Security & data handling
How we store, protect and share data. Last updated July 2026.
Australian data residency
ORCAA's application databases and backend services are hosted in Sydney, Australia. Our public website is served from Australian and global edge infrastructure, with all application data stored onshore. We do not transfer personal information overseas in the ordinary course of operating the Service.
What we hold
Provider listings are compiled from public Australian Government registers (NDIS Provider Register, Aged Care Quality and Safety Commission, ACECQA and others) and describe organisations and registered practitioners in their professional capacity. Providers can claim, correct and enrich their own listing.
Verification data — professional registration numbers, ABNs and screening evidence — is collected from providers to perform identity and registration checks. We display the outcome, not the underlying evidence.
Family enquiries — name, contact details and the message a family chooses to send — are stored and shared only with the specific provider the family selected.
Payments are processed by Stripe. Card details are tokenised in the browser and never touch ORCAA's servers; we store only a payment token and display metadata (brand, last four digits).
How access is controlled
Every API endpoint requires authenticated machine-to-machine credentials; there is no anonymous write access. Credentials are scoped per application, stored as managed secrets, and rotated. Administrative access to production infrastructure is limited to named individuals with multi-factor authentication.
All data-changing operations are recorded in an append-only audit log — who acted, what changed, and when. Public-facing endpoints are rate-limited to prevent scraping and abuse.
Encryption, backups and availability
Data is encrypted in transit (TLS) and at rest. Databases are backed up automatically on managed infrastructure, and restoration procedures are part of our operational runbook. Security headers (HSTS, content-type protections, frame protections) are enforced across the public site.
Frameworks and law
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles — see our Privacy Policy. Our security program is guided by the principles of ISO 27001 and the Australian Government's IRAP/ISM guidance. We are a young company and do not yet hold formal certification; we say so plainly, and we build as if the audit were tomorrow.
If something goes wrong
We operate a notifiable data breach process consistent with the OAIC's scheme: contain, assess, notify affected individuals and the OAIC where required, and remediate. Security concerns or suspected incidents can be reported to hello@orcaa.app — reports are acknowledged within one business day.
Questions
Partners and assessors can request further detail on our architecture and controls at hello@orcaa.app.