💡 Tip: You can explore our full security, privacy, and compliance position, including certifications, incident response, and uptime history, at our Trust Centre.
Keeping your data safe and secure
You work with sensitive personal information, and Minikai is designed to support that responsibility with care, transparency, and security.
Built for the sector: Minikai is designed for regulated care environments like NDIS, aged care, and community services.
Purpose-built for your region: Our policies and systems reflect the laws and expectations in Australia, New Zealand, and the United Kingdom.
Transparent by design: Every access to your data is logged, and you stay in control of who sees what, always.
Certifications
Minikai is independently certified to two international standards:
ISO/IEC 27001:2022 for information security management.
ISO/IEC 42001:2023 for responsible AI management, one of the first international standards of its kind.
Both certificates are issued by an accredited third party and maintained through annual surveillance audits. We are also working towards UK Cyber Essentials. You can view our current certificates at the Trust Centre.
Compliance
Minikai is built to comply with the privacy laws that apply to our Customers:
Australia: the Australian Privacy Principles under the Privacy Act 1988 (Cth).
New Zealand: the Information Privacy Principles under the Privacy Act 2020.
United Kingdom: the UK GDPR and the Data Protection Act 2018, where your organisation operates in the UK. We maintain a GDPR compliance programme.
These frameworks guide how we collect, store, use, and share personal and health information, and we build Minikai to exceed them wherever possible.
How we protect your data
Data privacy
All data is encrypted in transit and at rest. We monitor access continuously, and you'll always know who accessed what, and when.
Data sovereignty
Your data is stored and processed in the data region your organisation selects, currently Australia or the United Kingdom, and it does not leave that region except as required by law or as you have authorised.
User access management
Only authorised team members can access sensitive information. Minikai supports:
Role-based permissions that control what each user can see and do. Learn more about roles →
For Enterprise teams: Single Sign-On (SSO) for secure, simplified login using your organisation's identity provider, and automated provisioning (SCIM) to manage user access as staff join or leave.
Every action is tracked, and only authorised team members can access customer data.
ℹ️ Good to know: Minikai does not use your data to train AI models. The information your organisation provides is used only to power the Minis in your workspace. For more on how the AI works, see How Minikai's AI works.
Need help or have a concern?
If you have questions about security or privacy, or want to report an issue, message us through the Help Desk in the app or on this page, or contact your workspace admin. We take every concern seriously.
