How does CordoCare protect NDIS and allied health records?
CordoCare uses encrypted connections and storage, managed cloud infrastructure, encrypted backups, role-based access controls and audit trails to protect sensitive practice records.
Organisation permissions, encrypted storage, customer-approved support and verified recovery help protect sensitive NDIS records. Understand the controls and their limits before choosing how to use the platform.
Sensitive data is protected with managed cloud infrastructure, encrypted backups, and access controls designed for Australian providers.
Encrypted application connections, managed storage and encrypted recovery archives protect information in transit and at rest.
Granular permissions ensure team members only access what they need. Seven built-in roles with organisation-unit scoping.
Recorded changes and approved in-app support requests identify the actor and time. The organisation audit log can be filtered and exported; it is not a complete log of every ordinary record read or infrastructure access.
Built to align with NDIS Practice Standards and Quality and Safeguards Commission requirements.
An organisation owner or administrator confirms a named support person using a code sent to their account email. The session uses the approving person’s role, expires automatically and can be revoked.
Retention and deletion depend on the record type and applicable requirements. Removing a participant from normal access does not immediately erase related evidence or backups.
Production changes use checks tied to the release revision, migration rehearsal and encrypted recovery snapshots. These technical checks do not establish ISO certification or a SOC 2 audit opinion.
CordoCare security FAQs
CordoCare uses encrypted connections and storage, managed cloud infrastructure, encrypted backups, role-based access controls and audit trails to protect sensitive practice records.
No. Access can be limited by organisation, role, team, organisation unit and assigned client or participant so staff only see records needed for their work.
Yes. CordoCare keeps an audit trail for important record activity, including the user, timestamp and relevant before-and-after values where supported.
No. AI and MCP requests are checked against current organisation, role, team and client or participant permissions. Connected agents do not receive unrestricted access.
CordoCare does not claim current ISO 27001 certification. Its application checks, access controls and backup verification are technical measures, not independent certification. Contact us for current assurance evidence.
Yes. CordoCare provides controlled exports for relevant records and workflows, helping organisations retain portable evidence before migration or account closure.
We're happy to discuss our security practices in detail. Reach out to our team for a security review or to request our security documentation.