Security & compliance

The audit trail your regulator will trust — and the controls your CISO will sign off on.

Clinical competency data is among the most sensitive a provider holds. SkillComp protects it with end-to-end encryption, role-based access, immutable audit logs and Australian data residency — by default, on every plan.

Six pillars

How we protect competency data.

Encryption everywhere

TLS 1.3 in transit. AES-256 at rest for the database and all file uploads. Per-tenant encryption keys for sensitive evidence.

Role-based access

Admin, Educator, Assessor, Reviewer and Staff roles with strict read/write boundaries. Service accounts and audited API tokens.

Full audit trail

Every change to a competency, run, score or attachment is versioned. Exportable evidence trail for ACQSC visits and internal review.

Australian data residency

Production data is hosted in Australian regions. No clinical evidence leaves the country at rest or in backups.

Backups & recovery

Daily encrypted backups with 30-day retention. Documented RPO ≤ 24 hours, RTO ≤ 4 hours, tested quarterly.

Vulnerability handling

Coordinated disclosure at [email protected]. Critical issues triaged within one business day; SLA published in our incident policy.

What we align to

Australian frameworks, treated as floor — not ceiling.

SkillComp is built for the legal and regulatory environment Australian aged-care, nursing and NDIS providers actually operate in.
  • Privacy Act 1988 (Cth) & Australian Privacy Principles
  • ACQSC Strengthened Aged Care Quality Standards
  • AN-ACC funding evidence requirements
  • AHPRA scope-of-practice & NMBA standards
  • NDIS Quality and Safeguards Framework
Disclosure

Found a vulnerability? Tell us.

We follow coordinated disclosure. Email [email protected] with reproduction steps. We acknowledge within one business day.