In development

Your name comes out before the AI sees anything.

AI is genuinely useful for the writing part of support work. But handing someone's clinical history to a general-purpose model as it was written isn't something we're willing to do — so the personal information comes out first, and goes back afterwards. This page explains exactly how.

Everything we already know about a participant is replaced before an AI model sees their text.

Their name, NDIS number and contact details, and the names of the people and organisations recorded around them, are swapped for placeholders taken from their own record. That happens first, every time, before anything leaves our environment.

Names that aren't on the record are the hard part, and they're where most of our work has gone. A neighbour mentioned once, a small local business, a nickname: every word the system doesn't positively recognise is hidden before the AI sees it, then judged without being shown. That catches almost all of them. Very occasionally one still gets through, so we measure how often and keep driving it down.

Three rules for every AI feature

CDS is still in development. These are the rules each AI feature has to meet before it's released. Some features in our development environment don't meet them yet, and they won't be released until they do.

Where it runs

In Australia

Model calls go to Amazon Bedrock on Australian infrastructure, alongside the rest of the platform. Nothing is sent to an overseas AI service.

Who handles it

No outside AI services

No consumer AI tools, and no third-party de-identification service holding your text. The de-identification is our own, and it runs inside our own environment.

Who decides

A person signs off

AI produces a draft or a suggestion. It is saved to a participant's record only after a person has read it and accepted it.

Step by step

Follow one case note the whole way through

A support worker finishes a shift and types a few rough lines. Here is every stage between that and the note saved on the participant's record. The example below is invented — the names and places aren't real.

STEP 1 OF 6

The idea at the centre of it

We ask about words we never show

Names are messy. Nicknames, misspellings, words that are a person in one sentence and a suburb in the next. Guessing which is which — and guessing wrong — is how a real person's identity ends up inside a model.

So we invert it. Anything not positively recognised as ordinary language is replaced with a blind marker before the request is built. The model is then asked whether that marker is a person — and answers from the sentence around it, having never been shown the word.

That question can't leak the word, because the word was never in it. The answer still matters, though. If the model wrongly decides a name is an ordinary word, the word goes back into the text for the writing step. That rare miss is what we measure, and it's why the system leans towards redacting whenever it isn't sure.

What the worker wrote

Bilbo said the bus was late again.

What the model was sent

{3:?} said the bus was late again. Is {3:?} a person?

What the model answered

Yes — it is the subject of a speech verb.

The word "Bilbo" was never in the request. It is restored on our side, after the answer comes back.

If it goes wrong

One last check before it's sent

Once the text has been de-identified, and just before it goes to the AI, it's checked against every name and detail the earlier steps replaced. If a copy of one is still somewhere in the text — say, a second mention the substitution missed — it's swapped for the same placeholder and the text is checked again. Only if that can't make it clean does the request stop, with nothing sent. The worker still has their own notes, and finishes the entry themselves.

When in doubt, it redacts

If the system can't tell whether a word is a name, it treats it as one. The finished note still reads normally, because every placeholder, including an unnecessary one, is swapped back for the original word when the draft returns. Letting a real name through is the mistake that matters, so every close call goes towards redacting.

We assume our own numbers are optimistic

Every change is scored against a test set we built ourselves, because no de-identification benchmark exists for Australian disability-support language. The test notes are invented, and real notes will be messier, so we treat the leaks we can measure as a floor, not a total.

Nothing runs on trust alone

The component that puts real names back has no permission to contact any AI model whatsoever. Even if it were compromised, it would have no way to reach one.

Your say in it

AI is used on your information only if you agree to it

It's the participant's information, so it's the participant's call — or their guardian's. You decide whether your information can be de-identified and used by AI to help the people supporting you with writing and analysis.

Per purpose

Consent is not all-or-nothing

Consent is given separately for each kind of use, such as rewriting case notes, drafting reports or reading documents. You can allow some and refuse others, and change your mind at any time.

Off by default

Nothing until you say yes

Consent starts switched off. Until you agree to a purpose, AI isn't used on your information for that purpose.

Saying no

Declining costs you nothing

Refusing AI doesn't limit your access to anything else on the platform. Anything AI would have drafted is written by a person instead, as it always has been.

Security & access

In plain terms

Where it lives

Participant records are stored on AWS in Sydney (ap-southeast-2), and AI processing runs on AWS in Australia. Data is encrypted in transit and at rest, and every request is checked so that an organisation only ever reaches the participants connected to it. Ordinary email correspondence with us is a separate system, hosted in the United States — so please don't send us clinical details by email.

Who can see it

The providers a participant has connected, and the workers those providers assign. Connecting grants a provider access to the profile so they can support the person properly — it isn't split into partial views, because a support worker acting on half a picture is how people get hurt. Disconnecting a provider removes that access.

Guardianship

Authority is set per account — full authority, limited to certain areas, supported decision-making where the participant stays in charge, or co-decision where both the guardian and the participant have to agree. Actions a guardian takes on someone's behalf are recorded in a log that the platform can add to but not edit, and a copy is archived each day to locked storage.

What we don't do

We don't sell data, and we don't use participant information to train AI models; the AI services we use don't train on it either. We don't browse accounts. When we do open one through the platform, to operate or support it, that access is logged.

Ask us

Questions we haven't answered here?

We would much rather be asked than assumed about — especially by providers who have to satisfy their own obligations before they can use us.