(03) 9770 1000 Mon–Fri 9am–5pm AEST · support@guardiandesk.com.au
Security & Data Protection

Australian-hosted. Per-tenant isolated. Yours to export.

Guardian Desk is hosted in Australia, runs over HTTPS only, scopes every record to your company at the database level, and gives you per-worker permissions over who in your team sees what. You own your data.

How we design our controls

Practices drawn from recognised frameworks

We adhere to practices drawn from ISO/IEC 27001, ISO/IEC 27701, and Australia’s Essential Eight to protect personal and operational data. That means concrete controls — not a certification badge.

ISO/IEC 27001 practices

Information-security controls shaped around risk, access, encryption, logging, and secure operations — the same themes an ISMS expects, applied to how Guardian Desk is built and run.

ISO/IEC 27701 practices

Privacy-oriented controls for personal information: purpose limitation, tenant scoping, worker permissions, and handling under the Privacy Act 1988 and Australian Privacy Principles.

Essential Eight practices

Australian Signals Directorate guidance informs hardening priorities such as patching posture, privileged access discipline, backups, and multi-layered defence of the hosting environment.

We are not claiming ISO certification or Essential Eight accreditation. Providers remain responsible for their own NDIS Practice Standards obligations; Guardian Desk helps you evidence those standards with audit-ready records.

Where your data lives — and stays

Guardian Desk runs on Australian-hosted infrastructure. NDIS provider data, participant records, service notes, invoices, and documents are stored on servers physically located in Australia and operated under Australian law (Privacy Act 1988, Australian Privacy Principles, and Notifiable Data Breaches scheme).

HTTPS is enforced on every page request. Sensitive document storage sits behind the same per-tenant access controls as every other record.

Guardian Desk protected by TLS and AES-256 encryption — HTTPS address bar showing guardiandesk.com.au
TLS & AES-256 encryptionEvery session over HTTPS — guardiandesk.com.au
Controls that exist today

The security surface, plainly described

HTTPS-only access

Every page request is forced over HTTPS via a server-level redirect. HTTP requests are upgraded automatically; we don’t serve plain-text traffic.

Per-tenant data isolation

Every participant, worker, plan manager, service note, invoice, and document is scoped by company_id at the database level. There is no cross-tenant read path. Your data is yours.

Per-worker permissions (RBAC)

Workers are matched to login accounts by email. The owner is pinned with full access. Per-worker permission flags control what each invited worker can see and edit — participants, service notes, invoices, documents.

Hashed passwords & encrypted secrets

Account passwords are stored hashed — never as plain text. Sensitive integration secrets (for example API keys and SMTP credentials) are encrypted at rest where the platform supports it.

Logging & terms acceptance

Significant actions and security-relevant events are logged. Workers and owners pass a terms-acceptance gate on first login (and when terms change), recorded with version and timestamp.

Data ownership & export

Your data belongs to you. Documents are exportable as PDFs. Invoices and statements export as PDFs. We don’t sell or repurpose customer data for advertising, and we don’t use your records to train AI models. Optional AI writing tools only send text you explicitly submit when you press the AI button.

Your own SMTP

Outbound email (invoices, statements, follow-up reminders) goes through your own SMTP server — configured in settings. Email leaves your domain to your participants and plan managers, not a generic SaaS sender.

Frequently asked

Security questions

Where is my data stored?

In Australia. Guardian Desk runs on Australian-hosted infrastructure and your data does not leave Australian jurisdiction. We can provide our current hosting provider and region details to enterprise customers under NDA.

Is data encrypted in transit?

Yes. HTTPS is enforced on every request via a server-level redirect; plain-text HTTP traffic is not served. Browser-to-server traffic uses modern TLS as negotiated by your browser and our hosting platform.

Do you follow ISO 27001 or Essential Eight?

We adhere to practices drawn from ISO/IEC 27001, ISO/IEC 27701, and Australia’s Essential Eight to protect personal and operational data. We are not claiming certification or accreditation — the focus is concrete controls (TLS, tenant isolation, RBAC, hashed passwords, encrypted secrets, logging, Australian hosting) under the Privacy Act and APPs.

Can other Guardian Desk customers see my data?

No. Every record — participants, workers, plan managers, service notes, invoices, documents — is scoped to your company at the database level. There is no shared-database read path between tenants.

Who in my team can see what?

The owner of the tenant has full access. Workers are invited by email; each worker has permission flags controlling which sections they can access. The owner cannot be locked out, and permissions are managed from the Permissions page.

What happens to my data if I cancel?

You can export your documents, invoices, statements, and service reports as PDFs at any time. On cancellation, contact support and we will arrange a full data export of your tenant before deletion.

Do you train AI models on my data?

No. We do not use your participant, worker, service note, or invoice data to train AI models, and we do not bulk-export your records to AI providers.

When is my data sent to an AI service?

Only when you choose an optional AI writing feature and press the AI button (for example, rewording a support note or a quick-note phrase). That action sends the text in that field to our AI writing assist provider to generate a rewritten version. Nothing is sent automatically in the background.

By using the AI button you agree to that transfer for that request. See our Privacy Policy for sub-processor details.

How do I report a security issue?

Email security@guardiandesk.com.au or call (03) 9770 1000. We accept responsible-disclosure reports and will acknowledge within one business day.