Data governance
Data governance
How Rupert approaches access and clinical data for NDIS reporting workflows. This page describes as-built product behaviour — not certifications or audit frameworks.
Authenticated access
Clinicians can create an account and sign in. On first use, Rupert collects profession and registration details for accountability. Clinical work and protected APIs stay behind authentication.
Owner-scoped reports
Published reports are scoped to the owning user. You can list, preview, and download reports you own. Other users cannot access your report store through the product APIs.
Confidential clinical data
Sources, reports, and review artifacts are treated as confidential clinical data. The product surface and APIs require authentication before that material is available.
Assessor control
You remain responsible for clinical content and submissions. Rupert drafts from your notes and proposes amendments from planner feedback; you decide what enters the final document. Rupert does not replace clinical judgement.