🐒Monkey AssetsAsset register
Data residency & sovereignty

Your asset data lives in Australia — and we will show you exactly where

Monkey Assets is hosted in Sydney. Your register, its history, the files you upload and the audit trail are stored on Australian infrastructure. A short, complete list of things does leave: two AI features, one that runs only when somebody scans a photo and one that is on by default until an admin switches it off; your billing details if you subscribe; and your own Microsoft tenant if you connect it. This page says precisely what each one sends, when, and how to decline it.

What we store, and where

One answer, not a region list you have to decode: your register is stored in Sydney, Australia. That covers the whole of it, not just the database row.

  • Hosted in Sydney The register, every asset and its full movement history, on Australian infrastructure.
  • Your files too Photos, receipts, spec sheets and any other attachment are stored in Australia alongside the record they belong to, not on some other continent.
  • The audit trail Who changed what and when is recorded and kept here, which is usually the part an auditor actually asks to see.
  • Per-organisation isolation Hard tenant boundaries enforced on every request, so one organisation can never see another's gear.

What can leave your register — and exactly what it sends

Most vendors answer this with "we may share data with sub-processors". Here is the actual list for your asset data. Both are AI features and both send only what the feature needs, but they are declined differently. Performance scoring is on by default, and an admin switches it off for the whole organisation in settings. AI photo intake has no switch because it never runs on its own — it happens when somebody scans a photo, so declining it means not scanning one. Either way the result comes straight back to your Australian-hosted register.

  • AI photo intake Sends the photo you scan, to read the make, model and serial off the device or its label. This happens only when someone runs an AI scan, from the AI Import page or the app. Add assets by hand and this call is never made.
  • Performance scoring Sends the hardware a machine reports about itself — type, manufacturer, model, serial, operating system, CPU, memory and storage, plus a fixed list of processor, disk, graphics, motherboard, BIOS and system details, and nothing else, to rate what the machine is still good for. This happens automatically when a machine first registers itself through a check-in — from the desktop uploader, an intake key, or your own tooling calling the check-in API — and whenever someone re-scores an asset, unless an admin has switched performance scoring off for your organisation (it is on by default). Switch AI performance scoring off in your organisation settings and no specs are sent, whatever checks in.

What can leave about your account — the part most pages leave out

This is separate from your register and much smaller, but it is real, so it belongs on the page rather than in a sub-processor annexe you have to go digging for. It is who you are to us as a customer, never what is in your register.

  • Stripe Receives your organisation name, the billing admin's email address and your account number with us, to raise the subscription and send the receipts. This happens only once someone starts a checkout for a paid plan — an organisation that never starts one is never registered with Stripe at all. Never start a checkout and no billing record of yours is created.
  • Card details never touch us Your card number, CVC and billing address are typed into Stripe's own hosted checkout page. They never reach our servers at all, so there is nothing here for us to store, leak or be asked for.
  • Nothing is created until you start a checkout A Stripe customer record is created the moment an admin begins checkout — not when the payment succeeds — and it stays if you later cancel. Evaluate without ever pressing upgrade and no billing detail of yours exists anywhere.

Your own Microsoft tenant, if you connect it

Worth naming separately because it is your environment rather than a supplier we chose: if you use Microsoft sign-in or import devices from Intune, you are talking to your own Microsoft tenant, at your initiative.

  • Microsoft 365 sign-in and device import Sends the sign-in request, the identifier of the tenant it belongs to and — if you switch on Intune enforcement or handover gating — the device and the directory id of the person it is assigned to, so Microsoft can authenticate your own staff, hand back the devices you asked us to import, and record the assignment back in your own directory. This happens only if an admin connects a Microsoft 365 tenant, or someone signs in with Microsoft instead of an email address. Use email sign-in and leave the integration disconnected.
  • Nothing is connected by default A new organisation has no Microsoft connection at all. Somebody with admin rights has to deliberately set one up.

One more, for completeness

This one is ours rather than yours, and it is the smallest thing on the page. It is here because a list that quietly omits the inconvenient item is the thing this page exists not to be.

  • Our own signup notification Sends nothing but an organisation id, so a small team knows an organisation was created and can go and look. This happens once, at the moment the organisation is created. Nothing to decline — it carries an id and no names.

Want nothing to leave at all? That is a supported way to run it

None of the doors above is load-bearing. Decline all of them and nothing of yours goes offshore — the register is completely usable that way, not a crippled mode. One of the doors is a setting rather than a habit: an admin switches performance scoring off once, for everybody, instead of the whole team having to remember not to press a button.

  • Add assets by hand Creating and editing assets in the web app makes no AI call whatsoever — the register is fully usable without either feature.
  • QR labels are entirely local Tags are minted, printed and scanned by us in Australia. Labelling and scanning your fleet never involves an AI call.
  • The AI scan is a deliberate act A photo is only ever sent because somebody chose to run an AI scan on it.
  • Scoring can be switched off Left alone it is on, and specs are sent when a machine checks in — through the desktop uploader, an intake key, or your own tooling calling the check-in API — and when somebody presses Re-score on an asset. An admin can switch AI performance scoring off for the whole organisation in settings, and then neither trigger sends anything. Machines still register and still get their asset tag and QR code; they just arrive unrated.

What to hand procurement — including what we are not

The useful thing in a tender response is a straight answer, so here are both halves of ours.

  • You can name the country Asset data is stored in Sydney, Australia, and every exception above is documented on this page rather than buried in a sub-processor annexe. Quote it straight into your tender response.
  • Australian-made and supported Built and run by Ausplace Solutions Pty Ltd, an Australian company, billed in AUD with GST included.
  • Helps with your asset inventory Maintaining an accurate hardware inventory underpins frameworks like the Essential Eight, and the audit trail evidences that you keep it current.
  • We are not certified, and we will not imply it We do not hold ISO 27001, SOC 2 or IRAP assessment. If your policy requires a certified provider, we are not it yet, and you should know that before a trial rather than after.

Common questions

Where exactly is my data stored?

In Sydney, Australia. That includes your asset register, its full history, the files you upload and the audit log. If your procurement process needs the specific provider and region named in writing, ask us and we will confirm it.

Does any of my asset data leave Australia?

Only through two AI features, and only what each one needs. AI photo intake sends the photo you scan, to read the make, model and serial off the device or its label, only when someone runs an AI scan, from the AI Import page or the app. Performance scoring sends the hardware a machine reports about itself — type, manufacturer, model, serial, operating system, CPU, memory and storage, plus a fixed list of processor, disk, graphics, motherboard, BIOS and system details, and nothing else, to rate what the machine is still good for, automatically when a machine first registers itself through a check-in — from the desktop uploader, an intake key, or your own tooling calling the check-in API — and whenever someone re-scores an asset, unless an admin has switched performance scoring off for your organisation (it is on by default). Nothing else from your register — no asset record, no file, no history, no audit entry — goes to our AI provider or any other supplier we chose. The one exception is your own Microsoft tenant: switch on Intune enforcement or handover gating and we write the device and its assignee back into your directory, because that is what you turned it on to do.

Does anything else leave Australia?

Three things, none of them from your register. Stripe receives your organisation name, the billing admin's email address and your account number with us, to raise the subscription and send the receipts, only once someone starts a checkout for a paid plan — an organisation that never starts one is never registered with Stripe at all. Nothing from your register goes with it, and card details are typed into Stripe's own page and never touch our servers. Microsoft 365 sign-in and device import sends the sign-in request, the identifier of the tenant it belongs to and — if you switch on Intune enforcement or handover gating — the device and the directory id of the person it is assigned to, so Microsoft can authenticate your own staff, hand back the devices you asked us to import, and record the assignment back in your own directory, only if an admin connects a Microsoft 365 tenant, or someone signs in with Microsoft instead of an email address. Our own signup notification sends nothing but an organisation id, so a small team knows an organisation was created and can go and look, once, at the moment the organisation is created. We would rather list those here than have you find them in a sub-processor annexe.

Can I run Monkey Assets with nothing leaving Australia at all?

Yes, and it is a fully usable register that way — add and edit assets, print and scan QR labels, invite your team, keep the audit trail. Here is the whole recipe: Add assets by hand and this call is never made. Switch AI performance scoring off in your organisation settings and no specs are sent, whatever checks in. Never start a checkout and no billing record of yours is created. Use email sign-in and leave the integration disconnected. Do that and nothing of yours goes offshore. The only thing that ever crosses in that setup is our own signup notification telling us an organisation was created, which carries an id and no names.

Are you ISO 27001, SOC 2 or IRAP certified?

No. We do not hold those certifications and we would rather say so plainly than let a security page imply otherwise. What we do provide is Australian hosting, per-organisation isolation, two-factor authentication or Microsoft SSO, and a full audit trail.

Does this make us Essential Eight compliant?

No product can do that for you. Monkey Assets makes the asset-inventory part straightforward and gives you an audit trail to evidence it, while your compliance overall stays your responsibility.

Who can see my organisation's data?

Only people you invite, and only as far as their role and site purview allow — viewers see just the gear assigned to them or at their sites. Tenant boundaries are enforced on every single request, so another customer can never see your assets.

Keep reading

An asset register that can tell you where your data is

Start free — hosted in Sydney, priced in AUD, with AI performance scoring yours to switch off.