Version 1.0 · Effective 1 October 2026 · Altren Group Pty Ltd ABN 32 700 087 332 trading as Altego · Melbourne, VIC
Where your data lives, how it is protected, and what happens when something goes wrong.
Altego holds the records a reporting entity relies on to meet its obligations: customer identities, transactions, screening results, cases, and the reports it lodges with AUSTRAC. This page sets out plainly where that data lives, how it is protected, and what happens when something goes wrong. No jargon, and no badges we have not earned.
Your data stays in Australia. Platform data is hosted on Microsoft Azure in Australia East (Sydney), with a replica and the daily backups in Australia Southeast (Melbourne). Both are Australian regions.
Encrypted in transit and at rest. Traffic to Altego uses TLS 1.2 or above. Stored data and backups are encrypted at rest with AES-256.
Multi-factor authentication on every sign-in. Not optional, not a setting. Every sign-in to Altego requires it.
Businesses are separated at the data layer. Separation is enforced in the database, not only in the interface, so one business cannot reach another's data.
Everything is in an audit trail. Every alert, parameter change, screening decision and report action is written to an append-only log. Nothing that fires is ever deleted.
You own your data. It is yours, not ours. We process it to run the service and nothing else. We do not sell it, and we do not use it to train AI models without your consent.
99.9% uptime target. A contractual target, not a marketing line, with service credits if we miss it.
We are software, not your compliance function. Altego does not give legal or regulatory advice, does not form a suspicion, and never lodges a report for you. The obligations stay with you.
Where your data actually lives. Production data is stored in Azure Australia East, in Sydney. A live replica and the daily backups are held in Azure Australia Southeast, in Melbourne. Platform data does not leave Australian infrastructure as part of normal operation.
Encryption. TLS 1.2 or above in transit. AES-256 at rest, including backups and object storage.
Backups. We run a live replica between two Australian regions, back up daily, and keep those backups for a month.
Change management. Changes are reviewed before release and can be rolled back. Releases that affect availability are scheduled into a maintenance window with notice.
Multi-factor authentication. Required for every sign-in to Altego, and mandatory on every internal system we use that supports it.
Roles, not blanket access. Access inside your business is set by role, so an operator login is not a compliance officer login. Role separation is enforced at the data layer.
Tipping-off partitions. Who can see that a report exists, or is being contemplated, is restricted by permission. You set those permissions, and you are responsible for setting them so that only people entitled to that information can see it.
Our access to your data. Nobody at Altego holds standing access to your data. Where a support request needs it, access is granted for that request, logged, and removed when the request closes.
Audit trail. Every action in your business is recorded with the user, the time and what changed, and retained for seven years. The log is append-only and is not editable by you or by us.
Our target. 99.9% monthly uptime for paid subscriptions, set out in Schedule 1 of the Customer Agreement, with service credits if we fall short.
Planned maintenance. We reserve Tuesday and Thursday nights, 11 pm to 1 am AEST, for maintenance, and in most weeks we do not use them. You get at least 48 hours notice before any planned downtime, and planned maintenance does not count against the uptime target.
When something breaks. We post to our status page before we start diagnosing, and keep updating until it is fixed. For a critical outage we contact affected businesses directly.
An outage does not pause your obligations. Statutory deadlines keep running whether or not the platform is available. You should have a documented process for meeting your obligations during an outage, and your AML/CTF programme should describe it.
We are the software. You are the reporting entity. Every obligation the law places on you stays with you. It cannot be transferred to a software supplier, and using Altego is not evidence that you have met an obligation.
How the rules were built. The monitoring rules, thresholds, typologies, templates and workflows were developed from the operational practice of remittance providers and other practitioners in the field, and from public material. They were not prepared on the basis of legal advice, and they have not been reviewed, approved or certified by AUSTRAC or any other regulator. They are a starting point for you to tune and approve, not a legal opinion.
Alerts are not findings. Monitoring rules detect the patterns they are configured to detect, in the data you supply. A matter that raises no alert is not thereby legitimate, and a matter that raises one is not thereby suspicious. Forming a suspicion is a human judgment only you can make.
We never lodge for you. Altego builds and validates your SMR, TTR and IFTI-DRA files, checks them, tracks the deadline and keeps the evidence. A person at your business lodges through AUSTRAC Online and records the receipt. Altego never lodges a suspicious matter report.
Screening, and who does it. No screening provider is connected to Altego today, so screening is performed by you in your own system and the check is recorded in Altego. If we connect one, you choose whether to use it, for which lists and at what match thresholds, and you can keep screening in your own system instead. Enabling a provider does not move responsibility to us or to that provider. Where a provider is connected and enabled, its data comes from third parties and we do not warrant that it is available, accurate, complete or current, and if a source fails in a way that affects your screening we will tell you and record the period affected. Name matching is inherently imprecise whichever method is used; false positives and false negatives are normal, and the consequences of a match you discount are yours.
Identity is verified by your staff. Identity checks are recorded in Altego by your own people, against the document the person provides. No electronic verification provider is connected, so no identity data leaves Altego for one. If that changes, this page and our Privacy Policy will say which provider, what is shared and what comes back, before the method can be enabled.
Australian privacy law. We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Our Privacy Policy sets out what we collect and why.
Your customers' data. Information you hold in Altego about your own customers is yours. You decide how it is used; we hold it on your behalf so you can meet your obligations under the AML/CTF Act.
Suppliers who help us run Altego. Some suppliers handle information on our behalf. A current list, what each handles and where it operates, is available on request from altegoprivacy@altego.com.au.
If a breach ever happens. We have a written breach response process aligned to the Notifiable Data Breaches scheme. If your data is involved, we tell you, and we tell you what we know rather than waiting until we know everything.
While you are with us. Ask for an export at any time and we will provide it within 10 business days at no charge. Because an export can contain personal, financial and suspicious matter information, we confirm the person asking is an authorised contact on the account, send the file in an encrypted archive through a secure link that only that person can open and which expires, and send the password separately by text message to a mobile number already on the account. We do not email an export as an attachment.
Records we keep while you are a customer. Records subject to AML/CTF retention rules are kept for the periods those rules require, which is seven years for customer identification, transaction, report and screening records, and are not deleted on request while a retention obligation applies.
After you leave. We keep your data for 90 days after your subscription ends so you can still request an export. After that it is deleted, other than anything we are required by law to keep.
The seven-year obligation is yours. Altego is not your system of record once you have gone. Export your records before your subscription ends and hold your own copy. After the 90-day period, records held only in Altego cannot be recovered.
Security. Found something, or think you have? Email security@altego.com.au. We will acknowledge within 24 hours, and we will not pursue anyone who reports a genuine issue in good faith.
Privacy. Questions, access requests, or a complaint: altegoprivacy@altego.com.au. We respond within 5 business days.
Anything else. Email hello@altego.com.au or call 1300 556 527 during Business Hours, 9 am to 5 pm AEST Monday to Friday excluding Victorian public holidays, and we will come back to you.
Altren Group Pty Ltd · ABN 32 700 087 332 · Melbourne, Victoria, Australia