
Loading
Parkway is operating software for NDIS providers. The database sits in Australia. Access is scoped to the organisation. Money movement needs a fresh authenticator check. That is the posture. Not a badge.
These are the controls we operate. If a control is not here, we do not claim it.
Personal information in the Service is stored in Sydney (Supabase, region ap-southeast-2). Files sit in the same region. Transport is TLS. Data at rest is encrypted by Supabase (AES-256).
Every query is restricted to the requesting organisation. Staff see what their role allows. We do not sell personal information. We do not use participant or worker data for advertising.
Two-factor authentication (TOTP) is optional for ordinary sign-in. A fresh authenticator check is required before money movement. We do not hard-block support workers on MFA at clock-in.
Production deploys go through GitHub. Required checks on main include lint, typecheck, tests, build, generated types, scope-guard, migrations, and e2e smoke. Force-push on main is off. That is how a change reaches parkways.com.au.
Admin and team audit logs record who did what in the platform. Email send logs sit separately. We keep operational records for seven years where NDIS retention requires it.
Email hello@parkways.com.au. Do not probe, scan, or test the Service without written consent. See the Terms. We will acknowledge and work the issue.
We are not SOC 2 certified. We are not ISO 27001 certified. Connecting a trust-management tool is not a certificate. We do not publish a pentest letter from a named firm on this page. When we have those, they will be named here.
A vendor is on the public list before it sees personal information. The same names sit in the Privacy Policy.
ACN 697 911 890
Unit 5/5-7 Cairns Street, Loganholme QLD 4129
hello@parkways.com.au