DailyCore Security & Data Protection
Last Reviewed: September 2026 | Enterprise Security Whitepaper Summary
Security First Principle: Managing sensitive healthcare, medication, and participant care records demands uncompromising defense-in-depth security. DailyCore implements military-grade encryption, Australian sovereign data residency, and continuous automated vulnerability monitoring.
1. Australian Sovereign Hosting & Infrastructure
All primary databases, file attachments, and backups are hosted in geographically redundant, tier-III+ data centers located strictly within Australia (Sydney and Melbourne regions).
- Data Centers: ISO 27001, SOC 1, SOC 2 Type II, and PCI-DSS Level 1 certified facilities;
- Zero Overseas Data Shunting: Clinical notes, participant identifiers, and staff records never traverse international servers;
- High Availability: Multi-zone clustering provides 99.9% uptime with automated failover.
2. Cryptographic Standards
Data in Transit
All communications between web clients, mobile apps, and APIs are enforced via HTTPS using TLS 1.3 with high-strength cipher suites and strict HTTP Strict Transport Security (HSTS).
Data at Rest
All database volumes, file storage buckets, and automated backups are encrypted using AES-256 with rotating cryptographic keys managed via sovereign hardware security modules (HSMs).
3. Identity & Role-Based Access Control (RBAC)
DailyCore enforces the Principle of Least Privilege across all tiers:
- Granular Role Privileges: Distinct permission boundaries separate Administrators, Care Coordinators, Support Workers, and Family Portal users;
- Password Hygiene: Enforced complexity rules and bcrypt/Argon2 one-way hashing;
- Multi-Factor Authentication (MFA): Supported across all administrative and staff access points;
- Automated Session Expiry: Inactive sessions automatically expire to protect unattended clinical workstations.
4. Mobile & Field Device Safeguards
The DailyCore mobile application is engineered specifically for frontline support workers operating in dynamic community environments:
- Encrypted Local Storage: Offline cached rosters and notes are stored in hardware-backed encrypted storage;
- Purge on Logout: Signing out permanently flushes sensitive local caches from the handset;
- No Background Surveillance: Location telemetry is accessed exclusively at the discrete moments of shift Clock-In and Clock-Out, with no continuous GPS tracking.
5. Backups & Disaster Recovery
- Continuous Backups: Point-in-time recovery (PITR) with automated daily snapshot validation;
- Recovery Point Objective (RPO): Less than 15 minutes of transactional data;
- Recovery Time Objective (RTO): Less than 2 hours for total cluster rebuild;
- Annual DR Drills: Simulated failover drills conducted annually to verify business continuity protocols.
6. Responsible Vulnerability Disclosure
We welcome collaboration with cybersecurity professionals. If you identify a potential security vulnerability in our platform, please report it directly to:
DailyCore Security Operations Team
Email: security@dailycore.com.au
We commit to acknowledging reports within 24 business hours and providing regular remediation updates.