Security & trust

Compliance you can read in one breath.

We design Sahajilo for the auditor, the support worker, and the participant — in that order of paranoia. Here's the honest, plain-English version of how we treat your data.

Data residency

All data, backups and logs live in AWS ap-southeast-2 (Sydney). Nothing leaves Australia, ever.

Tenant isolation

Every query is tenant-scoped at the ORM boundary. There is no UI-only filter that an attacker could strip.

Encryption

TLS 1.3 in transit, AES-256 at rest, per-tenant secret keys for sensitive fields like medication notes.

Access control

Role-aware screens, action-level permissions, session-per-subdomain, and rate limiting on auth.

Audit log

Every create, update and delete is recorded with actor, timestamp and the prior value. Diffable. Exportable.

Backups

Continuous WAL backups. 35-day point-in-time restore on Professional. Quarterly DR drill.

Privacy

No tracking pixels in the app. No analytics on participant data. No third-party scripts on tenant subdomains.

Subprocessors

Listed in plain English below. We notify customers in plain English at least 30 days before any change.

Data residency

Sydney, full stop. No exceptions.

Australian providers carry obligations to participants that don't survive a hop to a US data centre. Sahajilo runs entirely inside AWS ap-southeast-2 — primary, replica and backups.

ap-southeast-2 · Sydney
Where each thing lives
ApplicationAWS Sydney · multi-AZ
Primary databaseAWS Sydney · ap-southeast-2a
Read replicaAWS Sydney · ap-southeast-2b
Document storageAWS Sydney · S3 IA
BackupsAWS Sydney · cross-AZ, 35d
WAL streamAWS Sydney · 7d retention
Logs (scrubbed)Sydney · 30d hot · 365d cold
Email deliveryResend AU egress
NDIS Practice Standards

Aligned to the standards your audit will quote.

Sahajilo's data model and audit trail map directly to the Core and Supplementary modules of the NDIS Practice Standards (2026). Below is how each module shows up in the product.

Rights & Responsibilities

Per-participant communication preferences, consent capture, complaints intake via Helpdesk.

Provider Governance

Role-aware permissions, audit log per resource, change history across agreements and plans.

Provision of Supports

Service agreements with versioning, plans → goals → progress notes traceable end-to-end.

Provision of Supports Environment

House records (intake), risk assessments, incident capture, follow-up tasks.

High Intensity Daily Personal Activities

Medication regimens with two-staff witness, missed-dose escalation, regimen change history.

Implementing Behaviour Support Plans

Behaviour records on the participant, restrictive practice flags, regulated-restrictive-practice tracking (roadmap Q3).

Subprocessors

Four names, none of them surprising.

The third parties that touch your data, and what they touch. We notify customers at least 30 days before any change.

VendorPurposeRegion
AWS (ap-southeast-2)Hosting, storage, backups, email sendSydney, AU
CloudflareDNS for sahajilo.com and edge TLSAU edge
ResendTransactional email delivery (admin alerts only)AU/US
Sentry (self-hosted)Error monitoring — scrubbed of PIISydney, AU
Security FAQ

The rest of the honest answers.

Are you NDIS Commission registered software?
Sahajilo is the platform you operate; registration sits with your organisation. Our data model and audit trail are aligned to the NDIS Practice Standards and Code of Conduct, and we will walk an auditor through the system on your behalf during your audit cycle.
Where is my data?
Sydney. AWS ap-southeast-2. Backups, WAL streams and logs all stay in Australia. Nothing replicates to overseas regions, regardless of plan tier.
What happens if you go away?
You own your data. A one-click export gives you every record as portable CSV plus document attachments. We commit to a 90-day data return window in our terms.
Do you train AI on customer data?
No. We do not use customer data — including participant records, notes, agreements or medication logs — to train any model, ours or anyone else's.
How do I report a security issue?
Email security@sahajilo.com with details. We acknowledge within one business day and aim to triage within three. We do not currently offer a paid bounty programme.
Trust

Want a deeper security walkthrough?

We're happy to share our written security posture, run an architecture call with your CISO, or fill out a custom DDQ. Email security@sahajilo.com.