About usCareersCase studiesPricingBook a demoLog in
Security

Where your clients' data actually lives

Australian advice firms ask us one question before any other: where does the data go? Here's the straight answer. Where it's stored, what happens during processing, and the controls that stand behind all of it.

Sacha Lala

Sacha Lala

Security & Compliance Lead, Marloo

Sacha spent years assessing organisational risk and cybersecurity controls at EY and Arm before joining Marloo. Having sat on both the external consulting and internal GRC sides of the table, she brings an auditor's eye to what actually matters in AI and third-party tools.

Before joining Marloo as Security & Compliance Lead, I spent years assessing organisational risk and cybersecurity controls at EY and Arm (a British semiconductor company). I've sat on both sides of the table: the external consultant reviewing a vendor's claims, and the internal team defending its own. That work leaves you with a particular habit. You stop listening to what a company says about security and start looking at what it can show.

This post is written in that spirit. When an Australian advice firm evaluates an AI tool, the first question is almost never about features. It's about location. Client files in this industry carry everything: financial positions, health disclosures, family circumstances. Firms want to know, in plain terms, where that information physically sits.

Your data is stored in Australia

Customer data for Australian firms is stored in Australia, on Supabase infrastructure hosted in Sydney. That's where your recordings, transcripts, file notes, client records and documents live. Daily encrypted backups are also held in Australia.

What happens during processing

Delivering the service takes specialist providers: Recall AI (meeting recording), AssemblyAI (transcription), and Anthropic and OpenAI (the language models that draft your file notes, summaries and documents). Each is a named sub-processor with a contract that governs exactly what it can and can't do with the data.

The terms are what count. Recall AI and AssemblyAI hold recordings and audio only for as long as it takes to do their job, then delete them. The language models operate under enterprise zero data retention agreements: a prompt goes out, a draft comes back, and nothing is stored or used to train models. Our privacy policy commits us to the same (section 9.5).

Your client records live in Sydney. What leaves is transient and comes straight back, and where that round trip crosses the border we remain accountable under the Australian Privacy Principles.

What happens to your data if you leave?

While your account is active, your data stays available to you. Your account administrator can also set specific retention periods for both the raw transcript and audio recordings. These can be 7, 14, 30 or 90 days, 1 year, or keep forever. Content is deleted automatically when the chosen period ends. When an account terminates, you can instruct us to delete or export everything. We delete working copies promptly and retain one encrypted legal-backup copy for up to seven years, unless you request a shorter hold. Earlier deletion of specific items is available any time via support@marloo.com.

The controls behind the claims

Saying the right things is easy. Here's what's independently verified:

  • SOC 2 Type 2. Currently held, with live controls visible in our Trust Centre at trust.marloo.com. The full report is available under NDA.
  • Google CASA.We recently completed Google's Cloud Application Security Assessment, the independent security review required of applications that access Google user data at the depth Marloo does.
  • Two independent penetration tests in the last ten months, October 2025 and April 2026. Executive summaries available under NDA.
  • A “Very Good” Aphore CARR rating, the same cyber-maturity category as Microsoft Copilot.
  • Cyber Essentials. Certification is in progress through our UK entity under the UK government-backed scheme.

Behind the certifications, the everyday controls matter just as much. Your data is encrypted with AES-256 at rest and TLS 1.2 or higher in transit. Row-level security is enforced in the database itself, which means the database, not just the application, ensures one customer can never see another customer's data. Access for our own staff is governed by least-privilege policies with mandatory multi-factor authentication, and those access rights are reviewed every quarter. And if a personal data breach ever affects your data, our DPA commits us to notifying you without undue delay, with the details you need to meet your own obligations.

Security is someone's job here

Our security team is myself (Security and Compliance Lead) and a Founding Security Engineer. We answer your security questionnaires and the compliance questions that come with using AI in a regulated industry. When your licensee or compliance team has questions, there are people on the other end who have answered them before.

The short version

Your clients' data is stored in Sydney. Processing happens with named providers under contracts where nothing is retained. The claims above are backed by independent audits, and there are people at Marloo whose job is to keep us secure. If your compliance team has further questions, our Trust Centre at trust.marloo.com is open, and we're happy to complete your due-diligence questionnaire.

Your calling is advice,
not admin

Set up in minutes. Start with your next meeting, completely free.

Start with your next meeting
See it in action