Trust Center / Sub-Processors
Sub-Processors
TRAK uses the third parties below to deliver the platform. Material changes are notified to customers at least 30 days in advance by email to security@ironbarktech.com.au. Register last reviewed: 2026-06-25.
Pre-production status. TRAK is currently pre-production. No real participant data has yet been transmitted to any sub-processor. Entries marked Planned are not yet integrated and will be confirmed here when active. Entries marked Active are code-confirmed integrations with credentials configured in the environment.
AI Sub-Processors
Detailed AI and model governance is on the AI governance page.
| Provider | Status | Role | Data policy | Region |
|---|---|---|---|---|
| Anthropic | Planned | Claude LLM API (compliance auditor and support agent features, Phase 4+) | Zero-retention Trust Tier. No NDIS participant PII is transmitted without explicit consent, and customer data does not train models. | US control plane (AU-region model access via AWS Bedrock is the swap path) |
Infrastructure and Service Sub-Processors
| Provider | Status | Tier | Service | Data received | Region | Certifications |
|---|---|---|---|---|---|---|
| BinaryLane | Active | Critical | Production compute and managed Postgres (NDIS participant data, RLS-enforced) | NDIS participant personal information and provider operational data | Australia only (Australian-owned, NextDC S1 Sydney). Not subject to the US CLOUD Act. | ISO 27001-aligned, Australian-law-only |
| RackCorp | Active | Critical | Encrypted database backups and 7-year immutable (Object Lock WORM) audit retention | AES-256-encrypted database backups (no plaintext participant data) | Australia only (Australian-owned, IRAP-assessed, Sydney) | IRAP-assessed |
| Railway | Active | Standard | Development and verification environment only (no production participant data) | Synthetic test data only (no NDIS participant personal information) | Singapore (development only, synthetic test data) | SOC 2 Type II |
| Resend | Active | Standard | Transactional and lifecycle email delivery (family digests, staff notifications) | Recipient email addresses and notification content (minimal PII, no clinical detail) | US control plane | SOC 2 Type II |
| GoCardless | Active | Critical | BECS Direct Debit for NDIS plan-manager billing | Bank debit instruction tokens (no full account number stored locally) | AU local processing (UK control plane) | SOC 2 Type II, ISO 27001:2013 |
| Sentry | Active | Marginal | Error monitoring and operational telemetry (no participant data) | Internal operational and error telemetry only | US control plane | SOC 2 Type II |
| GitHub | Active | Critical | Source code and CI/CD (no participant data) | Source code (no NDIS participant data) | US control plane | SOC 2 Type II, ISO 27001:2013 |
| Stripe | Planned | Standard | Card payments for non-debit billing (deferred, not yet integrated) | Payment tokens (no card number stored locally) | US control plane (payment tokens only) | PCI DSS Level 1, SOC 2 Type II |
| Cloudflare | Planned | Critical | WAF, DDoS protection and DNS (deployment-time control, not yet active) | HTTP request metadata | Global edge (HTTP metadata only) | SOC 2 Type II, ISO 27001:2013 |