Skip to content

Security & Compliance

NoteGate™ is built for Australian health and disability services. Every technical and operational control is designed to support NDIS and Aged Care regulatory requirements.

Certification status: NoteGate's controls are mapped to ISO 27001:2022 Annex A. NoteGate is not certified. Essential Eight maturity is a self-assessed target (Maturity Level 2), not an independent assessment. Last reviewed 21 September 2026.

✓ Participant data stored only in AWS Sydney ASD Essential Eight: target Maturity Level 2, self-assessed ✓ Privacy Act 1988 (Cth) ✓ NDIS Act 2013 ISO 27001:2022 Annex A controls mapped (not certified)

Key security controls

Controls mapped to ISO 27001:2022 Annex A and ASD Essential Eight

Two-factor authentication

Two-factor authentication is available on all user accounts. At sign-in the account holder is emailed a one-time code, which is exchanged for a session token. A browser can be marked trusted for 30 days to skip the code; the password is still required at every sign-in, and trust is revoked automatically on any password change or reset. Email-delivered codes are not phishing-resistant and do not on their own satisfy ASD Essential Eight #7. Authenticator-app TOTP is planned, not yet shipped.

Active - A.9.4.2
🔒

Account lockout

Accounts lock for 15 minutes after 5 consecutive failed login attempts. Protects against credential stuffing and brute-force attacks.

Active - A.9.4.2
👤

Role-based access control

Six granular roles: Super Admin, Tenant Admin, Clinical Admin, Supervisor, Support Worker, Read Only. Workers are scoped to assigned participants only.

Active - A.9.1 / A.9.2
🗝️

Password security

Minimum 12 characters. Bcrypt hashing (cost factor 12). Session tokens invalidated immediately on password change. Secure reset via time-limited email token.

Active - A.9.4.3

Security audit log

Every authentication event, password change, MFA action, and access decision is logged with timestamp, IP address, and user agent.

Active - A.12.4
🌏

Australian data residency

All data stored only on AWS Sydney (ap-southeast-2). S3 bucket policy includes a region-deny condition preventing data from leaving Australia.

Active - A.11.2 / APP 8
🛡️

Encryption in transit

TLS 1.2+ enforced on all endpoints via AWS CloudFront. HTTP is not served. Internal API communication is TLS-secured. HSTS headers enforced.

Active - A.10.1 / A.13.1
💾

Encryption at rest

managed database encrypted with AES-256 (AWS KMS). S3 objects encrypted with SSE-S3. Application volumes encrypted at rest.

Active - A.10.1
🤖

AI de-identification (our de-identification service)

Participant identifiers are tokenised before transmission to any AI processing provider. Zero Data Retention agreement in place. Every AI call is logged.

Active - A.18.1.4 / APP 8
🏗️

Security headers

Helmet.js enforces Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and HSTS on all API responses.

Active - A.13.1 / A.14.2
⚡

Rate limiting

Authentication endpoints: 10 requests per 15 minutes per IP. All other endpoints: 100 requests per 15 minutes. Protects against automated attacks.

Active - A.9.4.2
🔍

Input validation

All API inputs validated with Zod schema enforcement. SQL injection prevented by parameterised queries. CORS restricted to notegate.com.au subdomains.

Active - A.14.2

ISO 27001:2022 Annex A - Technical controls mapping

ControlAnnex A refImplementationStatus
Access control policyA.5.15RBAC enforced at API middleware layer on every requestActive
Identity managementA.5.16UUID-based user identity, tenant-scoped, bcrypt(12) credentialsActive
Authentication informationA.5.1712-char min, bcrypt(12), forced reset on first login, self-service resetActive
Access rightsA.5.18Worker scope limited to assigned participants; role checks on every routeActive
Use of cryptographyA.5.10 / A.8.24AES-256 at rest (KMS), TLS 1.2+ in transit, bcrypt for passwordsActive
Secure authenticationA.8.5JWT tokens, account lockout (5 attempts / 15 min), MFA availableActive
Privileged accessA.8.2Super Admin role scoped to platform operations; tenant admins scoped to own orgActive
Event loggingA.8.15Winston structured JSON logs (CloudWatch). Security audit log table with all auth eventsActive
MonitoringA.8.16ECS health checks, CloudWatch metrics, structured error loggingActive
Web filtering / input validationA.8.23Zod schema validation, parameterised queries , CORS restrictionActive
Information transferA.5.14TLS enforced, HSTS, no sensitive data in URLs, presigned S3 for file accessActive
Protection of recordsA.5.33Soft-delete only (no hard deletes on clinical records), audit trail on all approvalsActive
Privacy & PII protectionA.5.34APPs compliance, de-identification before AI, data residency in AustraliaActive
Incident managementA.5.26SIRS-ready incident module, structured logging for investigation evidenceActive
BackupA.8.13Managed database automated daily backups, 7-day retention, point-in-time recoveryActive
Network securityA.8.20ECS tasks in VPC, RDS not publicly accessible, CloudFront WAF-readyActive
Secure developmentA.8.25 / A.8.28Zod validation, no raw SQL, ORM layer, dependency pinning, Docker buildActive
Two-factor authenticationA.8.5Optional email one-time code at sign-in, bound to a short-lived challenge token and to the action it was issued for, with a five-attempt limit. Trusted browsers stored as a SHA-256 hash of a 256-bit token in an httpOnly cookie, 30-day absolute expiry, revoked on password change or reset. Authenticator-app TOTP not implemented; no org-wide enforcement setting.Active

Australian regulatory compliance

Legislation / StandardObligationHow NoteGate™ satisfies it
Privacy Act 1988 (Cth) - APPsAPP 1: Open & transparent managementThis page, privacy policy, and in-app disclosure
APP 6: Use or disclosureData used only for service delivery; no sale or model training
APP 8: Cross-border disclosureZDR agreement + our de-identification service; data stays in Australia
APP 11: SecurityEncryption at rest/transit, RBAC, MFA, audit log
NDIS Act 2013 - Part 7Protected NDIS informationTenant-scoped isolation; worker scoped to assigned participants only
Aged Care Act 2024Information securityAES-256 encryption, access control, de-identification
Aged Care Quality StandardsStandard 5 - clinical documentationAI quality gate, mandatory validation, approval workflow
SIRS (Serious Incident Response)Incident reporting obligationsIncident module with structured capture and export
ASD Essential EightMaturity Level 2 (target)Privileged access (#5), patching via ECS rolling deploy (#2, #6). MFA (#7) partially met: two-factor is available but email-delivered, which is not phishing-resistant.

Security enquiries

For security assessments, IRAP evaluation support, or responsible disclosure, contact our security team.

security@notegate.com.au

Start with NoteGate today.

Solo and Starter subscribe immediately. Growth and above start with a 14-day trial with a card saved.

Choose a plan → Book a 20-minute walkthrough →