Overview & Security Posture
Meliora Support Services processes highly sensitive diagnostic histories, trauma records, and tribunal-grade evidence to navigate complex National Disability Insurance Scheme (NDIS), Administrative Review Tribunal (ART), and My Aged Care appeals.
To meet the highest standards of corporate due diligence and protect the participants we serve, Meliora operates a "Zero-Trust," closed-loop enterprise digital ecosystem. This appendix outlines the technical architecture, data segregation protocols, and AI governance models that guarantee participant trauma and sensitive information are never exposed to public networks or commercial machine-learning models.
Download PDF Version
Server Architecture & Cryptographic Sovereignty
Meliora does not rely on consumer-grade storage or communication platforms. Our foundational architecture is built on enterprise-grade infrastructure heavily utilised by global financial institutions and government agencies.
- Primary Data Lake (Google Workspace Enterprise Plus): All private medical reports, administrative submissions, and official communications are hosted within our sovereign Google Workspace Enterprise Plus environment.
- Client-Side Encryption (CSE): We enforce Client-Side Encryption for all highly sensitive files. Meliora retains direct control of the encryption keys via an external key management service. Google cannot access the decrypted content of these files, ensuring absolute cryptographic sovereignty.
- Data Sovereignty & Government Compliance (IRAP): While standard cloud data may be distributed globally, Meliora’s enterprise architecture complies with Australian federal data privacy regulations (Privacy Act 1988 and the Australian Privacy Principles) through strict Data Processing Addendums (DPAs). Furthermore, our Google Workspace infrastructure is independently assessed by the Australian Cyber Security Centre (ACSC) under the Information Security Registered Assessors Program (IRAP) up to the PROTECTED level. It also holds a 'Certified Strategic' rating under the Australian Government's Hosting Certification Framework (HCF), ensuring it meets the rigorous cybersecurity standards required by federal agencies.
Patient Data Segregation & Compartmentalisation
A core requirement of the Unfunded Lives program is the strict separation of philanthropic expert system navigation from Meliora’s standard commercial operations.
- Logical Segregation (Asana Enterprise+): The Unfunded Lives program is logically isolated within our central case management system (Asana Enterprise+). Philanthropic workflows, statutory triggers, and statutory countdowns are managed via dedicated, strict portfolio tagging rather than commingled with standard operational delivery.
- Role-Based Access Control (RBAC): Meliora operates on the principle of "least privilege." Access to an unredacted medical file or a sensitive statutory portfolio is programmatically restricted exclusively to the specific Specialist Support Coordinator (SSC) assigned to the case and the Executive Board.
- Systemic Database Segregation (ShiftCare): To prevent the accidental commingling of commercial compliance data and philanthropic workflows, our rostering and time-tracking architecture (ShiftCare) enforces strict database siloing. Unfunded Lives participants are maintained on entirely distinct client profiles tagged as "Philanthropic." While federal identifiers (like NDIS or My Aged Care ID numbers) are securely recorded purely for internal identification, absolutely zero billable federal service bookings, portal claims, or external financial identifiers are attached to these philanthropic profiles. Custom, internal-only cost codes (e.g., specific codes for evidence navigation and crisis stabilisation) are enforced at the system level to guarantee absolute financial fencing.
Enterprise AI Infrastructure (The Closed Loop)
To beat strict statutory deadlines (e.g., the 28-day ART window and critical My Aged Care assessment periods), Meliora deploys the "Evidence Engine"—a highly advanced deployment of Google Gemini Enterprise—to rapidly distil complex diagnostic evidence and draft legislative submissions.
- The "No-Train" Enterprise Guarantee: Exposing client trauma to public machine-learning models is an unacceptable risk. Our enterprise agreements with Google strictly prohibit the use of our prompts, uploaded medical files, or generated outputs to train, refine, or inform public AI models (including public, consumer-facing versions of Gemini).
- Ephemeral Processing: AI is deployed strictly as a processing accelerator. Data ingested by the AI model exists only in ephemeral memory for the duration of the generation task. Once the legislative map or draft submission is output into our secure environment, the prompt data is expunged.
- Human-in-the-Loop Safeguard: The AI is systematically restricted from autonomous execution. It functions as a drafting and extraction tool. All diagnostic logic, legislative mapping, and final submissions must be manually reviewed, edited, and authorised by a human Specialist Support Coordinator before dispatch.
- Endpoint Device Management & Zero-Trust
Hardware vulnerability (lost or compromised laptops) is neutralised through strict Mobile Device Management (MDM), operated in continuous partnership with our onshore managed IT provider, All Computer Services Australia Pty Ltd.
- Outsourced Managed IT (Security & Compliance): Meliora has partnered with All Computer Services to provision and maintain a compliant, secure endpoint environment. This ensures our hardware and network infrastructure are governed by a dedicated, Queensland-based Managed Service Provider (MSP) with extensive experience securing data for Not-For-Profit (NFP) and corporate sectors.
- Credential-Gating & Access Control: Participant data cannot be accessed without secure login credentials. Access policies are actively managed to ensure strict compliance and security standards are maintained across the organisation's hardware fleet.
- Local Data Protection: Any files temporarily required locally by specialists to execute offline work are strictly governed by our enterprise authentication layers. Endpoint access policies are actively enforced by our IT provider to prevent unauthorised data extraction or local compromise.
- Incident Response & Device Containment: In the event of hardware theft or compromise, our outsourced IT partner provides the capability to swiftly contain the device, sever network access, and execute remote wipes to protect sensitive data.
Audit Logging & Incident Response
- Immutability and Auditing: Every interaction with a client file—including views, downloads, edits, and AI extractions—is logged immutably within Asana Enterprise+ and Google Workspace Admin Console.
- Regulatory Compliance: Our incident response protocols operate in strict, proactive alignment with the Office of the Australian Information Commissioner (OAIC) and the Notifiable Data Breaches (NDB) scheme.
(For further technical clarification or external auditing requests, please contact the Meliora Support Services Board of Directors).
Go heart or go home,
David Ryan ~ Founding Director
Meliora Support Services
david@meliora.org.au | 0429 319 539
Entity: Meliora Support Services | ABN: 60 683 124 076 |
Tax Status: Public Benevolent Institution | DGR Item 1 (100% Tax Deductible)
Document Status: Open access – De-Identified For Participant Privacy