Trust Center / Compliance Roadmap

Compliance Roadmap

TRAK does not claim certifications it does not hold. Every item below is labelled with its honest status: in place today, committed on a specific trigger, or planned but not yet started.

Register last reviewed: 2026-06-25. Questions: security@ironbarktech.com.au

How to read this page

  • ActiveIn place today
  • On first enterprise customerCommitment: initiated on the first enterprise NDIS provider customer
  • PlannedOn the roadmap. Not yet started or held.

Active today

  • WCAG 2.2 AA conformanceActive
  • Privacy Act 1988 + Australian Privacy PrinciplesActive
  • Notifiable Data Breaches schemeActive
  • NDIS Practice Standards alignment (5-module mapping)Active
  • ACSC Essential Eight: self-assessment (pre-launch)Active

These frameworks and obligations are operational. TRAK already meets these requirements through normal platform operation.

Committed on trigger

  • SOC 2 Type I (triggered on first enterprise NDIS customer)On first enterprise customer

These certifications are not yet held. TRAK commits to initiating the process on the trigger event described (for example, first enterprise NDIS provider customer). SOC 2 Type I requires approximately 4 to 6 weeks to complete once initiated.

Planned

  • SOC 2 Type II (12-month observation post Type I trigger)Planned
  • ISO 27001:2022 (Gate 2 trigger)Planned
  • ISO 27701 (first plan-manager onboarded)Planned
  • ISO 42001 AIMS: first NDIS AI certification target (post ISO 27001)Planned

These certifications are on the roadmap. None are currently held and none are being actively pursued yet. Each is sequenced to begin after an earlier certification or business milestone.

Note on certification lead times: SOC 2 Type II requires a 12-month observation period following the Type I trigger. ISO 27001:2022 typically takes 6 to 12 months from initiation to first certificate. ISO 42001 (AI management system) can run in parallel once ISO 27001 is in place (approximately 4 to 6 months additional). These lead times are included here so buyers can plan accordingly and are not surprised by the calendar.

Why TRAK does not hold certifications pre-launch

SOC 2 Type II (the certification enterprise buyers care most about) requires a 12-month observation period. Starting it before any customer data is live means paying for a 12-month window of observation on an empty system, then repeating the exercise once production data flows. TRAK instead funds the controls and architecture now, defers the auditor fees until the trigger, and starts the observation period on real production load. The result is a Type II report that reflects actual production security rather than a demo environment.

If your procurement requires SOC 2 Type II before contract signature, contact security@ironbarktech.com.au to discuss your timeline. We can share the control evidence library and infrastructure posture under NDA.