Trust & security

Where your data lives, and how we protect it

You are trusting CareHub with some of the most sensitive records in the country: participant health information, worker screening, incident reports. Here is the plain version of how we hold it, who can touch it, and the things we will never do with it. Real practices, not a trust badge.

Encrypted in transit & at rest Every change logged Your data stays yours

Built and supported in Australia

CareHub is designed here, for the NDIS specifically, and supported by an Australian team in Australian business hours. Not a global tool with a local reseller.

A care system, not a data broker

We make money one way: providers paying for software that runs their organisation. We do not sell data, rent audiences, or train AI on your participants. That is a line, not a setting.

No lock-in, your data is yours

Published pricing, cancel anytime, and full export of your records and audit log on the way out. Leaving is always your decision, and your data comes with you.

The practical security story

How your data is protected

No jargon, no acronym soup. The four things that actually keep your records safe, in plain terms.

Encrypted end to end

Every connection is protected with TLS in transit, and your database and uploaded files are encrypted at rest. Nothing travels or sits in the clear.

Your organisation is walled off

Every provider's data is isolated at the database layer with row-level security. One organisation can never see another's participants, staff or records. Ever.

Least-privilege access

Inside your organisation, roles decide who sees what: a support worker sees their participants, not everyone's. Our own staff have no routine access to your data.

Every change is logged

Who did what, and when, is written to an audit trail as it happens. The same log that keeps you audit-ready also means nothing in the system is untraceable.

Data residency

Your data is hosted in Australia

Participant and provider records are stored in the Sydney region of our cloud infrastructure. That keeps sensitive NDIS data onshore, under Australian privacy law, and away from the offshore-hosting questions auditors and families increasingly ask.

  • Sydney region hosting: your database and files sit in Australia, not overseas
  • Australian privacy law applies: handled to the standard expected of health information, regardless of our size
  • Breach notification built in: aligned to the Notifiable Data Breaches scheme, with a committed notification window
  • Support stays local: the people who can help are in the same time zone as you
hellocarehub.com.au/trust
Data residencySydney, AU
DatabaseEncrypted at rest · Sydney region
Onshore
Uploaded documents & filesEncrypted object storage · Sydney region
Onshore
BackupsEncrypted · retained to policy
Onshore
In transitTLS on every connection
Encrypted
Full transparency

The companies that help us run CareHub

We do not pretend to build every layer ourselves. Here is exactly who touches your data on our behalf, what they do, and where it sits. We give notice before this list changes.

Provider What they do Data region
Supabase Database, authentication & file storage Sydney, AU
Vercel Application hosting & content delivery Global edge
Google Transactional email (Workspace SMTP) & push notifications (Firebase) US / global
Anthropic AI features (summaries & assistance); does not train on your data US

Your records are stored in Australia. A small amount of data is sent to the processors above only to deliver a specific function you have asked for, such as an email, a push notification or an AI summary, and never for advertising. We give notice before this list changes.

Where the lines are

What we will never do

Most trust pages only tell you what a company does. Here is what we refuse to do, so you can hold us to it.

Sell your data. Ever.

Not to advertisers, not to data brokers, not to anyone. It is not part of how CareHub makes money.

Train AI on your participants

Your participant and care records are never used to train models. CareHub's AI features work on your data only to help you, inside your organisation.

Hold your data hostage

No exit fees, no locked exports, no "contact sales to leave". Your records and audit log export cleanly, whenever you ask.

Hide behind a trust badge

We would rather show you the real practices on this page than flash a logo. If something here changes, we will say so.

Questions about security or privacy?

Talk to our team directly. We are happy to walk your board, your auditor or your privacy officer through exactly how CareHub handles your data.

Australian support · Data hosted onshore · No lock-in