Built for the trust NDIS providers need
Participant information is sensitive. ProvideWise is designed from the ground up to protect it — with Australian-hosted data, strong encryption, role-based access, audit trails and privacy-first AI processing.
This page is maintained by the ProvideWise team to help NDIS providers evaluate our platform. It describes the controls currently enabled in ProvideWise — it is not an independent certification. Providers remain responsible for their own obligations under the NDIS Practice Standards and the Privacy Act 1988 (Cth).
Security pillars
A layered approach to protecting participant data
Every layer of ProvideWise — hosting, database, application, access, and AI — is designed with the sensitivity of NDIS participant information in mind.
Australian-hosted
Participant data is stored in Australian cloud regions, with backups replicated in-country.
Encrypted end to end
TLS 1.2+ in transit and AES-256 at rest for databases, documents and backups.
Secure sign-in
Password + Google SSO, breached-password detection and short-lived session tokens.
Role-based access
Row-level security in the database — users only see the participants their role permits.
Auditable activity
Authentication and record changes are logged, so you can see who did what and when.
Backups & recovery
Automated daily backups and point-in-time recovery so participant data isn't lost.
Privacy-first AI
AI only runs when you ask, is not used to train models, and always leaves a human in the loop.
Aligned with Australian privacy
Designed to support the Privacy Act, APPs and NDIS record-keeping expectations.
Shared responsibility
We secure the platform; you manage users, roles and lawful use — together end to end.
Last updated: 29 July 2026
Australian data hosting
Participant data stored in ProvideWise is hosted in Australian data centres operated by our cloud infrastructure provider. Data does not need to leave Australia for the ProvideWise application to work.
- Databases and file storage located in Australian regions.
- Backups replicated within Australia for resilience.
- We disclose any overseas subprocessors used for a specific feature (for example, an AI model provider) in our Privacy Policy.
Encryption in transit and at rest
All traffic between your browser and ProvideWise is encrypted using TLS 1.2 or higher. Data stored in our database and file storage is encrypted at rest using industry-standard AES-256 encryption managed by our underlying cloud provider.
- HTTPS enforced across the entire application.
- HSTS enabled to prevent downgrade attacks.
- Encrypted database storage and encrypted document storage buckets.
- Secrets, API keys and credentials stored in an encrypted vault — never in application code.
Secure authentication
Access to ProvideWise requires authenticated user accounts. We provide multiple sign-in options and enforce password-safety controls appropriate to a system holding sensitive participant information.
- Email + password sign-in with strong password rules.
- Optional Google single sign-on for organisations that prefer federated identity.
- Compromised-password detection against known-breached password lists at sign-up and password change.
- Session tokens are short-lived, rotated automatically and stored securely in the browser.
- Support for SAML SSO can be enabled for enterprise customers on request.
Role-based access control
ProvideWise enforces access controls at the database layer using row-level security. A user only sees the participants and records their role and organisation permit — every request is checked, not just filtered in the UI.
- Row-level security policies applied to every table holding participant, note, task, funding or document data.
- Roles are stored in a dedicated table and evaluated by a security-definer function to prevent privilege escalation.
- Least-privilege by default: new users see nothing until they are explicitly granted access.
- Administrative actions require an administrator role and are logged.
Audit logs
Sensitive events in ProvideWise are logged so that organisations can review who did what, and when. Logs are retained for a period appropriate to NDIS record-keeping expectations and are protected from tampering by our database controls.
- Authentication events (sign-in, sign-out, password change) captured by the identity layer.
- Changes to participant records, notes, tasks and documents recorded with the acting user and timestamp.
- AI-generated case notes are marked as AI-drafted and require human review before they become part of the participant record.
Backups and business continuity
ProvideWise data is backed up regularly so that a serious incident does not mean lost participant information. Our underlying cloud infrastructure provides continuous point-in-time recovery for the database and versioned storage for uploaded documents.
- Automated daily backups of the production database.
- Point-in-time recovery available for a rolling recovery window.
- Backups stored within Australia and encrypted at rest.
- Infrastructure runs across multiple availability zones for resilience against isolated failures.
Privacy-first AI processing
ProvideWise uses AI to turn rough notes into professional case notes and to surface follow-up actions. AI is a tool to save time — the coordinator remains the author and decision-maker for every participant record.
- AI processing is triggered only when a user explicitly asks ProvideWise to generate a note or detect actions.
- Prompts sent to the AI provider are limited to the content required for that task.
- Our AI provider is contracted not to use ProvideWise prompts or responses to train their models.
- AI-generated content is clearly marked and always reviewable and editable by the user before it is saved.
- We recommend organisations avoid pasting information that is not required for the case note into the AI input.
Alignment with Australian privacy requirements
ProvideWise is built for Australian NDIS providers and is designed to help you meet your obligations under the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and the record-keeping expectations of the NDIS Practice Standards. Our Privacy Policy sets out how personal information is collected, used, stored and disclosed.
- Collection is limited to information reasonably necessary for support coordination.
- Participants and their nominated representatives can request access to, or correction of, their personal information through your organisation.
- A privacy contact is available at privacy@providewise.com.au.
- We work with providers to complete privacy impact assessments and data processing agreements where required.
ProvideWise supports your compliance program but does not replace independent legal advice. Providers remain the data controllers for the participant information they hold in ProvideWise.
Reporting a security concern
If you believe you have found a security issue in ProvideWise, we want to hear about it. Please email security@providewise.com.au with details of the issue and steps to reproduce it. We will acknowledge your report and keep you informed as we investigate.
Please do not test against real participant data or perform denial-of-service testing.
Need more detail for your security review?
We're happy to walk your team through our controls or provide documentation for your procurement process.