practices map to the Cloud Controls Matrix.

Review our CAIQ Lite responses

Questions about how we handle your data?

Start your 14-day free trial and see how AMLify handles your compliance data. No credit card required.

Start free trial