Security + Compliance

NDIS provider software security controls for trusted, audit-ready operations.

Lamassu Care is built for provider teams that need strong security, clearer compliance visibility, and practical controls around billing workflows, documents, and day-to-day access.

The NDIS Practice Standards set principles-based information management obligations rather than naming specific algorithms. Where we say a control exceeds baseline, that is our implementation-based interpretation against the NDIS standards and OAIC privacy guidance.

For operations context, review our billing workflow guide and software vs spreadsheets comparison.

Security highlights

  • Your saved data is strongly locked

    We encrypt stored information so it is unreadable without the right key (AES-256-GCM).

  • Data is protected while moving online

    Connections are forced to secure HTTPS so information cannot be easily intercepted in transit (TLS 1.3 + HSTS).

  • Safer sign-in without relying on passwords

    Staff can sign in with passkeys like Face ID, fingerprint, or device PIN to reduce phishing and weak-password risk (WebAuthn).

  • Recoverability if something goes wrong

    We create encrypted backups every day to help restore data after incidents or mistakes.

Security controls

Controls mapped for compliance and audit readiness.

AES-256-GCM encryption at rest

Exceeds the principles-based baseline

Sensitive data including participant names, NDIS numbers, user contact and banking fields, and activity logs is encrypted using AES-GCM with 256-bit keys for confidentiality and integrity.

NDIS information management + OAIC encryption guidance

Password hashing

Exceeds the principles-based baseline

Passwords are stored with PBKDF2-SHA512 hashing rather than reversible storage, aligning with OAIC guidance that strong hashing is part of sound password protection.

OAIC password hashing guidance

TLS 1.3 enforced

All traffic is protected with TLS 1.3 and forward secrecy. HSTS is enabled to force HTTPS.

OAIC encryption guidance

Passkeys (WebAuthn)

Exceeds the common authentication baseline

Passwordless authentication is supported through passkey registration and assertion, reducing phishing risk and going beyond the baseline requirement for appropriate authentication controls around sensitive information access.

OAIC authentication and multi-factor guidance

Session hardening

Secure, HTTP-only, SameSite cookies are used with server-side session protection and short-lived auth tokens.

OAIC access security guidance

Rate limiting

Rate limiting on login and sensitive APIs reduces abuse, slows automated attacks, and helps protect platform availability.

OAIC risk-based security guidance

Implementation notes (for auditors)

These implementation details are available for technical review and procurement due diligence.

  • +AES-GCM is used for model fields storing personal and plan data, and Activity Log text/JSON is encrypted with GCM.
  • +Legacy Fernet-encrypted data is re-encrypted through managed rotation scripts.
  • +WebAuthn endpoints provide passkey registration and authentication flows.
  • +TLS 1.3 termination with HSTS is configured at the edge, and the app only serves HTTPS.

FAQ

Security questions teams usually ask first.

Short answers for provider leadership, procurement, and IT stakeholders reviewing Lamassu Care.

How does Lamassu Care protect participant and staff data?

Lamassu Care uses encryption at rest, TLS 1.3 in transit, secure session controls, and role-based access to reduce data exposure and support safer day-to-day use.

Does Lamassu Care support NDIS and NDIA compliance expectations?

Lamassu Care is designed for provider teams that need stronger workflow controls, audit visibility, document oversight, and security practices that align with NDIS and NDIA-focused operational expectations.

Can procurement or IT teams request more technical detail?

Yes. Lamassu Care can walk procurement, compliance, or IT stakeholders through implementation notes, security controls, and rollout considerations for provider teams.