Wealth management runs on trust. So does Alcova.
Advice cannot tolerate sloppy handling of client information, so every control here exists for a reason, and each one is easy to prove to a compliance team. Certified to SOC 2 Type II, with data resident in Australia, and your information is never used to train any AI.
The full pack, including the SOC 2 Type II report, is in the Trust Centre.
Choose where your client data lives.
Australian firms run on the Sydney region by default, with backups in Australia, encrypted to the same controls. Enterprise firms that need another jurisdiction can choose one on request, and data stays resident in the region you pick.
Australia · Sydney. The standard for Australian firms. Backups stay in Australia.
Wherever it lives, processing stays inside a private network and the result returns to your region. Upstream providers commit, in writing, to no logging and no retention. The architecture is on How it works.
Three things a compliance team needs first.
Certified. The SOC 2 Type II report is available through the Trust Centre.
Stored at rest in the Sydney region. Backups stay in Australia.
TLS 1.2 and above in transit, AES 256 at rest, with per firm encryption keys.
How client data is handled.
The areas a vendor risk review works through.
In transit and at rest, with per firm encryption keys.
Role based access, MFA for personnel, and the firm controls who sees which clients.
Resident in the Sydney region, with backups held in Australia.
Client data is never used to train any AI. Training and abuse retention are disabled on every provider, in writing.
Calendar access is read only, email is optional and transient, and you can disconnect any time.
Monitoring, a defined incident response, and third party penetration testing each year.
Staff training, background checks, and formal security policies.
A short, scrutinised subprocessor list, signed data processing agreements, and advance notice of changes.
Every action leaves an audit trail.
Anything that reaches a client is gated by approval, and what happens is recorded as it happens. The result is a register your licensee can hand to an auditor without assembling it after the fact. How the same record supports supervision of advice across the firm is set out for compliance and risk teams.
Illustrative. Recorded at the outcome level, ready for an auditor.
The standards Alcova is held to.
Certified, report available
Privacy Act 1988
Limited Use requirements
Found something? Tell us.
Report a vulnerability through the Trust Centre. We act on reports made in good faith, and good faith research is covered by safe harbour.
The questions a review asks.
Where is my data stored?
In Australia. Data is stored at rest in the Sydney region and backups stay in country, encrypted to the same controls.
Do you train on my data?
No. Client data is never used to train any AI. Training and abuse monitoring retention are disabled on every AI provider, in writing.
How is data encrypted?
TLS 1.2 and above in transit, AES 256 at rest, with per firm encryption keys.
What can Google or Microsoft see?
Calendar access is read only and required, email is optional and transient, and you can disconnect either at any time.
Can I get the SOC 2 report?
Yes. Request it, along with the full pack, through the Trust Centre.
Who do I contact for a security issue?
Report it through the Trust Centre. Good faith research is covered by safe harbour.
Everything a review needs, in one place.
The subprocessor list, the SOC 2 Type II report, the penetration test summary and our standard data processing agreement, all in the Trust Centre.
Visit the Trust Centre →