Security & privacy

Privacy boundaries built into the product

AML/CTF work is sensitive. Lex-AML is structured so each audience only sees what it should — your team in the Organisation Workspace, and each customer only their own submission.

By design

What protects your information

Separated applications and access

The Organisation Workspace and Customer Portal are kept apart, with separate sign-ins, so each audience only sees what it should.

Your team makes the decisions

The Customer Portal collects information; your organisation makes every customer due diligence decision. The platform never decides for you.

Records used only to run the service

GetPost Labs operates the platform and processes limited operational metadata to run, monitor, secure and support it. Your compliance records are not used for unrelated marketing purposes.

Organisation-specific data boundaries

Each organisation’s records are handled within organisation-specific data boundaries, with access restricted to authorised operational, security, support or legal purposes — controlled and logged.

Customers see only their own information

In the Customer Portal, each customer sees only their own submission, in plain language — never another customer’s information or your internal workspace.

Complete audit trail

Important actions are recorded in your Organisation Workspace audit trail, supporting review-ready, defensible record keeping.

Operational safeguards

Access & sessions

Your organisation manages who has access to its workspace, with time-limited invitations and one-time codes and session timeouts to help keep accounts secure. Authentication and multi-factor sign-in are supported and configurable.

Configured verification and screening support

Lex-AML can support DVS identity verification and Australian PEP checks where configured for an organisation. These checks depend on provider setup, credentials and release configuration. Your team remains responsible for reviewing results and recording decisions.

Record retention support

Lex-AML supports organised record keeping, including 7-year retention settings where configured. Retention settings should be aligned with your organisation’s policy, legal obligations and service agreement.

Records & audit trail

Important actions are captured in your audit trail to support review-ready, defensible record keeping.

Operational metadata

GetPost Labs processes limited operational metadata to run, monitor, secure and support the platform. Access to organisation and customer records, where technically available, is restricted to authorised operational, security, support or legal purposes — controlled and logged.

Organisation-specific data boundaries

Organisation and customer records are handled within organisation-specific data boundaries, with access restricted to authorised operational, support, security or legal purposes.

For how we handle personal information, see our Privacy Policy.

Lex-AML supports compliance workflows and record keeping. It does not provide legal advice, does not guarantee compliance, and does not replace professional judgement or advice from a qualified AML/CTF adviser or legal professional.

Questions about data handling?

Book a demo and we’ll walk through exactly how your data is separated, stored and audited.