Trust & Security

Your Data, Protected

Organisation permissions, encrypted storage, customer-approved support and verified recovery help protect sensitive NDIS records. Understand the controls and their limits before choosing how to use the platform.

Managed Infrastructure
Encrypted Storage
Approved Support Access
Application Audit Log

Data Protection & Infrastructure

Sensitive data is protected with managed cloud infrastructure, encrypted backups, and access controls designed for Australian providers.

  • Managed cloud infrastructure with regional deployment controls
  • Encrypted backups and recovery procedures
  • Privacy controls designed to support Australian providers
  • Customer workspace access and infrastructure administration have different controls

Encryption

Encrypted application connections, managed storage and encrypted recovery archives protect information in transit and at rest.

  • HTTPS connections to the application
  • Managed database and file-storage encryption
  • Encrypted database backups
  • Secure file storage with encryption

Role-Based Access Control

Granular permissions ensure team members only access what they need. Seven built-in roles with organisation-unit scoping.

  • Owner, Admin, Manager, Finance, Coordinator, Therapist, and Viewer roles
  • Participant-level access restrictions
  • Organisation-scoped data isolation
  • Invitation-only team onboarding

Audit Trail

Recorded changes and approved in-app support requests identify the actor and time. The organisation audit log can be filtered and exported; it is not a complete log of every ordinary record read or infrastructure access.

  • Recorded application changes and approved support-session activity
  • User and timestamp recorded on every entry
  • Relevant before-and-after values where supported
  • CSV export of the audit trail

NDIS Compliance

Built to align with NDIS Practice Standards and Quality and Safeguards Commission requirements.

  • Case note compliance tracking
  • Incident, risk, and feedback registers
  • Worker screening tracking
  • Evidence collection for audits

Customer-Approved Support Access

An organisation owner or administrator confirms a named support person using a code sent to their account email. The session uses the approving person’s role, expires automatically and can be revoked.

  • Read-only access by default, with explicit approval required for changes
  • Time-limited approval for one named support person
  • Organisation owners and administrators notified on confirmation and first access
  • Support requests and denied changes recorded in the organisation audit log
  • Privileged hosting, database and backup access remains a separate boundary

Data Retention & Deletion

Retention and deletion depend on the record type and applicable requirements. Removing a participant from normal access does not immediately erase related evidence or backups.

  • Participant removal and permanent erasure are separate operations
  • Deletion requests require authority and a review of retained evidence
  • CSV export available before account closure
  • Participant anonymisation for right-to-erasure requests

Release Verification and Recovery

Production changes use checks tied to the release revision, migration rehearsal and encrypted recovery snapshots. These technical checks do not establish ISO certification or a SOC 2 audit opinion.

  • Application and database checks before deployment
  • Migration rehearsal before production schema changes
  • Fresh encrypted database and storage recovery snapshots
  • Deployed version and health verification

CordoCare security FAQs

Clear answers about access, audit trails and data protection.

How does CordoCare protect NDIS and allied health records?

CordoCare uses encrypted connections and storage, managed cloud infrastructure, encrypted backups, role-based access controls and audit trails to protect sensitive practice records.

Can staff see every client or participant?

No. Access can be limited by organisation, role, team, organisation unit and assigned client or participant so staff only see records needed for their work.

Does CordoCare record changes to important data?

Yes. CordoCare keeps an audit trail for important record activity, including the user, timestamp and relevant before-and-after values where supported.

Does AI or MCP access bypass CordoCare permissions?

No. AI and MCP requests are checked against current organisation, role, team and client or participant permissions. Connected agents do not receive unrestricted access.

Is CordoCare ISO 27001 certified?

CordoCare does not claim current ISO 27001 certification. Its application checks, access controls and backup verification are technical measures, not independent certification. Contact us for current assurance evidence.

Can an organisation export its CordoCare records?

Yes. CordoCare provides controlled exports for relevant records and workflows, helping organisations retain portable evidence before migration or account closure.

Have security questions?

We're happy to discuss our security practices in detail. Reach out to our team for a security review or to request our security documentation.