Security and data protection
Security and data protection for aged care.
Review how Statura handles personal information, health records, incident reports and protected disclosures. Bring your IT and governance team into the discussion about hosting, access and data responsibilities.
Security architecture
Controls across the platform.
Infrastructure, database and application controls work together. The details below explain the protections relevant to your technical review.
Australian infrastructure
Core production application hosting is configured in Sydney, Australia. Certain limited support, telemetry, communications, and billing workflows may involve approved subprocessors outside Australia, as disclosed in our privacy policy and subprocessor schedule.
Encryption in transit and at rest
Production hosting and database services provide encryption in transit and at rest. Include encryption requirements, connection settings and key-management responsibilities in your technical review.
Row-level security
Tenant-scoped row-level security (RLS) on application data is designed to prevent cross-tenant access. Each organisation's data is scoped to that organisation and enforced at the database layer as defence in depth alongside the application's own tenant filtering.
Role-based access control
Role-based permissions distinguish care, clinical, workforce, finance and governance responsibilities. During setup, review the permissions for your named roles and verify representative workflows before granting access.
Audit records
Audit records capture the actor, action, affected record and available change details for instrumented workflows. Review coverage, access and retention for the processes your organisation needs to evidence.
Authentication and device controls
Statura Care supports role-appropriate authentication controls, including email/password and organisational single sign-on where configured, with device-level PIN and biometric protection in the mobile app.
Privacy and data handling
How sensitive information is handled.
Personal information, health records and protected disclosures require clear access boundaries and handling responsibilities.
Whistleblower confidentiality
Whistleblower reports use designated-recipient access rather than general staff access. If no active recipient is configured, limited administrator access applies to reports accepted through default routing. Confirm recipients and fallback handling during setup.
Data isolation
Multi-tenancy is implemented with organisation-scoped data isolation. Each provider's data is logically separated at the database level. Tenant-scoped RLS on application data is designed to prevent cross-tenant access.
Privacy responsibilities
Statura Care is designed to support your obligations under the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs). The platform handles personal information, sensitive information, and health information with appropriate access controls and audit trails.
Document security
Documents are associated with organisation records and subject to access rules for the relevant workflow. Include document visibility, downloads and any external sharing in your permissions review.
Monitoring and follow-up
Monitoring and follow-up.
Monitoring, escalation and notifications support the people responsible for reviewing operational events and taking action.
Scheduled compliance checks
Scheduled checks support screening expiry, assessment due dates, notification deadlines and alert escalation. Your team remains responsible for reviewing alerts and acting on outstanding work.
Alert escalation
Compliance workflows surface urgency and overdue work so responsible staff can prioritise follow-up. Confirm escalation responsibilities and the channels your team will monitor.
Notifications
Email and in-app notifications support operational follow-up. Confirm recipients, delivery monitoring and fallback procedures for time-critical communications.
Accessibility
Our accessibility target is WCAG 2.1 Level AA. Include keyboard use, assistive technology and the workflows your staff rely on in your evaluation.
Data your review should cover
- Care recipient and staff personal information
- Health records and clinical data
- Serious incident reports
- Whistleblower disclosures
- Financial records, including accommodation deposits
- Worker screening and police check results
Confirm access permissions, audit coverage and retention requirements for each part of your proposed scope.
Security questions, answered.
Where is Statura Care data hosted?
Core production application hosting is configured in Sydney, Australia. Some limited support, telemetry, communications, and billing workflows may involve approved subprocessors outside Australia. See our privacy policy and subprocessor schedule for current details.
How does Statura Care protect resident data?
The platform combines organisation-scoped access, role-based permissions, encryption and audit records. Your technical review should confirm how these controls apply to the workflows, documents and interfaces in your proposed scope.
How does Statura Care support our privacy responsibilities?
Statura Care is designed to support privacy obligations through access controls and data-handling workflows. Review our privacy policy, subprocessors and proposed service arrangements with your privacy and governance team.
How does whistleblower confidentiality work?
Access is scoped to designated recipients. Where no active recipient is configured, limited administrator fallback applies only to reports accepted under default routing. Confirm recipient setup and confidentiality arrangements before using the workflow.
What should we review before connecting clinical systems?
Confirm the interface scope, source of truth, review steps, handling of conflicting updates and exception ownership for each connection. Test representative records with your clinical and IT reviewers before enabling a production feed.
Can I get a detailed security review?
Yes. We welcome security enquiries from IT teams, governance boards, and procurement processes. Contact us for additional security documentation and detailed technical information.
Need additional documentation for a procurement review? Contact our team.
Bring the work you need to improve.
Show us where your team spends time today. We’ll walk through the relevant care, workforce or finance workflows and discuss what a move to Statura would involve.