Security and governance

Start with the questions
your agency needs answered.

Review records can contain sensitive information. Security and information governance belong in the conversation from the outset.

This page sets out topics for due diligence. It is not a statement of certification or a completed security specification.

Before a pilot,
agree the requirements.

Access and identity

Who needs access, which roles can see each record, how private preparation is handled, and what authentication your agency requires.

Hosting and data handling

Where data would be stored, who would process it, and the arrangements for encryption, backup and recovery.

Retention and deletion

How long records and private notes need to be retained, how deletion would work, and how your agency would retrieve its data.

Traceability and handover

What attribution, version history and audit evidence your agency needs, including the separation of recommendation and decision.

Procurement documentation

The agreements, data-flow information, subprocessor details and assessment material your team would need to review.

Professional judgement and AI

Any proposed AI assistance should have an explicit scope. Our intended boundary is support for administration and preparation, with suitability assessments, recommendations and decisions remaining with professionals.

Bring your questions.
We’ll discuss the fit.

Tell us which security and governance requirements matter to your organisation.

Current capabilities and available documentation should be confirmed directly with Arcaja Tech before sharing live case information or agreeing a pilot.

Book a 30-minute workflow review