Data Security Statement

Where your data lives, how workspaces are isolated, and how we handle health information. Hosted in Australia.

Cloud Infrastructure & Hosting

Harvest Flow is hosted on the Google Cloud Platform (GCP), one of the world's most secure cloud environments. To guarantee data sovereignty and optimal performance for our local users, all primary databases and application servers are hosted in Sydney, Australia. We leverage scalable, serverless technologies to ensure the system remains stable even during peak usage periods.

Data Encryption

  • In Transit All data transmitted between your devices (mobile phones, web browsers) and our servers is encrypted using industry-standard TLS/HTTPS protocols.
  • At Rest All data stored within our databases is encrypted at rest using advanced encryption algorithms (e.g., AES-256), meaning your sensitive notes and contact details are shielded from unauthorized access.

Access Control & Authentication

  • Role-Based Access Control Harvest Flow employs strict role-based access controls. Your organization's administrators have full authority to grant or revoke system access for their team, ensuring each member only sees the information necessary for their specific role.
  • System Integrity We operate on a principle of least privilege. To investigate a support request, one of our operators can open a read-only view of your workspace. That view expires after two hours, cannot create, change or delete anything, and each one is recorded in our audit log.

Workspace Isolation

  • Separate Workspaces Every organisation on our platform runs on the same application and the same database, hosted in Sydney. What keeps them apart is a boundary our servers enforce: every record carries the identifier of the workspace it belongs to, and every signed-in request is checked against the workspace of the person making it before anything is read or written. The separation never relies on your browser.
  • Dedicated Workspaces A Dedicated workspace is an organisation of its own on the platform: its own configuration, templates, branding and data space, with no other organisation inside it. It is not separate hardware or a separate database. It is the same boundary, drawn around your organisation alone. Its logins exist only inside it, so someone who also works for another organisation holds a separate login there, and an administrator in one workspace cannot reach an account in another.

Backups and Reliability

We understand that losing follow-up data is not an option. Our systems perform automated, routine backups of your database. In the unlikely event of a hardware failure or disruption, our disaster recovery protocols allow us to restore services and data quickly, minimizing any impact on your day-to-day workflow.

Application Security

The Harvest Flow application is built using modern, secure development frameworks. We continuously monitor our infrastructure for vulnerabilities and apply the latest security patches to our cloud environments to defend against emerging threats.

Incident Response

While no system is completely immune to security incidents, we have protocols in place to detect and respond to anomalies rapidly. In the event of a confirmed data breach that compromises your information, we commit to notifying your designated account administrators promptly, outlining the nature of the breach and the steps we are taking to mitigate it, in full compliance with the Notifiable Data Breaches (NDB) scheme in Australia.

On the NDIS digital platform rules.

From 1 July 2026 the NDIS Commission registers "digital platforms" as a class of support. That class covers systems that sit between participants and workers and move plan funds through themselves. HarvestFlow does neither — we're provider-side operations software. We don't match participants to workers, and your invoices go from you to your client or their plan manager, and are paid to your bank account, not ours.