PracticeStack Assurance

Security and assurance, without vague claims.

We are building security controls and auditable evidence into PracticeStack from the start. This page shows our current public posture and targets. It is deliberately explicit about what is implemented, what is still in progress, and what has not yet been independently attested.

No SOC 2, ISO 27001 or IRAP certification is claimed on this page.
Security baseline in final verification

Controls designed to produce evidence, not just policy statements.

These controls are part of the Security Assurance Baseline currently undergoing final verification. We will update their public status as that work closes and the production Recovery boundary matures.

Secure software development

Final verification

Security checks are being integrated into the development lifecycle and CI rather than treated as a launch-day checklist.

Secret scanning

Final verification

The assurance baseline includes automated scanning designed to detect committed credentials and other secret material.

Dependency risk management

Final verification

The assurance baseline includes production dependency auditing with blocking rules for unacceptable vulnerabilities and explicit treatment for residual risk.

Static application security testing

Final verification

Automated SAST is included in the baseline. Coverage limitations are tracked rather than reported as complete when they are not.

Software bill of materials

Final verification

The security evidence workflow is designed to generate a production software bill of materials.

Secure logging and data minimisation

Final verification

The baseline includes application logging controls designed to minimise personal information, backed by automated redaction tests.

Assurance roadmap

One control system, mapped to the frameworks that matter.

Rather than maintain separate checkbox programmes, we are building one evidence-led assurance system and mapping it to relevant Australian and international frameworks as PracticeStack grows.

PracticeStack Security Assurance Baseline
Final verification in progress
A machine-verifiable security baseline covering CI, logging, dependency risk, SAST, evidence collection and documented residual risk.
Australian privacy and health information obligations
Built into design
Recovery is being designed around applicable Australian privacy and health-information requirements. Formal legal scope and customer contractual roles will be confirmed before production patient-data processing.
ASD Essential Eight
Assessment planned
We intend to assess the operating environment against the Essential Eight maturity model and engineer toward an appropriate target maturity.
ASD Information Security Manual
Mapping in progress
Relevant ISM controls are being used as an Australian-government security reference for engineering and assurance.
SOC 2 Trust Services Criteria
Readiness work underway
Controls and evidence are being designed with SOC 2 readiness in mind. PracticeStack is not currently SOC 2 attested or certified.
ISO/IEC 27001
Future certification target
A formal information security management system and accredited certification are future targets as the operating environment matures.
Independent penetration testing
Planned before production patient-data use
Independent security testing is planned before Recovery handles production customer patient data.
IRAP
Future, customer-driven
An IRAP assessment would be considered if Australian Government or other customer requirements justify it. PracticeStack does not claim IRAP certification.
Recovery and patient data

The production data boundary comes before the claim.

PracticeStack Recovery is still in early access. Development and security verification are performed without populated customer patient exports in the shared engineering environment.

Before production customer patient data is processed, the production system boundary, access model, retention rules, incident-response obligations, customer agreements and independent testing will be reviewed against the applicable risk and privacy requirements.

Security questions

Need assurance information for a review?

As the assurance programme matures, customer-facing evidence will be made available at the appropriate level without publishing sensitive implementation detail or internal security findings.

Contact PracticeStack
Get started

Ready to see what your practice could improve first?

Book a free growth plan session. We review your website, search presence and advertising, and give you a clear plan - with no obligation.

No commitment requiredWritten findings report includedNo offshore support - Melbourne based