Security, privacy & AI governance for accounting firms.

XBert is the AI automation platform used by accounting firms across AU, NZ, UK, SA, CA, and the US. The Trust Centre describes how we protect your firm's and your clients' data.

Aligned to

ISO 27001 OWASP Secure Development ACSC Essential Eight Privacy Act 1988 (Cth) GDPR (where applicable)

Built on Australian Azure

Customer data is stored in Microsoft Azure Australian regions — Australia Southeast (primary), Australia East (DR). Geo-replicated within Australia. 28-day point-in-time restore plus 12-month long-term retention. RTO < 24h, RPO < 1h.

Data Sovereignty & Residency →

AI handled responsibly

OpenAI and Anthropic are used under Data Processing Agreements that prohibit retention and model training on customer data. AI calls are ephemeral. Agent memory (Mem0) runs in Australia.

AI Governance & Data Processing →

Encrypted end-to-end

TLS 1.3 with 256-bit ciphers for traffic. AES-256 transparent data encryption on SQL. Server-side encryption on Blob Storage. Secrets in Azure Key Vault with managed rotation. Auth0-managed passwords with MFA.

Data Encryption Policy →

Compliance posture

Aligned to ISO 27001, OWASP, and the ACSC Essential Eight. Annual external penetration testing, quarterly internal audits, continuous Dependabot scanning. Privacy Act 1988 (Cth) and GDPR commitments published.

Due Diligence FAQ →

Request the Full Trust Centre

The Full Trust Centre includes the detailed architecture deep-dive, the MCP Gateway security overview, access-management, network-monitoring, incident-response, vendor-management, and the compliance framework. Access is granted on request — typically within one Australian business day.

Request access