Trust Centre

Security at Antio

A plain-language summary of how we approach the security of your data. On request and under NDA we can share available security documentation, and we are happy to sign a Data Processing Agreement.

Last updated 26 July 2026

Where your data lives — Australia

Your business data and uploaded documents are hosted in Australia, and we apply appropriate technical and organisational measures designed to keep it there. To deliver some features — including AI-assisted analysis — we may engage reputable third-party service providers; where such a provider processes data outside Australia, we limit it to the content needed to perform the task you requested and require contractual data-protection terms.

Who can get in — identity & access

  • Multi-factor authentication is available, with a policy you set per organisation.
  • Enterprise single sign-on is available, including an “SSO required” mode for organisations that need it.
  • Role-based, least-privilege access, with ownership checks applied when records are accessed.
  • Strong, breach-checked passwords, protection against automated guessing, and short, revocable sessions with a per-organisation timeout.

How your data is protected — encryption

We encrypt data in transit and at rest using industry-standard methods, and apply additional application-level safeguards to particularly sensitive information such as authentication secrets. We review and update these measures over time.

Keeping tenants apart — isolation

Antio is multi-tenant. We are designed so that each request for your data is scoped to your organisation, and we apply layered access controls intended to keep organisations separated. We continue to strengthen these safeguards over time.

Seeing what happened — audit & transparency

An audit log records security-relevant events (sign-ins, multi-factor authentication, single sign-on, invites, role changes, and admin actions) on a tiered retention schedule. Organisation admins have a self-service audit log with export.

AI you can trust — governed, advisory, non-training

Antio uses AI to assist estimators, never to make binding decisions on its own. We do not use your data to train AI models. AI is subject to a global control and a per-organisation budget governor, is designed to be read-only in relation to your business data, and operates under rules intended to keep AI-assisted output advisory and non-authoritative. You are responsible for reviewing AI-assisted output before relying on it.

Resilience & operations

Automated backups are configured, and our systems are designed for resilience with health monitoring. Formal, measured recovery objectives and regularly drilled disaster-recovery are on our roadmap.

Honesty about where we are

We are a focused team practising security-by-design. Our identity, audit logging, protection of sensitive secrets, and Australian-hosting posture are strong today, and we continue to invest in our security programme. We do not yet hold formal, recognised security certifications; obtaining one is on our roadmap for when our engagement scale warrants an independent audit. We would rather tell you where we are than overclaim.