Data & security

How we handle your data

Your practice holds some of the most sensitive information there is: identity documents, visa history, health and character matters. Here is exactly how that data is handled, from where it lives to who can touch it to how it stays yours.

Onshore in AustraliaPer-practice isolationEncrypted in transit and at rest
Where it livesOnshore
Australian data centres
Practice A
Practice B
Practice C

Kept strictly separate, practice by practice.

Your data stays in Australia.

01Data residency

Where your data lives

Migration Ready stores your data in Australian data centres, so your clients' information stays onshore. It is encrypted while it travels between you and the platform, and while it is stored, in line with the Australian Privacy Principles.

Stored in Australia, encrypted in transit and at rest

02The team behind it

Built by data professionals

Migration Ready is built by a team whose background is data projects and data engineering. That means data security and data protection are not features bolted on at the end. They are first-class product requirements, designed in from the start and treated the way a data team treats data it is trusted with.

03Access controls

Who can touch it

The controls below are in place today, on every practice, on every plan.

Strict per-practice isolation

Every practice's data is kept strictly separate from every other practice's, so one practice can never reach another's records.

Role-based access

Access follows the role each person holds in the practice, so team members see what their work needs and no more.

Mandatory multi-factor authentication

Multi-factor authentication is required for every user and cannot be switched off, so a leaked password alone is not enough to get in.

Complete audit trail

Every change is written to a complete audit trail, so who did what and when is always on the record.

04AI and your data

What touches it: our AI principles

Your clients' documents and files are never sent to AI. Uploaded documents, portal submissions and everything else a client provides stay inside our controlled, audited environment, not in a browser extension that injects them into third-party websites.

By default, the only built-in AI is the help assistant. mGenie answers how-to questions about the product. It reads our documentation, not your data.

Two optional assists, off until you switch them on. Both work only on content you write or dictate yourself, never on what a client sends you. Tidying a dictated transcript into a draft file note is processed in Australia, and the recording is deleted as soon as transcription completes. Drafting a lead's conversion summary works the same way, from your own file notes, excluding anything tagged Internal or Lawyer. Each is processed in Australia, each stays off until your practice turns it on, each carries its own consent, and nothing from either is ever used to train AI models.

05What we send out

What leaves it

We do not sell personal information, we never use it for advertising, and we never use client records to train AI models. We rely on a small number of trusted service providers strictly to run the platform, and nothing more.

Backup you control

You can mirror a continuous, one-way backup of your documents to your own SharePoint or Google Drive, so a copy always sits in storage you own. It is one-way: we write your documents out to your storage, we never read them back.

06You own it

Your data stays yours

You own the data your practice puts into Migration Ready. If you ever close your account, we will make your practice's data available for export for a reasonable period before deletion, subject to any legal or professional record-keeping obligations.

For the full detail, see our privacy policy and terms of service.

Data you can trust us with

Onshore storage, strict isolation and controls designed in from the start, by a team that treats data protection as the job, not an afterthought.