DailyCore Trust & Legal Center

Legal, Privacy & Compliance

Clear, transparent, and legally binding commitments safeguarding healthcare providers, participants, and support staff under Australian law.

NDIS & Privacy Act 1988 CompliantUpdated: September 2026

DailyCore Security & Data Protection

Last Reviewed: September 2026 | Enterprise Security Whitepaper Summary

Security First Principle: Managing sensitive healthcare, medication, and participant care records demands uncompromising defense-in-depth security. DailyCore implements military-grade encryption, Australian sovereign data residency, and continuous automated vulnerability monitoring.

1. Australian Sovereign Hosting & Infrastructure

All primary databases, file attachments, and backups are hosted in geographically redundant, tier-III+ data centers located strictly within Australia (Sydney and Melbourne regions).

  • Data Centers: ISO 27001, SOC 1, SOC 2 Type II, and PCI-DSS Level 1 certified facilities;
  • Zero Overseas Data Shunting: Clinical notes, participant identifiers, and staff records never traverse international servers;
  • High Availability: Multi-zone clustering provides 99.9% uptime with automated failover.

2. Cryptographic Standards

Data in Transit

All communications between web clients, mobile apps, and APIs are enforced via HTTPS using TLS 1.3 with high-strength cipher suites and strict HTTP Strict Transport Security (HSTS).

Data at Rest

All database volumes, file storage buckets, and automated backups are encrypted using AES-256 with rotating cryptographic keys managed via sovereign hardware security modules (HSMs).

3. Identity & Role-Based Access Control (RBAC)

DailyCore enforces the Principle of Least Privilege across all tiers:

  • Granular Role Privileges: Distinct permission boundaries separate Administrators, Care Coordinators, Support Workers, and Family Portal users;
  • Password Hygiene: Enforced complexity rules and bcrypt/Argon2 one-way hashing;
  • Multi-Factor Authentication (MFA): Supported across all administrative and staff access points;
  • Automated Session Expiry: Inactive sessions automatically expire to protect unattended clinical workstations.

4. Mobile & Field Device Safeguards

The DailyCore mobile application is engineered specifically for frontline support workers operating in dynamic community environments:

  • Encrypted Local Storage: Offline cached rosters and notes are stored in hardware-backed encrypted storage;
  • Purge on Logout: Signing out permanently flushes sensitive local caches from the handset;
  • No Background Surveillance: Location telemetry is accessed exclusively at the discrete moments of shift Clock-In and Clock-Out, with no continuous GPS tracking.

5. Backups & Disaster Recovery

  • Continuous Backups: Point-in-time recovery (PITR) with automated daily snapshot validation;
  • Recovery Point Objective (RPO): Less than 15 minutes of transactional data;
  • Recovery Time Objective (RTO): Less than 2 hours for total cluster rebuild;
  • Annual DR Drills: Simulated failover drills conducted annually to verify business continuity protocols.

6. Responsible Vulnerability Disclosure

We welcome collaboration with cybersecurity professionals. If you identify a potential security vulnerability in our platform, please report it directly to:

DailyCore Security Operations Team

Email: security@dailycore.com.au

We commit to acknowledging reports within 24 business hours and providing regular remediation updates.