SECURITY

Security

Our products hold some of the most sensitive records in the country — disability and care data about real people. This page describes how we approach that, and how to reach us if you find something wrong.

Orion Technology Pty Ltd · ABN 51 701 742 690 · Last updated 26 August 2026

Report a vulnerability

If you believe you have found a security issue in any Orion system or product, please tell us before you tell anyone else. Email hello@oriontechnology.com.au with SECURITY in the subject line.

Useful things to include: what you found, where, the steps to reproduce it, and what you think the impact is. A rough note that arrives today is more valuable to us than a polished report that arrives next month.

What you can expect from us

  • We acknowledge reports and tell you whether we can reproduce the issue.
  • We keep you updated while we work on it, and tell you when it is fixed.
  • We will credit you if you would like to be credited, and respect your wish not to be.
  • We will not pursue or support legal action against anyone who reports in good faith under the terms below.

What we ask of you

  • Use only your own accounts and test data. Do not access, modify or retain anyone else's information — particularly participant or client records.
  • Do not run denial-of-service tests, send spam, or use social engineering against our people or our customers.
  • Give us reasonable time to fix an issue before disclosing it publicly.

We do not currently run a paid bug bounty. That is not a reason to stay quiet — we would still very much like to hear from you.

How we build

Security is part of the first commit rather than an audit at the end. In practice that means the things below are properties of the system from the start, not features added when a customer asks.

Access control
Role-based permissions, so people see the records their job requires and not the rest. Multi-factor authentication for administrative access.
Encryption
Data encrypted in transit, and sensitive fields encrypted at rest with organisation-scoped keys.
Audit trails
Records of who changed what and when, written append-only so history cannot be quietly rewritten.
Tenant isolation
Multi-tenant platforms keep each organisation's data separated, so one customer cannot reach another's records.
Operations
Infrastructure as code, continuous integration, monitoring and backups — the unglamorous work that makes recovery possible and change safe.

Data residency

Our products are built for Australian providers and state their own residency arrangements. CareOp and MySienna are hosted in Australia; each product's own security and privacy pages are the authoritative statement for that product, and are the ones to rely on in a procurement or audit.

This marketing site is a separate thing and is served from a global CDN, so it may be delivered from outside Australia. It holds no customer data — see our privacy policy.

Certifications

We hold no formal security certification at this time. We would rather say so plainly than imply one. The practices above are real and are how the systems are built; if you need certified assurance for a procurement process, talk to us about what your process requires.

Incidents

If an incident affects customer data, we notify the affected organisations directly, and we meet our obligations under Australia's Notifiable Data Breaches scheme where they apply. Providers using our products have their own obligations to participants and to regulators, and we support them in meeting those rather than leaving them to work it out alone.

Contact

Orion Technology Pty Ltd
ABN 51 701 742 690
4530 G/470 St Kilda Road, Melbourne VIC 3004
hello@oriontechnology.com.au

← Back to Orion