SECURITY
Security
Our products hold some of the most sensitive records in the country — disability and care data about real people. This page describes how we approach that, and how to reach us if you find something wrong.
Report a vulnerability
If you believe you have found a security issue in any Orion system or product, please tell us before you tell anyone else. Email hello@oriontechnology.com.au with SECURITY in the subject line.
Useful things to include: what you found, where, the steps to reproduce it, and what you think the impact is. A rough note that arrives today is more valuable to us than a polished report that arrives next month.
What you can expect from us
- We acknowledge reports and tell you whether we can reproduce the issue.
- We keep you updated while we work on it, and tell you when it is fixed.
- We will credit you if you would like to be credited, and respect your wish not to be.
- We will not pursue or support legal action against anyone who reports in good faith under the terms below.
What we ask of you
- Use only your own accounts and test data. Do not access, modify or retain anyone else's information — particularly participant or client records.
- Do not run denial-of-service tests, send spam, or use social engineering against our people or our customers.
- Give us reasonable time to fix an issue before disclosing it publicly.
We do not currently run a paid bug bounty. That is not a reason to stay quiet — we would still very much like to hear from you.
How we build
Security is part of the first commit rather than an audit at the end. In practice that means the things below are properties of the system from the start, not features added when a customer asks.
- Access control
- Role-based permissions, so people see the records their job requires and not the rest. Multi-factor authentication for administrative access.
- Encryption
- Data encrypted in transit, and sensitive fields encrypted at rest with organisation-scoped keys.
- Audit trails
- Records of who changed what and when, written append-only so history cannot be quietly rewritten.
- Tenant isolation
- Multi-tenant platforms keep each organisation's data separated, so one customer cannot reach another's records.
- Operations
- Infrastructure as code, continuous integration, monitoring and backups — the unglamorous work that makes recovery possible and change safe.
Data residency
Our products are built for Australian providers and state their own residency arrangements. CareOp and MySienna are hosted in Australia; each product's own security and privacy pages are the authoritative statement for that product, and are the ones to rely on in a procurement or audit.
This marketing site is a separate thing and is served from a global CDN, so it may be delivered from outside Australia. It holds no customer data — see our privacy policy.
Certifications
We hold no formal security certification at this time. We would rather say so plainly than imply one. The practices above are real and are how the systems are built; if you need certified assurance for a procurement process, talk to us about what your process requires.
Incidents
If an incident affects customer data, we notify the affected organisations directly, and we meet our obligations under Australia's Notifiable Data Breaches scheme where they apply. Providers using our products have their own obligations to participants and to regulators, and we support them in meeting those rather than leaving them to work it out alone.
Contact
Orion Technology Pty Ltd
ABN 51 701 742 690
4530 G/470 St Kilda Road, Melbourne VIC 3004
hello@oriontechnology.com.au