Trust Centre

    Enterprise-grade security for Aged Care.

    We protect resident data with the same rigour as a financial institution. Our platform is built on a foundation of strict data sovereignty, encryption, and compliance with Australian law.

    Regulatory Compliance

    We are a compliant APP Entity under the Privacy Act 1988 (Cth).

    We adhere to the Notifiable Data Breaches (NDB) scheme.

    Our governance aligns with Aged Care Quality Standard 5 (Clinical Governance).

    Data Sovereignty

    Your data never leaves Australia.

    Primary Database: Sydney (AWS ap-southeast-2).

    AWS Services: Sydney (ap-southeast-2).

    Backups: Sydney (Replicated across 3 Availability Zones).

    Infrastructure Security

    Hosted on Supabase (SOC 2 Type II Certified).

    Data Encrypted At Rest (AES-256).

    Data Encrypted In Transit (TLS 1.3).

    Network protection via AWS Shield.

    Security Controls

    Product Security

    How our application protects your data at the code level.

    Row Level Security (RLS)

    Every database query is cryptographically verified. Users can only access data belonging to their specific organisation.

    Authentication

    We use secure JWTs (JSON Web Tokens) for session management. Passwords are hashed using bcrypt and never stored in plaintext.

    Role-Based Access (RBAC)

    Granular permissions ensure staff members only see the data required for their specific role (e.g., carer vs. administrator).

    Automated Scanning

    Our codebase undergoes automated vulnerability scanning (SAST/DAST) prior to every deployment.

    Trusted Subprocessors

    We use a minimal set of enterprise-grade providers to deliver our service. We do not sell data.

    ProviderService ProvidedLocationSecurity Certifications
    Supabase (AWS)Core Database, Auth, Edge FunctionsSydney, AU
    SOC 2 Type II
    HIPAA
    AWSSES, Integrations, Amplify, AI/LLMSydney, AU
    SOC 2 Type II
    ISO 27001
    Zoho DeskCustomer Support TicketingSydney, AU
    ISO 27001
    GDPR

    Frequently Asked Questions

    Information valid as of: November 25, 2025