Multi-organisation separation
Organisation-owned records include an organisation boundary and are protected by active membership checks.
SECURITY & TRUST
SkillWard’s foundation uses multi-organisation separation, role-scoped access and auditable workflows. We make no claim of external certification that has not been formally achieved.
Organisation-owned records include an organisation boundary and are protected by active membership checks.
Authorisation comes from protected memberships and assignments—not editable browser metadata.
Managers and trainers are limited to authorised facilities, departments and relationships.
Supabase authentication provides secure sessions, invitation and password-recovery foundations.
Organisation-aware storage policies separate approved file paths.
Key administrative, training, assessment and support actions are designed to remain attributable.
Operational backup and recovery procedures require final production configuration and regular testing.
A documented incident-response process and contact path are required before a hospital pilot.
The intended training workflow does not require patient information; organisations should not upload it.
SkillWard is not claiming ISO 27001, SOC 2, HIPAA certification, Australian government certification or external clinical approval. Formal risk assessment, penetration testing, operational monitoring, incident exercises and legal review remain required before production hospital use.
Report a suspected security issue through Contact & Support. Do not include passwords, patient information or sensitive workforce records in the initial message.
READY FOR THE NEXT STEP?