Security & Trust

The rules that make firms cautious about AI are the rules we build around.

Your accountability to the TPB, the ATO, and your clients doesn't disappear when AI enters the workflow, so AccuMate is designed so it never has to. Here is every rule that matters, and exactly how the product answers it.

Regulation, answered by design.

TPB draft AI guidance: TPB(I) D62/2026

Using AI never reduces or transfers your responsibility. The registered practitioner stays fully accountable for the accuracy and quality of every service, and confidentiality obligations follow client data into any AI tool.

How AccuMate answers it
  • Three named practitioner sign-off gates: nothing reaches a client or the ATO without your approval
  • Client consent captured at onboarding before their data enters the platform
  • A full audit trail of every AI action, reviewable at any time
ATO Digital Service Provider framework

Software that interacts with ATO systems must meet the Operational Security Framework: ISO 27001-grade controls before direct lodgement is allowed.

How AccuMate answers it
  • Honest interim path: lodgements flow through Xero, an established DSP
  • Direct-lodgement certification sits on our compliance roadmap below, not claimed before it is earned
Privacy Act & Australian Privacy Principles

Personal and financial information must be protected, handled transparently, and kept under appropriate control.

How AccuMate answers it
  • Australian data residency, hosted in Azure Australia East
  • Per-practice tenant isolation: your clients’ data is never visible to another firm
  • We never train general AI models on your client data
APES 110 Code of Ethics

Independence, confidentiality, and professional competence sit with the member. They cannot be delegated to software.

How AccuMate answers it
  • Practitioner-in-the-loop by design: AI drafts, a registered practitioner approves
  • White-labelled under your firm’s brand, so your client relationship stays yours
  • Per-practice tenancy and role-based access inside the practice

TPB(I) D62/2026 is an exposure draft (consultation closed April 2026). We track it as it is finalised and will keep this page current.

Four commitments, in plain language.

We never train general models on your client data

Your clients’ books make your practice’s AI accountants better at serving your clients. They are never used to train models that serve anyone else.

Nothing lodges without a registered practitioner’s sign-off

There is no autonomous path to the ATO. Every lodgement passes a named human approval gate. That is an architectural constraint, not a setting.

Your data stays in Australia, and so does access to it

The platform runs in Microsoft Azure’s Australia East region. Client financial data is not shipped offshore for processing or storage, and access to production is limited to team members located in Australia.

We never sell or share your data

No data brokers, no advertising use, no sharing with third parties beyond the infrastructure required to run the service.

Certifications: what's real, what's next.

We don't wear badges we haven't earned. This is the honest state of our security programme, updated as each milestone lands.

In place today
  • Australian data residency (Azure Australia East)
  • Production access limited to team members located in Australia
  • Per-practice tenant isolation and role-based access
  • Practitioner sign-off gates on every lodgement and client output
  • Server-enforced read-only demo environment: real product, zero write access
Before public launch (February 2027)
  • Independent penetration test
  • Published security whitepaper and data-handling documentation
On the certification roadmap
  • SOC 2 examination
  • ISO 27001 certification
  • ATO DSP Operational Security Framework for direct lodgement

Questions a page can't answer?

Ask us directly. Security questions get a founder's answer, not a template.

Ask a security questionRequest alpha invite