Intelligent Roster

Security · Privacy · Compliance · Infrastructure

Trust Centre

Security, compliance, and infrastructure in one place — built for health service CTOs and security teams who need straight answers.

Last updated: February 2026 NEW — AWS Sydney option documented
One place for every hard question

Health services evaluate vendors on security, privacy, compliance, and where data lives. Scattered PDFs and vague claims don’t help. The Trust Centre is your single entry point to our security posture, compliance commitment, data residency options, and infrastructure — in plain language, with enough technical depth for CTOs and assessors.

At a Glance

The Quick Picture

Key facts for security and procurement reviews — with links to the full detail on each topic page.

Data
Workforce data only — no patient data, no payment data, no health records. Technically enforced
Encryption
AES-256 at rest TLS 1.2+ in transit AWS KMS (Sydney)
Auth
SSO Entra ID Google OIDC MFA RBAC
Regions
🌏 Singapore (Render) 🇦🇺 AWS Sydney — both live now. Choose your region →
Compliance
Privacy Act APPs NDB GDPR (where applicable)
Certifications
Render: SOC 2 Type II ISO 27001   AWS Sydney: SOC 2 Type II ISO 27001 IRAP-assessed
Our Commitments

What We Stand Behind

Four principles that guide every decision about how we build, operate, and document IRIS.

🔍

Transparency

We state where data lives, what we process, and which certifications we — and our providers — hold. No vague claims; specific providers, specific certifications.

📋

Compliance

We build and operate to Australian and, where relevant, international standards. We don’t overclaim certifications we don’t hold, and we’re explicit about what applies and what doesn’t.

Innovation With Guardrails

We ship quickly on modern infrastructure — containers, CI/CD, automated health checks — without compromising security controls or compliance obligations.

🗺️

Choice

We support both a global default (Singapore, Render) and Australian hosting (AWS Sydney) so you can match your organisation’s policy, procurement requirements, and risk appetite.

For Procurement & Security Reviews

Running a Questionnaire or Assessment?

We’re used to answering health-sector security assessments. Here’s where to find what you need — and we can provide additional documentation as part of a formal process.

Security Controls

Encryption, access control, audit logging, secure development practices, and provider certifications.

Security overview

Compliance Posture

Applicable frameworks (Privacy Act, APPs, NDB, GDPR), what’s in and out of scope, and why the boundary is clear.

Compliance commitment

Data Residency

Region options (Singapore vs AWS Sydney), certifications per region, and how to request Australian hosting.

Data residency

Infrastructure & Stack

Technology stack, providers, container architecture, deployment approach, and CI/CD pipeline details.

Infrastructure
💬 Need more? We can provide additional technical documentation as part of a formal procurement or security review process. Get in touch →
At a Glance

Why Health Services Choose IRIS

📂

One Place

Security, privacy, compliance, residency, and infrastructure — all here.

🎯

CTO-Friendly

Enough technical depth for serious evaluation — not a marketing brochure.

🇦🇺

Australian-Ready

Privacy Act, APPs, NDB, and optional AWS Sydney — all documented.

🚫

No Patient Data

Workforce only. Simpler scope, simpler compliance story for your review.

Ready to Go Deeper?

Let’s Have the Technical Conversation

Pick a topic above, or get in touch for a technical or compliance discussion. We’re used to health-sector procurement and happy to assist.