Australian accounting, audit, and tax firms hold some of the most sensitive financial information there is, whether you are a solo practitioner or a national network. The safety posture below is enforced in code, audited continuously, and visible to your IT team on request. The three guarantees below aren't aspirations; they're structural properties of how the system is built.
Every client, every job, and every workpaper Halo has touched lives in one persistent, encrypted Database, held in Australia, with up to 5 TB of storage per seat on the Organisation plan. Nothing has to be re-uploaded or re-explained. And rather than hunting through folders yourself, you can ask Halo anything about the files in your Database and it returns the exact figure or passage in seconds, cited back to the source document.
The agent has zero authority to delete data anywhere in the system. No row, no record, no file. Deletion is a human action that requires a human credential. The agent never holds one.
Enforced at the API boundary. Audited daily.
If Halo cannot point to the source of a number, the number does not appear. There is no fallback to a plausible value. There is no quiet rounding from an unknown input. Citations are mandatory at the type level.
Citations are required types. Builds fail otherwise.
Every query the agent runs is scoped to your firm, your users, and your Job by row level security enforced in the database itself. There is no path by which one firm's work becomes visible to another, and your files stay isolated to your own tenancy.
Row level security on every table. No cross tenancy access.
Inbound emails, scanned documents, and third party files are kept structurally separate from the instructions you give Halo. The agent treats them as data to be read, not as commands to be obeyed, so a prompt injection inside a PDF cannot tell Halo to do anything. This is enforced at the parsing layer; there is no path by which a document's contents become an instruction.
Your data lives on Australian infrastructure. Your files, your conversations, and the core AI that reads and reasons over them are stored and processed in Australia. It's encrypted at rest and in transit, access is row level and attributable, and every action is logged with the user, the Job, and the source files it read. A small number of supporting features rely on trusted providers outside Australia, and we set those out below.
Your files, your conversations, and all core AI processing sit in primary and replica regions within Australian borders.
AES 256 for data at rest. TLS 1.3 for data in transit.
Every query is scoped to the user, the firm, and the Job. No silent cross tenancy access. Ever.
Every action the agent takes is logged with a user, a Job, a timestamp, and the files it read. Exported on request.
Almost everything Halo does stays in Australia. Your files, your conversations, and the core AI that reads and reasons over them are stored and processed on Australian infrastructure. A few supporting features rely on trusted providers outside Australia. We set out each one here, and name them in full in our Data Processing terms.
So you can ask questions across your whole Database, the text of your documents is sent to our search indexing provider outside Australia to build the search index. This is the only feature that sends document content offshore.
When you ask Halo to research the open web, only a sanitised query is sent to our search provider outside Australia. Client names, ABNs, ACNs, TFNs, emails, phone numbers, and large dollar amounts are stripped first, and the answer is composed back in Australia. Your documents and client data are never sent to run a search.
Billing and the transactional emails Halo sends are handled by established providers outside Australia, as is standard for software. Your client documents are never part of this.
Sit your IT, infosec, and risk teams down with us. No demo, just architecture, threat model, and the audit trail. Bring your hardest questions.