Service · NDIS and regulated care
NDIS compliance software development
Custom systems for NDIS providers carrying an obligation their platform cannot represent. Usually not a replacement for that platform, but the narrow piece beside it, integrated so nobody maintains two sources of truth.
Every engagement starts with two weeks inside your workflow before any code is written. One legitimate outcome of those two weeks is being told to configure what you already have and build nothing.
Who this is for
- Providers on the certification pathway with blended SIL, SDA or shared-program arrangements
- Behaviour support practices tracking supervision, plan deadlines and restrictive practice authorisation across a clinical team
- Providers carrying a retention, consent or evidence-of-control obligation their platform does not model
- Providers where the same non-conformity has appeared at two consecutive audits
How the work runs
Stage 01 · Map the obligations
Two weeks inside your workflow. Not a discovery deck: sitting with the people doing the work and mapping what they hold against what you are obliged to hold. Produces a build plan, an accuracy baseline and a risk register, all three of which you keep whether or not anything follows.
Stage 02 · Design to the obligation
The obligation is the requirement, not a layer added afterwards. Audit trails, retention schedules and consent handling are designed as first-class features because retrofitting them is a rebuild.
Stage 03 · Build with evidence
Evidence generated as a by-product of the work rather than a second administrative task. This is the design decision that determines whether the system is still delivering compliance value in year three.
Stage 04 · Operate and harden
Deployment, monitoring and iteration against the ACSC Essential Eight, so the posture holds as the system and the threats evolve.
What every build carries
- Australian-hosted infrastructure, inside your own tenancy where that matters
- Architected against the Privacy Act 1988 (Cth)
- Hardening aligned to the ACSC Essential Eight, architecture referenced to ISO/IEC 27001
- WCAG 2.1 AA as a floor rather than an aspiration
- You own the code, the infrastructure accounts and the documentation from day one, with no dependency only I can renew
Under about 30 staff with standard Practice Standards obligations and no unusual service model, an established platform is the right answer and you should not commission custom development. You will be told that in the two weeks rather than in month three.
Proof
Common questions
Do you replace our existing compliance platform?
Usually not. The platform handles the standard obligations well and absorbs regulatory change. What gets built is the piece it structurally cannot represent, integrated with what you already run.
What does an engagement cost?
Scope decides it, and quoting a range without seeing your obligations would be guessing. The two-week review is fixed and produces enough to make the decision with evidence.
Who maintains the system afterwards?
Whoever you choose. Everything is handed over with documentation and no dependency only I can renew. A system you cannot leave is a system you should not commission.
Where is the data hosted?
Australia, and inside your own tenancy where the obligation calls for it. For several engagements that has removed a cross-border disclosure question that would otherwise have needed its own assessment.