Security & Trust
Built for compliance rigor
ADM Guard's architecture is designed for a compliance product - every decision is immutable, tamper-evident, and bound by cryptography.
Architecture
Technical trust layer
Zero-PII Firewall
Every payload is scanned before storage. Personal information is actively rejected with a 422 error before persistence in the audit stream.
Client-Generated Tokens
You generate the anonymous identifiers (e.g. cand_88192_x). ADM Guard never sees or stores the mapping between tokens and individuals.
SHA-256 Hash Chain
Every decision creates a tamper-evident hash linked to all previous decisions per tenant. If historical data is altered, the chain breaks.
Daily Merkle Anchors
Every 24 hours, audit batches are cryptographically anchored to an RFC 3161 external timestamp authority.
WORM-Locked Storage
Audit logs are archived to Azure immutable storage with locked retention policy.
Per-Tenant Envelope Keys
Each tenant's encryption key is stored in Azure Key Vault, isolated and rotatable. Crypto-erasure is possible: delete the key and the tenant's audit data becomes unrecoverable.
Compliance
Meeting the Privacy Act
ADM Guard's technical design directly addresses the obligations under Australia's Privacy and Other Legislation Amendment Act 2024 (APP 1.7-1.9):
- System Registration: Every ADM system is auto-registered the moment it executes.
- Decision Recording: Each decision is logged with factors and outcome.
- Disclosure Ready: Compliance evidence reports are PDF-downloadable from your dashboard.
- PII Controls: ADM Guard applies validation and rejection controls to reduce personal information in the audit stream.
- Residency & Sovereignty: Data remains in Australian regions.
Data Residency
Australian data sovereignty controls
ADM Guard operates with Australian data residency controls enforced by cloud policy and independently auditable controls.
- Ingestion, processing, and storage are configured for approved Australian regions.
- No uncontrolled cross-border data transfers.
- Archived audit logs are immutable and retention-controlled.
- Compliance can be verified by your security team.
API Security
Safe, simple integration
The ADM Guard REST API is stateless and designed for security from first principles:
- HMAC-SHA256: Every request is cryptographically signed with your tenant key.
- Idempotency: Every write includes a client-generated idempotency key.
- Rate Limiting: Fair-use limits help prevent abuse.
- Encryption in Transit: TLS on all connections.
Verification
Audit & inspection
ADM Guard's trust model assumes your auditors and counsel will inspect the evidence and verify it independently.
- PDF Reports: Download timestamped, hash-verified compliance evidence reports.
- Chain Verification: Any forensic tool can verify SHA-256 links.
- External Timestamp: RFC 3161 timestamps are standards-based and independently verifiable.
- No Magic: ADM Guard provides technical evidence, not legal advice.
Questions about security?
We can walk through architecture, threat models, and security questionnaire responses with your InfoSec team.
Get in touch