Your clients trust you with their passports, identity documents and life plans. Your records, your clients records and every document you upload are held in Australia. This page sets out what protects them, and every claim on it is one you can verify rather than take on trust.
Anyone can claim their platform is secure. Below is what a third party actually issued, what it was assessed against, and where its scope stops.
Certified by CyberCert

LodgeHQ Pty Ltd holds SMB1001:2026 Level 3 (Gold), certificate 012630000052696192677Q, issued by CyberCert on 27 July 2026 and current until 28 July 2027. At Bronze, Silver and Gold that scheme certifies a director attestation against a published control set — the certificate is issued on that attestation, so it is not an independent audit.
Google OAuth verification + CASA Tier 2 assessment
LodgeHQ was independently assessed in July 2026 by TAC Security, a Google-authorised CASA lab, as part of Google verification of our restricted Gmail scopes. It returned no critical, high or medium-severity findings.
Microsoft identity platform
Our Outlook and Microsoft 365 integration is published under a Microsoft-verified publisher identity, verified through the Microsoft Partner programme against our lodgehq.com.au domain. When your firm connects a mailbox or calendar, the consent screen shows a verified publisher — never an "unverified app" warning.
Google Chrome Web Store review
The LodgeHQ eLodge extension — our auto-fill tool for ImmiAccount and the AFP National Police Check portal — is reviewed and published on the Chrome Web Store, and updates automatically. It never lodges anything on its own: it pre-fills forms from your case data and you review and submit.
LodgeHQ itself is not ISO 27001 or SOC 2 certified. Those certifications belong to Amazon Web Services, which hosts us, and we do not present them as ours. The credentials above are LodgeHQ's own, and each one states its basis of issue and the limit of its scope rather than leaving you to look it up.
Your records and your clients documents are stored in Australia. Some data does leave, on paths we name. The recipients are set out, with their legal entity and country, on our Sub-processor Register.
LodgeHQ stores your practice’s records, your clients’ records and your uploaded documents in Australia — on Amazon Web Services infrastructure in the Sydney region (ap-southeast-2) — and AI processing runs on Amazon Bedrock in Australia (Sydney and Melbourne, ap-southeast-4).
Some of the services the platform depends on operate outside Australia — email delivery, card payments, messaging and document translation — as do any accounts your own firm chooses to connect. Each one is named, with its country and exactly what it receives, in the cross-border disclosure section of our Privacy Policy and on our Sub-processor Register.
AI features run on Amazon Bedrock in Australia — the inference profiles in use resolve only to the Sydney (ap-southeast-2) and Melbourne (ap-southeast-4) regions. The model vendor is Anthropic (Claude). Under Bedrock, AWS operates the model deployment accounts: Anthropic does not receive your prompts, your documents or the model output, and the data is not used to train models. That is the position AWS publishes for Bedrock, and it is the basis on which we use it.
The production database has point-in-time recovery enabled with a 14-day window and is encrypted at rest under a customer-managed key. That is the only backup figure we publish, because it is the only one we can demonstrate on the day you ask. When an account ends, your data remains available for export for 30 days. After that it is deleted from our active systems, and the last remaining copy ages out of our Amazon Web Services infrastructure 90 days later — 120 days from closure in total. That 90 days is the longest of three expiry rules set on the infrastructure itself: point-in-time recovery on the database runs a 14-day window, database exports expire at 35 days, and superseded document versions expire at 90. No manual database snapshots exist outside those rules.
The controls protecting every matter, every document and every login.
TLS with HSTS in transit; encryption at rest across database and document storage; an additional AES-256-GCM application layer on sensitive identifiers — passport, TRN and DHA file numbers — plus integration tokens and 2FA secrets.
12-character minimum passwords hashed with PBKDF2-SHA512, screening against known-breach databases, account lockout, optional firm-enforced two-factor authentication, and sessions revoked on password change.
Every tenant-scoped read and write is filtered by the firm identifier of the caller in the query itself, so a request for another firm record returns not-found. We will be precise about what that is and is not: it is enforced by each route handler, not by a database-level rule that makes an unscoped query impossible. Route-level scoping was reviewed across the codebase during the July 2026 assessment and no unscoped access path was found. Within a firm, role-based permissions apply: clerks, admins and agents each see only what their role allows.
Layered rate limiting at the edge and application level, CSRF protection, and hardened security headers with a Content Security Policy. We record sign-ins, administrative actions, document downloads, individual client-record views and data exports — each with the user, the action, the resource, the IP address and the user agent, and never the data values themselves.
Automated weekly dependency vulnerability scanning, which opens a tracked issue in our repository on a high or critical finding, and security review built into our release process. Independent dynamic (DAST) testing of the live application was performed once, in July 2026, as part of the CASA assessment.
Point-in-time recovery on the production database with a 14-day window, encrypted at rest under a customer-managed key, behind a documented incident response plan. We publish no other backup figure, and no offline-copy claim, because we would not be able to demonstrate one today.
Built by a practising Registered Migration Agent who answers to OMARA — client confidentiality isn't a checkbox here, it's a professional obligation.
Twelve maintained policy documents sit behind our certification — cyber security policy, incident response plan, data retention and secure disposal, password and authentication policy, invoice-fraud controls, and a responsible AI-use policy — reviewed on a set schedule.
LodgeHQ holds cyber insurance as part of its Gold-level certification requirements — protection sitting behind the platform, not just promises in front of it.
Our team trains through Cyber Wardens, the Australian Government-backed small-business cyber safety programme run by COSBOA — because most breaches start with people, not software.
We run a responsible disclosure process and publish a security.txt. If you believe you've found a vulnerability, email support@lodgehq.com.au and we'll acknowledge and act on it promptly. For how we handle personal information, see our Privacy Policy.
Australian-hosted, independently assessed, and published in enough detail that you can check it yourself. Built for Australian migration agents. Try everything free for 14 days.
Start Your Free TrialNo credit card required. Set up in 30 seconds.