Your clients trust you with their passports, identity documents and life plans. We built LodgeHQ so that trust holds all the way down — and then had it independently checked.
Anyone can claim their platform is secure. These credentials are issued and verified by third parties.
Certified by CyberCert

LodgeHQ Pty Ltd is certified to Gold level under SMB1001:2026, the Dynamic Standards International cyber-security standard for Australian organisations. Certification covers 23 implemented controls — endpoint detection and response, multi-factor authentication, password management, email anti-spoofing, encrypted backups, secure device disposal, incident response, staff security training and a responsible AI-use policy.
Google OAuth verification + CASA Tier 2 assessment
Our Gmail integration passed Google's OAuth app verification for restricted scopes — Google's strictest verification tier. That process includes an independent Cloud Application Security Assessment (CASA) Tier 2, carried out by TAC Security, an authorised assessor lab. The independent security testing of the LodgeHQ platform returned zero critical, high or medium-severity findings, and the assessment is repeated annually.
Microsoft identity platform
Our Outlook and Microsoft 365 integration is published under a Microsoft-verified publisher identity, verified through the Microsoft Partner programme against our lodgehq.com.au domain. When your firm connects a mailbox or calendar, the consent screen shows a verified publisher — never an "unverified app" warning.
Google Chrome Web Store review
The LodgeHQ eLodge extension — our ImmiAccount auto-fill tool — is reviewed and published on the Chrome Web Store, and updates automatically. It never lodges anything on its own: it pre-fills forms from your case data and you review and submit.
LodgeHQ runs on AWS infrastructure that is independently certified to ISO 27001 and SOC 2. Those certifications belong to AWS as our infrastructure provider; the credentials above are LodgeHQ's own.
Client files never leave Australian soil — hosted, processed and backed up onshore.
The platform, database and every uploaded document live on AWS infrastructure in the Sydney region (ap-southeast-2) — infrastructure independently certified to ISO 27001 and SOC 2.
AI features run on Amazon Bedrock in Sydney. Client files, questionnaire answers and documents are processed onshore — they are not sent overseas for AI processing.
Encrypted database backups run daily with 30-day retention, stored in Australia, plus an isolated offline copy as part of our documented backup and recovery strategy.
The controls protecting every matter, every document and every login.
TLS with HSTS in transit; encryption at rest across database and document storage; an additional AES-256-GCM application layer on sensitive identifiers — passport, TRN and DHA file numbers — plus integration tokens and 2FA secrets.
12-character minimum passwords hashed with PBKDF2-SHA512, screening against known-breach databases, account lockout, optional firm-enforced two-factor authentication, and sessions revoked on password change.
Every record is scoped to your firm with strict multi-tenant isolation and role-based permissions — clerks, admins and agents each see only what their role allows.
Layered rate limiting at the edge and application level, CSRF protection, hardened security headers with a Content Security Policy, and full audit logging across the platform.
Automated weekly dependency vulnerability scanning, security review built into our release process, and independent DAST testing of the live platform as part of the annual CASA assessment.
Daily encrypted backups with 30-day retention and an isolated offline copy, under a documented backup and recovery strategy with a formal incident response plan behind it.
Built by a practising Registered Migration Agent who answers to OMARA — client confidentiality isn't a checkbox here, it's a professional obligation.
Twelve maintained policy documents sit behind our certification — cyber security policy, incident response plan, data retention and secure disposal, password and authentication policy, invoice-fraud controls, and a responsible AI-use policy — reviewed on a set schedule.
LodgeHQ holds cyber insurance as part of its Gold-level certification requirements — protection sitting behind the platform, not just promises in front of it.
Our team trains through Cyber Wardens, the Australian Government-backed small-business cyber safety programme run by COSBOA — because most breaches start with people, not software.
We run a responsible disclosure process and publish a security.txt. If you believe you've found a vulnerability, email support@lodgehq.com.au and we'll acknowledge and act on it promptly. For how we handle personal information, see our Privacy Policy.
Certified security, Australian data residency, and 130+ features built for migration agents. Try everything free for 14 days.
Start Your Free TrialNo credit card required. Set up in 30 seconds.