SECURITY
Built in Australia. Your clients' data stays here.
Brokers hand Lend1 identity documents, bank data and financial history. Lend1 is built in South Australia and hosted in Sydney, so that data is not sent overseas to be stored or processed. This page sets out where it lives, who can reach it, and what we have done to prove it is safe.
Built and hosted in Australia
Designed in South Australia. Hosted on AWS Sydney, so client data stays onshore.
SOC 2 Type 2 infrastructure
Hosted on AWS, which holds SOC 2 Type 2 and ISO 27001 with Sydney in scope.
Pentested September 2026
Aikido Security. No critical or high severity findings.
AI stays in Australia
Amazon Bedrock in Sydney. Never used to train models.
AUSTRALIAN BUILT AND OWNED
Built in Australia, not localised for it
Lend1 Pty Ltd is an Australian company. The platform was designed and built in South Australia by a mortgage broker and a software engineer, rather than adapted from an overseas product with a local data centre bolted on the side.
Meet the team behind Lend1Product and engineering work happens here, by a team that knows NCCP obligations, Best Interests Duty and how an Australian aggregator actually works.
Support comes from the same people who build the platform, Monday to Friday, 9am to 5pm ACST. Not an overseas call centre reading from a script.
Client files, fact find data and AI processing stay in the AWS Sydney region. Nothing is shipped offshore for storage or model training.
Lend1 Pty Ltd (ABN 99 697 844 036) is based in South Australia, and our terms are governed by South Australian law.
HOSTING AND INFRASTRUCTURE
Hosted in Sydney on SOC 2 Type 2 infrastructure
Lend1 runs on Amazon Web Services in the Sydney region (ap-southeast-2). Client files, fact find data and bank data are stored and processed in Australia.
AWS compliance programsAWS is audited against SOC 1, 2 and 3 and certified to ISO 27001, with the Sydney region in scope. Reports are published through the AWS compliance programme.
All traffic is encrypted in transit with TLS, and data is encrypted at rest.
Automated database backups run on a schedule, so a lost or corrupted record can be restored.
Infrastructure is fully managed, with patching and network isolation handled at the platform level. There is no self-managed server to fall behind.
INDEPENDENT TESTING
Independently tested, with nothing critical left open
In September 2026 the Lend1 web application and API were penetration tested by Aikido Security. Aikido's agentic testing platform exploits and validates findings rather than just flagging them, so every result in the report is a confirmed issue, not a scanner guess.
Request the Letter of AttestationNo critical or high severity findings.
Every finding was remediated and confirmed closed by a retest.
A Letter of Attestation is available on request for due diligence and RFPs.
The Simplified Auditor Report is available to prospective customers under NDA.
AI AND YOUR DATA
AI that runs in Australia and never trains on your data
Lend1's AI features, from document extraction to plain-English deal updates, run on Amazon Bedrock in the AWS Sydney region. Nothing is routed to overseas AI providers.
How Lend1 uses AIPrompts and outputs are processed and stored in Sydney.
Amazon Bedrock does not use customer content to train or improve models, and does not share it with the model providers.
Bedrock sits within the scope of AWS's SOC 1, 2 and 3 reports and ISO 27001 certification.
AI output lands on the client's file in Lend1, where the same access controls and audit logging apply.
ACCESS AND ACCOUNTABILITY
Who can see what, and a record of what they did
A client file holds identity documents and years of financial history. Lend1 controls who inside your brokerage can reach it and keeps a record of activity.
See the client portalTwo-factor authentication for broker logins.
Role-based access, so admins, brokers and support staff only see what their role needs.
Audit logging records who did what on a client file, and when.
Clients only ever see their own portal, branded to your brokerage.
WHERE YOUR DATA GOES
The partners that touch client data
Lend1 connects to a small set of services to do its job. Each one only receives the data it needs for the task listed here.
| Partner | What it is used for |
|---|---|
| Amazon Web Services | Hosting for the Lend1 platform, and AI processing through Amazon Bedrock. Both in the Sydney region. |
| Fiskil | Collects bank data through the Consumer Data Right (open banking) with the client's consent. |
| CashDeck | Retrieves bank statements when a lender or client prefers a statement over an open banking feed. |
| Connective Mercury Nexus | Receives completed onboarding data so your aggregator software stays the system of record. |
| Brevo | Sends client emails and automated follow-ups on your behalf. |
| Twilio | Sends SMS reminders and follow-ups to clients. |
Privacy and compliance
Lend1 Pty Ltd handles personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth). Our privacy policy sets out what we collect, why we collect it, and how clients can access or correct it.
Because Lend1 is built here and client data is hosted and processed here, there is no overseas disclosure to explain to your clients or your aggregator.
Responsible disclosure
If you believe you have found a vulnerability in Lend1, email us with the details and steps to reproduce it. We acknowledge every report and keep you informed while we investigate.
We will not take action against researchers who report in good faith and give us a reasonable chance to fix the issue before disclosing it.
Need it for procurement?
Request our security pack and we will send the Letter of Attestation, details of our hosting and AI infrastructure compliance, and answers to your security questionnaire.
Built for brokers who take client data seriously.
Join the mortgage, finance and insurance brokers who trust Lend1 to streamline their operations and grow their business.
Get Started TodaySet Up in Minutes
Dedicated Support