Trust for Australian data workflows.
Approved access, clear records, and a source-cited Evidence Card for each supported check. Evidence Pack exports are separate prelaunch samples.
HoistAI gives account-approved tools access to Australian data for business workflows. Results stay tied to their source, searches stay inside the approved account boundary, and customers can inspect what was checked.
Registers stay the source
Results carry the originating source and timestamp. Hoist does not rewrite a register record.
Approved access only
Connected tools can only run the checks an account owner has approved, within the account's limits.
Evidence over claims
Searches produce timestamps, source labels, outcomes, and evidence references customers can review.
Legal entity
- Trading name: Hoist
- Operating entity: HoistAI Pty Ltd
- ABN: 11 695 718 659
- ACN: 695 718 659
- Registered office: 81–83 Campbell Street, Surry Hills NSW 2010
- Principal place of business: Same.
- GST registered: Yes (effective 2024).
What Hoist can check
Hoist supports available ABN checks. PPSR preview and explicit-confirmation mechanics are implemented but not currently customer-accessible; preview requests fail closed without a price or register dispatch. Paid PPSR searches and pricing are not currently available through Hoist. Individual-grantor searches are never supported. See /trust/afsa-b2g.
Hard limits
Hoist implements organisation and serial-number PPSR contract shapes, but current preview and paid-search requests fail closed. It never offers searches for individual people, driver licences, residential addresses, or personal identity details. That limit applies to every customer, every connected tool, and every support request. For the detailed boundary, see /trust/npii-boundary.
Controls
- Human approval: Connected tools can only use the access an account owner approves.
- Review and revoke: Account users can review connected access and disconnect tools from the account surface.
- No current paid dispatch: Available workflows are free. Any future paid source would require a separately proved price and explicit confirmation before dispatch.
- No override path: Support cannot turn on person searches or bypass the org-only boundary.
Logs
Every completed search gets a durable log. It records the account, the connected tool if one was used, the type of check, the identifier checked, the source, the time, the outcome, and the evidence reference. It does not store sign-in secrets, prompts, card numbers, or unrelated account data.
What customers can verify
Each supported search can return a source-cited Evidence Card with the source, timestamp, result summary, and record reference. The separate Evidence Pack export is a prelaunch sample whose fixture or unsearched rows are not source results. The customer-facing evidence formats are explained at /evidence-pack. Developers who need exact interface details should use the developer docs.
Data handling
- Service hosting: Cloudflare, with Australian routing preferred where available.
- Account, search, and log records: Encrypted storage with AU/APAC preference where supported.
- Record PDFs and certificates: Encrypted storage with AU/APAC preference where supported.
- Payments: Stripe (merchant of record). We do not store card numbers, expiry, or CVC.
- Email: Postmark.
- Error tracking: Sentry, AU region.
Residency model in detail at /trust/residency. Where Cloudflare or Stripe processes data outside AU, the categories and lawful bases are listed there.
Security
- Disclosure policy: Report security issues through /security.
- Certifications: SOC 2 and ISO 27001 are not certified today. We will not imply certification before it exists.
- Procurement review: Procurement teams can request a security questionnaire and current assurance material.
- Encryption: HTTPS in transit and encryption at rest. Higher-volume accounts can discuss customer-specific key controls.
Support
For account access, billing, setup help, or questions about a record, use /contact/. Security vulnerabilities should use the disclosure path at /security.
Insurance
Professional indemnity (A$5M aggregate), cyber liability (A$2M), public liability (A$10M). Certificates available on request to procurement contacts.
Data retention
Records and certificates stay available for 30 days after account closure or, for a legacy billing relationship, after that relationship ends so customers can export them. Minimal verification receipts are retained so historic records can still be checked. Billing metadata, where it exists, is retained as required for Australian tax records.
Subprocessors
| Vendor | Purpose | Region |
|---|---|---|
| Cloudflare, Inc. | Service hosting, storage, delivery | AU/APAC preference + global edge |
| Stripe Payments Australia | Payment processing | AU + US |
| Postmark (ActiveCampaign) | Transactional email | US |
| Sentry | Error monitoring | AU |
| Clerk | Dashboard sign-in | US (data minimised) |
| AFSA | Source PPSR register | AU |
| ABR / ATO | Source ABN register | AU |
Connected tools and AI agents
HoistAI is designed for account owners who want AI agents, assistants, business applications, or automated workflows to run Australian data searches and checks. The same safety rules apply no matter which tool starts the search.
- No silent spend. PPSR preview is not currently customer-accessible, and paid PPSR searches and pricing are also unavailable. Future paid actions will require explicit confirmation. See /pricing.
- Org-only regardless of caller. The individual-grantor boundary applies to humans, AI assistants, business apps, and batch jobs. See /trust/npii-boundary.
- Approved access only. A human approves what a connected tool may do. The tool cannot widen that approval by changing a prompt, field, or request.
- No bypass path. There is no prompt, setup option, or support switch that turns on person searches or bypasses price confirmation.
- Evidence, not advice. Supported HoistAI checks return source-cited Evidence Cards with what was checked, when it was checked, what came back, and what needs review. Separate Evidence Pack exports are prelaunch fixture or unsearched samples. HoistAI does not make compliance decisions. If a connected tool says "approved" or "cleared", that is the tool's interpretation, not HoistAI's conclusion.
- Security details. Connected-tool controls are summarised at /trust/security.
Material changes to this page
Tracked in /changelog with the tag trust. RSS feed: /changelog/feed.xml.
Example Due Diligence Record
Sample records show only the fixture PPSR response shape and are labelled as sample data. No current Hoist production PPSR record exists. A future production record would require a launch-approved paid search to complete with durable proof. View example record.
Sub-pages
Org-only PPSR
What we will and won't search.
Read boundary Unavailable boundaryPPSR access status (unavailable)
Current fail-closed AFSA access posture and the future org-only contract.
Read source notes ResidencyData residency
Where customer data is handled and retained.
Read residency SecuritySecurity posture
Controls, logs, disclosure, support, and assurance notes.
Read securityBuild on data you can stand behind.
Approved access, Australian data, and source-cited Evidence Cards your team can review.
