Trust Centre
Security, privacy, standards, and infrastructure in one place — built for health service CTOs, workforce leaders, and security teams who need straight answers.
Explore by Topic
Security
Encryption at rest and in transit, SSO, MFA, RBAC, audit logging, and security-by-design.
🛡️Privacy
What we collect and do not collect, data subject rights under APPs and GDPR.
📋Standards & Privacy
Privacy Act, APPs, NDB Scheme, GDPR where applicable, and clear workforce-data boundaries.
🌏Data Residency
Singapore (Render) for global default; AWS Sydney when Australian sovereignty is required.
⚙️Infrastructure
Containers, CI/CD, regional hosting options, and secure update practices.
The Quick Picture
- Data
- Workforce data only — no patient data, no payment data. Technically enforced.
- Encryption
- AES-256 at rest · TLS 1.2+ in transit · AWS KMS (Sydney)
- Auth
- SSO · Entra ID · Google · OIDC · MFA · RBAC
- Regions
- Singapore (Render) and AWS Sydney — both live. Choose your region.
- Standards
- Privacy Act · APPs · NDB · GDPR (where applicable)
- Certifications
- Render: SOC 2 Type II, ISO 27001. AWS Sydney: SOC 2, ISO 27001, IRAP-assessed.
What We Stand Behind
Transparency
We state where data lives, what we process, and which certifications we — and our providers — hold.
Standards respected
We build and operate with Australian and, where relevant, international privacy expectations in mind. We do not overclaim certifications.
Innovation With Guardrails
We ship quickly on modern infrastructure without compromising security controls or compliance obligations.
Choice
Global default (Singapore, Render) and Australian hosting (AWS Sydney) so you can match your policy and risk appetite.
Running a security assessment?
We can provide additional technical documentation as part of a formal procurement review.
Contact usSee how an ED-first roster platform works.
From emergency departments to whole health services — and the ED-like teams beyond them.