Hoist AI
Source-cited

Registers stay the source

Results carry the originating source and timestamp. Hoist does not rewrite a register record.

Governed

Approved access only

Connected tools can only run the checks an account owner has approved, within the account's limits.

Auditable

Evidence over claims

Searches produce timestamps, source labels, outcomes, and evidence references customers can review.

Plain disclaimer. HoistAI returns Australian data and review flags. It does not provide legal, financial, credit, tax, or compliance advice. Ask your lawyer, accountant, or compliance officer how a record fits a specific obligation.

Legal entity

What Hoist can check

Hoist supports available ABN checks. PPSR preview and explicit-confirmation mechanics are implemented but not currently customer-accessible; preview requests fail closed without a price or register dispatch. Paid PPSR searches and pricing are not currently available through Hoist. Individual-grantor searches are never supported. See /trust/afsa-b2g.

Hard limits

Hoist implements organisation and serial-number PPSR contract shapes, but current preview and paid-search requests fail closed. It never offers searches for individual people, driver licences, residential addresses, or personal identity details. That limit applies to every customer, every connected tool, and every support request. For the detailed boundary, see /trust/npii-boundary.

Controls

  • Human approval: Connected tools can only use the access an account owner approves.
  • Review and revoke: Account users can review connected access and disconnect tools from the account surface.
  • No current paid dispatch: Available workflows are free. Any future paid source would require a separately proved price and explicit confirmation before dispatch.
  • No override path: Support cannot turn on person searches or bypass the org-only boundary.

Logs

Every completed search gets a durable log. It records the account, the connected tool if one was used, the type of check, the identifier checked, the source, the time, the outcome, and the evidence reference. It does not store sign-in secrets, prompts, card numbers, or unrelated account data.

What customers can verify

Each supported search can return a source-cited Evidence Card with the source, timestamp, result summary, and record reference. The separate Evidence Pack export is a prelaunch sample whose fixture or unsearched rows are not source results. The customer-facing evidence formats are explained at /evidence-pack. Developers who need exact interface details should use the developer docs.

Data handling

  • Service hosting: Cloudflare, with Australian routing preferred where available.
  • Account, search, and log records: Encrypted storage with AU/APAC preference where supported.
  • Record PDFs and certificates: Encrypted storage with AU/APAC preference where supported.
  • Payments: Stripe (merchant of record). We do not store card numbers, expiry, or CVC.
  • Email: Postmark.
  • Error tracking: Sentry, AU region.

Residency model in detail at /trust/residency. Where Cloudflare or Stripe processes data outside AU, the categories and lawful bases are listed there.

Security

  • Disclosure policy: Report security issues through /security.
  • Certifications: SOC 2 and ISO 27001 are not certified today. We will not imply certification before it exists.
  • Procurement review: Procurement teams can request a security questionnaire and current assurance material.
  • Encryption: HTTPS in transit and encryption at rest. Higher-volume accounts can discuss customer-specific key controls.

Support

For account access, billing, setup help, or questions about a record, use /contact/. Security vulnerabilities should use the disclosure path at /security.

Insurance

Professional indemnity (A$5M aggregate), cyber liability (A$2M), public liability (A$10M). Certificates available on request to procurement contacts.

Data retention

Records and certificates stay available for 30 days after account closure or, for a legacy billing relationship, after that relationship ends so customers can export them. Minimal verification receipts are retained so historic records can still be checked. Billing metadata, where it exists, is retained as required for Australian tax records.

Subprocessors

VendorPurposeRegion
Cloudflare, Inc.Service hosting, storage, deliveryAU/APAC preference + global edge
Stripe Payments AustraliaPayment processingAU + US
Postmark (ActiveCampaign)Transactional emailUS
SentryError monitoringAU
ClerkDashboard sign-inUS (data minimised)
AFSASource PPSR registerAU
ABR / ATOSource ABN registerAU

Connected tools and AI agents

HoistAI is designed for account owners who want AI agents, assistants, business applications, or automated workflows to run Australian data searches and checks. The same safety rules apply no matter which tool starts the search.

  • No silent spend. PPSR preview is not currently customer-accessible, and paid PPSR searches and pricing are also unavailable. Future paid actions will require explicit confirmation. See /pricing.
  • Org-only regardless of caller. The individual-grantor boundary applies to humans, AI assistants, business apps, and batch jobs. See /trust/npii-boundary.
  • Approved access only. A human approves what a connected tool may do. The tool cannot widen that approval by changing a prompt, field, or request.
  • No bypass path. There is no prompt, setup option, or support switch that turns on person searches or bypasses price confirmation.
  • Evidence, not advice. Supported HoistAI checks return source-cited Evidence Cards with what was checked, when it was checked, what came back, and what needs review. Separate Evidence Pack exports are prelaunch fixture or unsearched samples. HoistAI does not make compliance decisions. If a connected tool says "approved" or "cleared", that is the tool's interpretation, not HoistAI's conclusion.
  • Security details. Connected-tool controls are summarised at /trust/security.

Material changes to this page

Tracked in /changelog with the tag trust. RSS feed: /changelog/feed.xml.

Example Due Diligence Record

Sample records show only the fixture PPSR response shape and are labelled as sample data. No current Hoist production PPSR record exists. A future production record would require a launch-approved paid search to complete with durable proof. View example record.


Sub-pages