Privacy & Cryptographic
Data Sovereignty Policy
Compliant with Privacy Act 1988 (Cth), Australian Privacy Principles (APPs), and SOCI Act 2018
- 100% Australian Soil Data Residency
- Zero-Knowledge Master Key Isolation
- NIST Post-Quantum Encryption
1. Zero-Knowledge Cryptographic Custody§ 1.0
Vanguard Lattice operates strictly under zero-knowledge architectural principles. In providing post-quantum migration, lattice mesh routing, and HSM key lifecycle orchestration, our systems do not inspect, log, or retain plaintext message contents, unencrypted database records, or customer private keys.
All encryption seeds are generated and isolated inside customer-controlled FIPS 140-3 Level 3/4 Hardware Security Modules or Multi-Party Computation (MPC) shards.
2. Categories of Operational Data Collected§ 2.0
We collect strictly necessary operational telemetry and account administrative information:
3. Sovereign Australian Data Residency§ 3.0
All administrative databases, telemetry logs, and customer support channels are hosted exclusively on Australian-sovereign soil across high-security data centres located in Sydney (NSW) and Melbourne (VIC). No client data is exported to foreign jurisdictions or processed on non-sovereign cloud regions without explicit client contractual direction.
4. Quantum-Resilient Encryption Protocols§ 4.0
All client transmissions are protected against “Harvest Now, Decrypt Later” espionage vectors using hybrid quantum-safe protocols:
- In Transit: NIST FIPS 203 (CRYSTALS-Kyber) combined with TLS 1.3.
- At Rest: AES-256-GCM with hardware-enforced ephemeral key sharding.
- Identity: Hardware Root of Trust via TPM 2.0 and FIDO2 Passkeys.
5. Strict Third-Party Non-Disclosure§ 5.0
Vanguard Lattice never sells, commercializes, or shares client organizational data or telemetry with advertisers or unauthorized third parties. Information is disclosed solely where strictly required under Australian federal law pursuant to authorized warrants.
6. Cryptographic Data Sanitization§ 6.0
When accounts or engagements are closed, all associated telemetry and transient attestation keys undergo verified cryptographic erasure in accordance with NIST SP 800-88 Rev 1 guidelines and Australian Information Security Manual (ISM) standards.
7. Australian Privacy Principles (APPs) Rights§ 7.0
In accordance with the Australian Privacy Act 1988 (Cth), you possess statutory rights to request access to, verify, or amend your personal and organizational records held by Vanguard Lattice.
