Security and assurance, without vague claims.
We are building security controls and auditable evidence into PracticeStack from the start. This page shows our current public posture and targets. It is deliberately explicit about what is implemented, what is still in progress, and what has not yet been independently attested.
Controls designed to produce evidence, not just policy statements.
These controls are part of the Security Assurance Baseline currently undergoing final verification. We will update their public status as that work closes and the production Recovery boundary matures.
Secure software development
Final verificationSecurity checks are being integrated into the development lifecycle and CI rather than treated as a launch-day checklist.
Secret scanning
Final verificationThe assurance baseline includes automated scanning designed to detect committed credentials and other secret material.
Dependency risk management
Final verificationThe assurance baseline includes production dependency auditing with blocking rules for unacceptable vulnerabilities and explicit treatment for residual risk.
Static application security testing
Final verificationAutomated SAST is included in the baseline. Coverage limitations are tracked rather than reported as complete when they are not.
Software bill of materials
Final verificationThe security evidence workflow is designed to generate a production software bill of materials.
Secure logging and data minimisation
Final verificationThe baseline includes application logging controls designed to minimise personal information, backed by automated redaction tests.
One control system, mapped to the frameworks that matter.
Rather than maintain separate checkbox programmes, we are building one evidence-led assurance system and mapping it to relevant Australian and international frameworks as PracticeStack grows.
The production data boundary comes before the claim.
PracticeStack Recovery is still in early access. Development and security verification are performed without populated customer patient exports in the shared engineering environment.
Before production customer patient data is processed, the production system boundary, access model, retention rules, incident-response obligations, customer agreements and independent testing will be reviewed against the applicable risk and privacy requirements.
Need assurance information for a review?
As the assurance programme matures, customer-facing evidence will be made available at the appropriate level without publishing sensitive implementation detail or internal security findings.
Contact PracticeStack