Search on this blog

Search on this blog

Trust Centre | Australian Data Residency, Security & AI Safety — ExpertEase AI

Trust Centre

Security, Privacy & AI Safety — Fully Transparent

ExpertEase AI provides AI-powered digital employees to Australian businesses. Our customers trust us with their knowledge, their conversations, and their customers' interactions. This Trust Centre explains exactly how we protect all three — with nothing hidden.

Talk to Us About Security →

100% Australian Data Residency Azure Sovereign Hosting Built on IRAP-Assessed Azure Infrastructure Sovereign Self-Hosted AI Option Privacy Act Compliant Full Sub-processor Transparency

Australian Sovereign by Default

All customer data is stored and processed in Australia — including all AI processing. Every digital employee runs on one of two AI configurations, both entirely within Australia. You choose which; conversation content never leaves the country on either.

Option 1 — Default

Azure OpenAI — Australian Regions

Frontier AI models served by Microsoft from Azure's Sydney and Melbourne data centres. Prompts and conversation content are processed within Australia, are not sent to OpenAI's own servers, are not retained, and are never used to train models.

Azure Australia EastSydney, NSW
Azure Australia SoutheastMelbourne, VIC
Option 2 — Sovereign AI

Self-Hosted Private AI Deployment

Open-weight AI models operated entirely on ExpertEase-controlled Australian infrastructure — private inference with no third-party AI provider involved at any point. Your data never leaves ExpertEase-controlled Australian infrastructure. Built for organisations with the highest data sensitivity: government, health, disability services, and legal.

ExpertEase Sovereign AI ServersAustralia — fully ExpertEase-controlled
Zero third-party AI processingPrivate inference, onshore only

Voice calls are processed through our telephony provider's Australian region, so call audio also remains onshore. The limited exceptions — SMS routing, transactional email, and payment processing, which transit US-based providers — are disclosed in full on our Sub-processors page.

→ See exactly which providers touch your data

100%Australian Data Residency
0Overseas AI Data Transfer
2Azure AU Regions — Sydney & Melbourne
30 daysData Deletion Guarantee
100%AI Interaction Traceability

How We Protect You

🛡️

Security

Platform security built on Azure's IRAP-assessed Australian infrastructure: end-to-end encryption, strict tenant isolation, hardened access controls, and continuous monitoring — under a clear shared responsibility model with Microsoft.

Security details →
🔒

Privacy

We handle personal information under the Australian Privacy Principles and the Notifiable Data Breaches scheme — and we already meet the Privacy Act's December 2026 automated decision-making transparency requirements.

Privacy & Data Protection →

AI Safety

Digital employees that identify as AI, always offer a path to a human, and are fully traceable. Governed under Australia's Voluntary AI Safety Standard, with every interaction logged and reviewable.

AI Safety & Governance →
🤝

Sub-processors

A short, fully disclosed list of the third parties that help deliver the platform — what each receives, and where it is processed. No hidden vendors.

Sub-processor Register →

Don't Take Our Word for It

Our sovereignty claims are built on Microsoft's independently audited Australian infrastructure — verify them through Microsoft's own documentation.

Microsoft Azure Data Residency (Official)

View Microsoft Documentation →

Azure Compliance: IRAP, ISO/IEC 27001, SOC 2

Microsoft Trust Center →

ExpertEase AI on Microsoft Azure Marketplace

View Our Listing →

Transparency statement: ExpertEase AI operates on Microsoft Azure Australian infrastructure. We do not claim Microsoft's certifications as our own — we provide these references so your legal, government, and procurement teams can independently verify the infrastructure our platform is built on.

AI You Can Hold Accountable

  • Digital employees always identify themselves as AI
  • Human escalation built into every deployment
  • Every interaction traced: transcripts, sources, actions, outcomes
  • Your data never trains shared or third-party AI models
  • Self-hosted sovereign AI available — no third-party AI provider at all

→ Our full AI Safety & Governance approach

"Every AI interaction on our platform is recorded, reviewable, and attributable. Nothing your digital employee says or does is invisible to you."

Frameworks We Align With

FrameworkStatus
Australian Privacy Principles (Privacy Act 1988)Compliant
Notifiable Data Breaches schemeCompliant
Privacy Act ADM transparency (December 2026)Ready ahead of deadline
ASD Essential EightSelf-assessed
Voluntary AI Safety Standard (VAISS)Adopted — self-assessed
OWASP Top 10 / OWASP LLM Top 10Development baseline
ISO/IEC 27001Aligned — certification on roadmap
ISO/IEC 42001 (AI Management Systems)Aligned — certification on roadmap

Trust Centre: Your Questions Answered

Where is my data stored and processed?

Exclusively in Microsoft Azure's Australian regions — Australia East (Sydney) and Australia Southeast (Melbourne). This includes AI processing: conversation content is never sent to overseas AI providers. The only offshore functions are SMS routing, transactional email, and payment processing, disclosed on our Sub-processors page.

Is my data used to train AI models?

No. Your content and conversations are used only to generate responses for your own digital employees. Azure OpenAI does not retain or train on your data, and our self-hosted models run entirely on our own Australian infrastructure.

Are you ISO 27001 or SOC 2 certified?

Our platform runs on Azure infrastructure certified to ISO/IEC 27001 and SOC 2 and IRAP-assessed for Australian Government workloads. ExpertEase AI's own security program is aligned with ISO 27001 principles, self-assessed against the ASD Essential Eight, and formal certification is on our roadmap. Our security whitepaper is available on request.

How do I run a security review of ExpertEase AI?

Contact us at security@experteaseai.com. We provide our security whitepaper, data processing agreement, sub-processor register, and completed security questionnaires under NDA.

What happens if there's a data breach?

We operate a documented incident response plan under the Notifiable Data Breaches scheme: containment, assessment, and notification of affected customers and the OAIC where required by law.

Ready for Your Security Review?

Security whitepaper, DPA, and completed questionnaires available to your procurement and legal teams.

Request the Security Pack →

Security  ·  Privacy  ·  AI Safety  ·  Sub-processors