Security and data privacy.
Every record in Rostrel is about a real person — a participant, their supports, or the worker who delivers them. That's why security isn't a checklist we did once; it's built into how the product handles data, every day.
Here's specifically what that means, in plain terms — not marketing claims.
How your data is protected
Data residency — Sydney, Australia
Your primary records live in a database hosted in Sydney, on Supabase infrastructure. Application hosting and content delivery run on Vercel's global network. We don't offshore your core participant and worker records to reduce cost.
Encryption in transit and at rest
All data moves over TLS and is encrypted at rest. Tax file numbers and bank account details get an additional layer of application-level encryption on top — they're never displayed anywhere they aren't needed, and never used or disclosed for anything beyond payroll.
Role-based access, enforced in the database
A support worker sees only their own shifts and notes. A coordinator or administrator sees only what their role requires. These rules are enforced with row-level security in the database itself — not just hidden in the interface — so a bug in a screen can't accidentally expose a record it shouldn't.
Tenant isolation
Each provider's data is fully segregated from every other provider's — participants, workers, rosters, claims, the lot. There is no shared view across organisations, by design.
Audit trails
Key records carry a deletion-protected audit log of roster and record changes — who changed what, and when. That matters for your own NDIS Commission audit evidence, not just for us.
AI features never train on your data
Some Rostrel features use AI to help coordinators — summarising or checking roster and billing data. Inputs are processed by our AI provider (Anthropic) solely to generate that response, in the moment, and are never used to train their models.
Who else touches the data — and why
Like almost all modern software, Rostrel uses a small number of specialist providers to run parts of the service. Each processes data only for a specific purpose, and only where you actively use that feature:
- —Supabase — primary database and file storage (Sydney, Australia)
- —Vercel — application hosting and content delivery
- —Xero — payroll and invoicing, only if you connect your own Xero organisation
- —Anthropic — AI features; inputs are not used to train models
- —Sentry — error monitoring, with NDIS numbers, tax file numbers and phone numbers scrubbed before any report leaves the platform
Full detail, including the remaining processors and how each is used, is in our Privacy Policy.
If something goes wrong
We follow the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth): contain and assess any incident, notify the affected provider promptly, and where a breach is likely to cause serious harm, notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as the scheme requires. We never sell personal information, and we never use participant or worker records for advertising.
Frequently asked questions
Where is Rostrel data stored?
Primary records are stored in Sydney, Australia, on Supabase. Application hosting runs on Vercel. A small number of specialist providers process limited data only where you use that specific feature.
Is participant and worker data encrypted?
Yes — TLS in transit, encrypted at rest, with an extra layer of application-level encryption on tax file numbers and bank details specifically.
Can one provider see another provider's data?
No — every account is tenant-isolated, enforced in the database itself, not just the interface.
Does Rostrel train AI models on participant data?
No — AI feature inputs are used only to generate that response and are never used to train models.
Questions about how we handle your data?
Read the full Privacy Policy, or book a demo and ask us directly.
Book a 20-minute demo