Compliance
We are implementing the controls and practices defined by the following security and privacy frameworks. See each framework below for details on how these practices are implemented.GDPR
Practices implemented. Data subject rights honoured on request (access, correction, deletion, and portability) with a designated privacy contact.
ISO 27001
Practices implemented. Our security controls follow ISO 27001 principles: access control, encryption, logging, and least privilege. Formal certification is planned.
Australian & NZ privacy law
Aligned. Antlect serves Australia and New Zealand first, with practices aligned to the Australian Privacy Principles (APPs) and the NZ Privacy Act 2020.
Our GDPR practices
Our GDPR practices
What we implement today:
- Data subject rights (access, correction, deletion, and portability) honoured on request via hello@antlect.com.
- Data minimisation: the personal data we hold is limited to your account profile and the content you create in your workspaces.
- No sale of personal data, and no use of your content to train AI models.
The full GDPR statement (lawful bases, retention schedule, and response SLA) is being finalised and will be published here.
Our ISO 27001 practices
Our ISO 27001 practices
What we implement today:
- Role-based access control enforced at the API layer.
- Encryption in transit on every connection; encrypted managed storage at rest.
- Audit logging of key account and content lifecycle actions.
- Rate limiting, hardened HTTP security headers, and input sanitisation on all user-supplied content.
The full control mapping against ISO 27001 Annex A is being prepared and will be published here, along with our certification timeline.
Australian Privacy Principles & NZ Privacy Act 2020
Australian Privacy Principles & NZ Privacy Act 2020
What we implement today:
- Customer file storage hosted in AWS ap-southeast-2 (Sydney), keeping data close to the Australasian organisations we serve.
- Collection limited to what the platform needs to operate; clear channels for access and correction requests.
Operating legal entity details and the full APP/NZ Privacy Act statement are being finalised and will be published here.
Security overview
Encryption
All traffic is encrypted in transit with TLS. Data at rest lives in managed database and object storage with provider-managed encryption. No unencrypted paths exist.
Workspace isolation
Every workspace is scoped to its owner and enforced on every API request. No cross-workspace data access is possible.
Audit logging
Key lifecycle actions (creates, deletes, restores, and password reset requests) are logged with who, what, and when, and are visible in Settings > Security > Audit logs.
Session management
Sign-in is handled by a dedicated identity provider. Every API request re-verifies the token’s signature and expiry server-side. Antlect never stores your password.
Role-based access
Two roles, user and admin, with the hierarchy enforced at the API level. Access to the platform itself is granted through admin-reviewed access requests.
AI data handling
Your content is processed to answer your queries and nothing more. Your data is never used to train AI models.
- Rate limiting on every route, with stricter per-route limits on public-facing endpoints such as access requests and support.
- Strict security headers and CORS locked to the Antlect application origin.
- Input sanitisation on all rich-text content before it is stored or rendered.
- Safe error handling: internal errors are never leaked to clients in responses.
- Upload limits on all file endpoints to prevent abuse.
Compliance & data protection
GDPR practices
Full data subject rights (export, deletion, and portability) honoured on request through our designated privacy contact. A formal response SLA will be published with our full privacy policy.
Australian & New Zealand privacy
Operated for the Australasian research sector, with customer file storage in AWS ap-southeast-2 (Sydney) and practices aligned to the Australian Privacy Principles (APPs) and the NZ Privacy Act 2020. Operating entity details to be published.
Your data rights
- Export: request a complete copy of your personal data by emailing hello@antlect.com. Self-serve export from Settings is on the roadmap.
- Correction: your profile fields are editable at any time in Settings > Profile.
- Delete: request permanent removal of your account and all associated data via hello@antlect.com. Self-serve deletion from Settings is on the roadmap.
- Privacy contact: reach our privacy team at hello@antlect.com. A designated Data Protection Officer will be announced with our full privacy policy.
Infrastructure & sub-processors
Antlect runs on managed, reputable infrastructure. Customer file storage is hosted in AWS ap-southeast-2 (Sydney), keeping data in the region we serve. The following third-party services process data on Antlect’s behalf:A data processing agreement (DPA) register covering each sub-processor is being prepared and will be published here. Need a DPA in the meantime? Contact hello@antlect.com.
Policies & documentation
Data privacy
Encryption, workspace isolation, access controls, deletion, and your data rights, the full technical breakdown.
Sub-processors
Complete list of third-party services that process data on behalf of Antlect, with DPA coverage.
Cookie policy
What cookies Antlect uses, why, and how to control them.
Audit logs
Track the key actions on your account (who did what, and when) from Settings.
Password & security
How sign-in works, and how to manage your password and account security settings.
Privacy Policy
Full legal privacy policy: how we collect, use, store, and protect your personal data.
Terms of Service
Terms governing your use of the Antlect platform.
Questions?
If you have security questions, need a DPA, or want to report a vulnerability, contact us:- Privacy & data protection: hello@antlect.com
- General support: support@antlect.com