Pillar Health Systems

Security & Governance

Patient communication your clinic can trust.

Patient conversations are among the most sensitive data an allied health clinic holds. Pillar's technical architecture is led by Australian cybersecurity and clinical-governance expertise from the beginning, not reviewed in afterwards.

Pillar

Protected patient intelligence

  • Audit loggingActions recorded & traceable
  • Security by designCybersecurity-led architecture
  • Controlled AIDefined rules & permissions
  • Australian serversAustralian-region hosting
  • Australian teamBuilt & supported locally
  • Encrypted dataIn transit & at rest
  • Controlled accessRole-based permissions
  • Human oversightDefined escalation pathways
  • HIPAAPrivacy aligned
  • AHPRAWorkflow aware
  • SOC 2Aligned principles
  • NISTSecurity principles
  • Essential EightAustralian guidance
  • ACSCAustralian guidance

Cybersecurity leadership

Cybersecurity and clinical governance expertise inside the founding team.

Ian Wilson, Co-Founder and Chief Technology Officer at Pillar, at an engineering workstation reviewing platform architecture.IW

Ian Wilson

Co-Founder and Chief Technology Officer

AI infrastructure · Cybersecurity · Platform architecture

Pillar's technical leadership includes hands-on experience across AI infrastructure, cybersecurity, cloud architecture and enterprise systems supporting mission-critical environments.

That expertise shapes how Pillar approaches access control, infrastructure, integrations and AI governance from the first line of code — not as a checklist added once the platform is built.

  • Secure architecture

  • AI governance

  • Cloud infrastructure

  • Access control design

  • Audit & logging systems

  • Health-data privacy

  • Integration security

  • Incident response

Professional experience demonstrates the cybersecurity expertise within Pillar's technical leadership and does not, on its own, independently certify the Pillar platform.

From expertise to architecture

Security experience means more when it changes how you build.

  1. 01

    Patient data

    • Calls, messages, bookings
    • Collected only for the clinic's use
  2. 02

    Access & encryption

    • Encrypted in transit and at rest
    • Key management separated from application access
  3. 03

    Pillar Brain

    • Clinic-controlled knowledge
    • Scoped to the clinic that owns it
  4. 04

    Bounded agent action

    • Least-privilege practice-management permissions
    • Logged and auditable
  5. 05 · Human checkpoint

    Human oversight

    • Escalation for anything clinical or sensitive
    • A person, not a policy, makes the judgement call

Controlled intelligence. Not unconstrained autonomy.

01

Data residency

Patient data is stored and processed in Australia, aligned with the Privacy Act 1988 and the Australian Privacy Principles.

02

Encryption

In transit and at rest, with key management separated from application access.

03

Access control

Role-based access for your team, scoped to the narrowest practice-management permissions needed to read availability and write bookings, and revocable immediately.

04

Audit trail

Every conversation, decision and write-back is logged and exportable.

05

AI governance

Pillar is designed around clinic-controlled knowledge, defined workflows and human escalation rather than unconstrained autonomous AI. Agents act within boundaries configured with your clinic.

06

Human oversight

Every agent has escalation rules. Clinical, sensitive or uncertain conversations are routed to a person with the context attached.

  • Role-based access for your team, revocable immediately
  • No patient data used to train third-party foundation models
  • Breach response and notification obligations documented before go-live
  • Data export and deletion on request, without penalty

From inside the practice

Guardrails matter most to the people responsible. This is how they describe them.

Clear boundaries, consistent communication and escalation to a person when a conversation needs one.

Josip Vujica, Director at Harrisdale Psychology Services
In psychology, technology has to know its boundaries. It's not just about answering quickly — patient privacy, appropriate escalation and knowing when a conversation needs a person matter. That's what makes the way Pillar has been designed important to us.
Josip VujicaDirector · Harrisdale Psychology Services

The biggest changes

  • 01

    Clear boundaries

    Administrative conversations can be handled while professional and sensitive matters remain with people.

  • 02

    Consistent communication

    Patients receive responses based on the practice's approved information and workflows.

  • 03

    Human escalation

    Conversations requiring a person are routed rather than AI attempting to answer everything.

01 / 03

Security principles

Built with recognised principles in mind.

  • Privacy Act & APPsAustralian privacy principles
  • ISO 27001Information security
  • NIST CSFCybersecurity framework
  • Essential EightACSC mitigation strategies
  • ACSC ISMInformation security manual
  • AHPRA obligationsPractitioner governance

Pillar's approach is informed by the principles behind the Privacy Act and Australian Privacy Principles, ISO 27001, the NIST Cybersecurity Framework, the Essential Eight and the ACSC Information Security Manual. Pillar does not currently hold formal certification or independent audit against any of these frameworks, and we will not imply otherwise. Where formal certification or independent audit is achieved, it will be published here. AHPRA regulates practitioners and their professional obligations — it does not certify software, and Pillar makes no claim of AHPRA approval.

A deliberate boundary

Administrative support, not a My Health Record system.

Pillar manages communication, scheduling and approved operational workflows — it is not a My Health Record–connected clinical record system, and it does not diagnose, prescribe or replace clinical judgement. Clinical decisions remain with qualified, AHPRA-regulated practitioners at all times.

Technical detail

Want to go deeper?

Where is patient data stored?

Patient data is stored and processed in Australia, aligned with the Privacy Act 1988 and the Australian Privacy Principles.

Who can access our clinic's information?

Access is restricted to authorised Pillar personnel who need it to deliver or support the service, using role-based access that your clinic can review and revoke at any time.

Does Pillar train AI models on our patient data?

No. Patient data is not used to train third-party foundation models.

How are practice-management integrations secured?

Pillar holds the narrowest practice-management permissions needed to read availability and write bookings in systems like your practice management system — nothing broader.

What happens when something needs a human?

Every agent operates inside boundaries configured with your clinic. Clinical questions, sensitive situations and anything outside those boundaries are escalated to your team with the context attached.

Can our clinic control what Pillar is allowed to say or do?

Yes. Your clinic's knowledge, tone, escalation rules, booking logic and the actions an agent may take are configured with you and can be changed at any time.

Is Pillar a My Health Record system?

No. Pillar is an administrative and communication layer for allied health clinics. It is not connected to My Health Record and does not function as a clinical record system.

What security frameworks inform Pillar's approach?

Pillar's design is informed by the Privacy Act and Australian Privacy Principles, ISO 27001, the NIST Cybersecurity Framework, the Essential Eight and the ACSC Information Security Manual, through our technical leadership's practical experience with them. Pillar does not hold certification against these frameworks.

What is retained, and for how long?

Interaction data is retained for the period agreed with the clinic and deleted on request or at the end of the agreement, other than records we are legally required to keep.

Who do we contact about a privacy complaint or breach?

Patients should contact their clinic in the first instance. Clinics and individuals may contact us directly to request access, correction or deletion, or to make a privacy complaint; unresolved complaints may be escalated to the Office of the Australian Information Commissioner.

Security you can understand.
People you can actually talk to.

Talk directly with our team about security, privacy, integrations, or how Pillar would operate inside your clinic — including your privacy impact assessment or vendor review.