Skip to main content
Enterprise-grade security

Your participant data, protected

Enterprise-grade security built into every layer. Not bolted on as an afterthought.

256-bit

AES-GCM encryption

SHA-256

Hash-chained audit logs

5 roles

Granular access control

72 hr

Breach notification SLA

Field-Level Encryption

AES-256-GCM encryption for NDIS numbers, dates of birth, emergency contacts, and bank details. HMAC-SHA256 blind indexes enable search without decryption.

Multi-Factor Authentication

TOTP-based MFA (Google Authenticator, Authy) with 10 backup codes. Inactivity lock screen with PIN protection after 5 minutes.

Immutable Audit Trail

SHA-256 hash-chained audit logs that cannot be modified or deleted. Daily integrity verification. Full chain of custody for every data change.

Role-Based Access Control

5 roles (Admin, Property Manager, Staff, Accountant, SIL Provider) with granular permissions. Every API call verified against user permissions.

NDIS-Aligned Data Protection

AES-256 encrypted at rest. Compliant with Australian Privacy Principles (APPs) and NDIS Practice Standards. Notifiable Data Breach response under the Privacy Act (Part IIIC).

Australian Data Residency

Your database and uploaded files are stored in the Supabase Sydney region (ap-southeast-2), and the application runs in Sydney too. A limited set of specialist subprocessors (payments, email, SMS, AI document analysis, error monitoring) operate in the United States and receive only the data their function requires. Each is listed in our Privacy Policy. NDIS participant PII is AES-256-GCM encrypted before it is written.

Compliance standards we follow

  • Australian Privacy Act 1988 (13 APPs)
  • NDIS Quality & Safeguards Commission Practice Standards
  • Notifiable Data Breach scheme (Privacy Act Part IIIC)
  • OWASP Top 10 security practices

Security is not a feature. It is the foundation.

Every line of code, every database query, every API call is designed with participant data protection as the first priority.