Wealth management runs on trust. So does Alcova.

Advice cannot tolerate sloppy handling of client information, so every control here exists for a reason, and each one is easy to prove to a compliance team. Certified to SOC 2 Type II, with data resident in Australia, and your information is never used to train any AI.

The full pack, including the SOC 2 Type II report, is in the Trust Centre.

Data residency

Choose where your client data lives.

Australian firms run on the Sydney region by default, with backups in Australia, encrypted to the same controls. Enterprise firms that need another jurisdiction can choose one on request, and data stays resident in the region you pick.

Australia · Sydney. The standard for Australian firms. Backups stay in Australia.

Wherever it lives, processing stays inside a private network and the result returns to your region. Upstream providers commit, in writing, to no logging and no retention. The architecture is on How it works.

The headline

Three things a compliance team needs first.

Certified
SOC 2 Type II

Certified. The SOC 2 Type II report is available through the Trust Centre.

Data residency
Resident in Australia

Stored at rest in the Sydney region. Backups stay in Australia.

Cryptography
Strong encryption end to end

TLS 1.2 and above in transit, AES 256 at rest, with per firm encryption keys.

Security posture

How client data is handled.

The areas a vendor risk review works through.

Encryption everywhere

In transit and at rest, with per firm encryption keys.

Least privilege access

Role based access, MFA for personnel, and the firm controls who sees which clients.

Australian data residency

Resident in the Sydney region, with backups held in Australia.

Never trained on your data

Client data is never used to train any AI. Training and abuse retention are disabled on every provider, in writing.

Workspace integrations

Calendar access is read only, email is optional and transient, and you can disconnect any time.

Operational security

Monitoring, a defined incident response, and third party penetration testing each year.

People and process

Staff training, background checks, and formal security policies.

Vendor governance

A short, scrutinised subprocessor list, signed data processing agreements, and advance notice of changes.

On the record

Every action leaves an audit trail.

Anything that reaches a client is gated by approval, and what happens is recorded as it happens. The result is a register your licensee can hand to an auditor without assembling it after the fact. How the same record supports supervision of advice across the firm is set out for compliance and risk teams.

Audit trail Recording
Henderson review · file note
09:02:14 Henderson review file note drafted
09:02:14 Scoped to the records the firm allows
09:02:15 Checked against the firm’s advice policy
09:21:06 Approved by the adviser
09:21:07 Released to the client

Illustrative. Recorded at the outcome level, ready for an auditor.

Compliance and certifications

The standards Alcova is held to.

AICPA SOC for Service Organizations
SOC 2 Type II

Certified, report available

Australian Privacy Principles

Privacy Act 1988

Google API Services

Limited Use requirements

Responsible disclosure

Found something? Tell us.

Report a vulnerability through the Trust Centre. We act on reports made in good faith, and good faith research is covered by safe harbour.

Vendor risk questions

The questions a review asks.

Where is my data stored?

In Australia. Data is stored at rest in the Sydney region and backups stay in country, encrypted to the same controls.

Do you train on my data?

No. Client data is never used to train any AI. Training and abuse monitoring retention are disabled on every AI provider, in writing.

How is data encrypted?

TLS 1.2 and above in transit, AES 256 at rest, with per firm encryption keys.

What can Google or Microsoft see?

Calendar access is read only and required, email is optional and transient, and you can disconnect either at any time.

Can I get the SOC 2 report?

Yes. Request it, along with the full pack, through the Trust Centre.

Who do I contact for a security issue?

Report it through the Trust Centre. Good faith research is covered by safe harbour.

The Trust Centre

Everything a review needs, in one place.

The subprocessor list, the SOC 2 Type II report, the penetration test summary and our standard data processing agreement, all in the Trust Centre.

Visit the Trust Centre