Service · NDIS and regulated care

NDIS compliance software development

What this is

Custom systems for NDIS providers carrying an obligation their platform cannot represent. Usually not a replacement for that platform, but the narrow piece beside it, integrated so nobody maintains two sources of truth.

Every engagement starts with two weeks inside your workflow before any code is written. One legitimate outcome of those two weeks is being told to configure what you already have and build nothing.

Who this is for

  • Providers on the certification pathway with blended SIL, SDA or shared-program arrangements
  • Behaviour support practices tracking supervision, plan deadlines and restrictive practice authorisation across a clinical team
  • Providers carrying a retention, consent or evidence-of-control obligation their platform does not model
  • Providers where the same non-conformity has appeared at two consecutive audits

How the work runs

Stage 01 · Map the obligations

Two weeks inside your workflow. Not a discovery deck: sitting with the people doing the work and mapping what they hold against what you are obliged to hold. Produces a build plan, an accuracy baseline and a risk register, all three of which you keep whether or not anything follows.

Stage 02 · Design to the obligation

The obligation is the requirement, not a layer added afterwards. Audit trails, retention schedules and consent handling are designed as first-class features because retrofitting them is a rebuild.

Stage 03 · Build with evidence

Evidence generated as a by-product of the work rather than a second administrative task. This is the design decision that determines whether the system is still delivering compliance value in year three.

Stage 04 · Operate and harden

Deployment, monitoring and iteration against the ACSC Essential Eight, so the posture holds as the system and the threats evolve.

What every build carries

  • Australian-hosted infrastructure, inside your own tenancy where that matters
  • Architected against the Privacy Act 1988 (Cth)
  • Hardening aligned to the ACSC Essential Eight, architecture referenced to ISO/IEC 27001
  • WCAG 2.1 AA as a floor rather than an aspiration
  • You own the code, the infrastructure accounts and the documentation from day one, with no dependency only I can renew
When I will tell you not to engage

Under about 30 staff with standard Practice Standards obligations and no unusual service model, an established platform is the right answer and you should not commission custom development. You will be told that in the two weeks rather than in month three.

Proof

300+behaviour support plans under management
15+practitioners and supervisors
10,000+pages redacted per month, separate engagement
20+systems delivered

Common questions

Do you replace our existing compliance platform?

Usually not. The platform handles the standard obligations well and absorbs regulatory change. What gets built is the piece it structurally cannot represent, integrated with what you already run.

What does an engagement cost?

Scope decides it, and quoting a range without seeing your obligations would be guessing. The two-week review is fixed and produces enough to make the decision with evidence.

Who maintains the system afterwards?

Whoever you choose. Everything is handed over with documentation and no dependency only I can renew. A system you cannot leave is a system you should not commission.

Where is the data hosted?

Australia, and inside your own tenancy where the obligation calls for it. For several engagements that has removed a cross-border disclosure question that would otherwise have needed its own assessment.

Related

Not sure whether you need custom at all?

That is what the two weeks answers. If the honest answer is configure what you have, you will be told that.

Start a conversation