Access control & MFA
Role-based access for agency users. Multi-factor authentication (MFA) is available. Session authentication is required for compliance workspaces.
How AMLHive protects agency and client data — Australian residency, encryption, access control, and an immutable audit trail.
Security posture: AMLHive is built as a security-compliant, multi-tenant platform with practical controls for protecting agency and client data.
Product boundary: AMLHive is a software compliance tool. Your agency remains responsible for meeting its AML/CTF obligations. AMLHive does not provide legal advice and is not affiliated with AUSTRAC.
Role-based access for agency users. Multi-factor authentication (MFA) is available. Session authentication is required for compliance workspaces.
Agency data is scoped so one agency cannot read another agency's compliance records. Access decisions are driven from authenticated identity, not request-body agency identifiers.
All documents are stored in private encrypted cloud storage with signed-URL document access. Data is protected with encryption at rest and in transit.
Compliance files, training records, and program documents are hosted with Australian data residency controls so compliance records remain in Australia.
Compliance actions are recorded in an append-only audit trail with seven-year retention and CSV/PDF export for your own records and review. Entries cannot be edited or deleted.
Personal information handling is designed around the Australian Privacy Principles. Identity verification via Veriff may involve overseas processing; that overseas disclosure is covered in our Privacy Policy (APP 8).