Trust & Security

How we handle your data.

Plain-English answers about where Clearline stores NDIS data, who can access it, and what we've built so far.

01 · Where your data lives

Hosted in Australia, full stop.

Production data is stored on Supabase Postgres running on AWS infrastructure in the Sydney region (ap-southeast-2). Our API runs on Fly.io in their Sydney region (syd). Same city, same regulatory jurisdiction, sub-5ms latency between the two.

02 · Backups & recovery

Daily, automated, verified.

Supabase takes a physical (block-level) backup of the database every 24 hours, retained for a rolling 7-day window. We monitor backup status and confirm completion before claiming a successful day.

03 · Encryption & access

Encrypted at rest, encrypted in transit.

Every connection to Clearline uses TLS 1.2 or higher. Database storage is encrypted at rest. Application secrets — API keys, database credentials, signing keys — live in platform secret management, never in source code or committed config files.

04 · Consent & participant rights

The participant is the centre of their data.

Connect — our cross-product layer — routes every data flow through the participant's nominated consent owner. Families approve who joins their participant's care team. Either side can revoke at any time. Every cross-product access is logged for the consent owner to see.

Connect isn't a metaphor — it's a real software layer. Here's what sits between the four products and routes the consent flows described above.

Connect cross-product architecture Four Clearline products arranged in a compass-point ring around a central Connect identity node, on a subtle dot-grid background. Aura OS for provider operations sits at the top, Pilot for the coordinator workspace at the right, Compass for the family view at the bottom, and Scrive for OT report writing at the left. Each product is connected to Connect by a quiet line — Connect is the layer that carries participant identity, consent state, audit events, and cross-product handoffs between them. Every line is bidirectional: each product both writes to and reads from Connect. Aura OS PROVIDER OPERATIONS Pilot COORDINATOR WORKSPACE Compass FAMILY VIEW Scrive OT REPORT WRITER Connect
Four products. One identity. Connect is the layer that keeps them in sync.
05 · What we haven't done yet

The honest list.

Trust pages that only list strengths are marketing. This is the list of things we have not done. We surface it on the same page as the rest so a buyer's IT lead can make an informed call.

06 · Who's accountable

One person to email.

Security disclosures and data-handling questions go to a single mailbox monitored by the founder. No security@ alias, no triage tier, no support runaround. Faster for everyone.

Richard Patriquin · Founder, Clearline Health Pty Ltd

Contact · support@clearlinehealth.com.au Acknowledgement · within two business days ABN · 16 707 891 605 Based in Australia
07 · NDIS sector posture

Built for the NDIS, not adapted from generic SaaS.

Clearline is built specifically around NDIS workflows — PACE reports, Practice Standards, SIL operational compliance, support-coordinator funding justifications, family consent. We build Clearline to help providers meet their obligations under the NDIS Practice Standards and the NDIS Code of Conduct, and to give participants and families clear visibility over their own data. The Practice Standards apply to registered NDIS providers, not to software vendors — but the workflows we build are shaped around them. A dedicated NDIS compliance page is in development covering how the platform maps to specific Practice Standards and audit expectations.

Questions about how we handle data?

Email support@clearlinehealth.com.au. The founder reads every message. We aim to acknowledge within two business days.