Security & data protection

KAINDIS handles sensitive participant information, so security and data residency are built in — not bolted on. Here is how your data is hosted, protected and kept under your control.

Australian data residency

All customer and participant data is hosted in Australia — AWS Sydney (ap-southeast-2). Your data does not leave the country in the ordinary course of running the platform.

Encryption in transit and at rest

Data is encrypted in transit with TLS, and at rest with AES-256. Traffic to the platform is served over HTTPS with HSTS.

Access control and audit logging

Role-based access controls scope what each user can see and do, multi-factor authentication is available (and enforceable) for administrators, and privileged actions are recorded in an audit log.

Privacy Act and NDIS alignment

The platform is built to support your obligations under the Australian Privacy Act 1988 and the Australian Privacy Principles, and to keep the kinds of records the NDIS Practice Standards expect.

Your data, and no lock-in

Your data stays yours. You can export it at any time, there is no lock-in contract, and account and data deletion is available on request.

Backups and resilience

The production database is backed up with point-in-time recovery on a rolling retention window, so data can be restored after an operational incident.

Sub-processors

We use a small set of vetted third-party providers to run the service. The current list, and what each one processes, is published and kept up to date.

View our sub-processors →

Responsible disclosure

Found a security issue? We want to hear about it. Email security@kai-auto.com and we'll respond quickly. Our security.txt has the details.

Questions about security or compliance?

We're a small Australian team and happy to talk through your requirements before you commit.

Contact us
Security | KAINDIS