Field-Level Encryption
AES-256-GCM encryption for NDIS numbers, dates of birth, emergency contacts, and bank details. HMAC-SHA256 blind indexes enable search without decryption.
Enterprise-grade security built into every layer. Not bolted on as an afterthought.
256-bit
AES-GCM encryption
SHA-256
Hash-chained audit logs
5 roles
Granular access control
72 hr
Breach notification SLA
AES-256-GCM encryption for NDIS numbers, dates of birth, emergency contacts, and bank details. HMAC-SHA256 blind indexes enable search without decryption.
TOTP-based MFA (Google Authenticator, Authy) with 10 backup codes. Inactivity lock screen with PIN protection after 5 minutes.
SHA-256 hash-chained audit logs that cannot be modified or deleted. Daily integrity verification. Full chain of custody for every data change.
5 roles (Admin, Property Manager, Staff, Accountant, SIL Provider) with granular permissions. Every API call verified against user permissions.
AES-256 encrypted at rest. Compliant with Australian Privacy Principles (APPs) and NDIS Practice Standards. Notifiable Data Breach response under the Privacy Act (Part IIIC).
Your database and uploaded files are stored in the Supabase Sydney region (ap-southeast-2), and the application runs in Sydney too. A limited set of specialist subprocessors (payments, email, SMS, AI document analysis, error monitoring) operate in the United States and receive only the data their function requires. Each is listed in our Privacy Policy. NDIS participant PII is AES-256-GCM encrypted before it is written.
Every line of code, every database query, every API call is designed with participant data protection as the first priority.