Trust Center / Sub-Processors

Sub-Processors

TRAK uses the third parties below to deliver the platform. Material changes are notified to customers at least 30 days in advance by email to security@ironbarktech.com.au. Register last reviewed: 2026-06-25.

Pre-production status. TRAK is currently pre-production. No real participant data has yet been transmitted to any sub-processor. Entries marked Planned are not yet integrated and will be confirmed here when active. Entries marked Active are code-confirmed integrations with credentials configured in the environment.

AI Sub-Processors

Detailed AI and model governance is on the AI governance page.

ProviderStatusRoleData policyRegion
AnthropicPlannedClaude LLM API (compliance auditor and support agent features, Phase 4+)Zero-retention Trust Tier. No NDIS participant PII is transmitted without explicit consent, and customer data does not train models.US control plane (AU-region model access via AWS Bedrock is the swap path)

Infrastructure and Service Sub-Processors

ProviderStatusTierServiceData receivedRegionCertifications
BinaryLaneActiveCriticalProduction compute and managed Postgres (NDIS participant data, RLS-enforced)NDIS participant personal information and provider operational dataAustralia only (Australian-owned, NextDC S1 Sydney). Not subject to the US CLOUD Act.ISO 27001-aligned, Australian-law-only
RackCorpActiveCriticalEncrypted database backups and 7-year immutable (Object Lock WORM) audit retentionAES-256-encrypted database backups (no plaintext participant data)Australia only (Australian-owned, IRAP-assessed, Sydney)IRAP-assessed
RailwayActiveStandardDevelopment and verification environment only (no production participant data)Synthetic test data only (no NDIS participant personal information)Singapore (development only, synthetic test data)SOC 2 Type II
ResendActiveStandardTransactional and lifecycle email delivery (family digests, staff notifications)Recipient email addresses and notification content (minimal PII, no clinical detail)US control planeSOC 2 Type II
GoCardlessActiveCriticalBECS Direct Debit for NDIS plan-manager billingBank debit instruction tokens (no full account number stored locally)AU local processing (UK control plane)SOC 2 Type II, ISO 27001:2013
SentryActiveMarginalError monitoring and operational telemetry (no participant data)Internal operational and error telemetry onlyUS control planeSOC 2 Type II
GitHubActiveCriticalSource code and CI/CD (no participant data)Source code (no NDIS participant data)US control planeSOC 2 Type II, ISO 27001:2013
StripePlannedStandardCard payments for non-debit billing (deferred, not yet integrated)Payment tokens (no card number stored locally)US control plane (payment tokens only)PCI DSS Level 1, SOC 2 Type II
CloudflarePlannedCriticalWAF, DDoS protection and DNS (deployment-time control, not yet active)HTTP request metadataGlobal edge (HTTP metadata only)SOC 2 Type II, ISO 27001:2013