Security & Governance
Patient communication your clinic can trust.
Patient conversations are among the most sensitive data an allied health clinic holds. Pillar's technical architecture is led by Australian cybersecurity and clinical-governance expertise from the beginning, not reviewed in afterwards.
Protected patient intelligence
Protected patient intelligence
- Audit loggingActions recorded & traceable
- Security by designCybersecurity-led architecture
- Controlled AIDefined rules & permissions
- Australian serversAustralian-region hosting
- Australian teamBuilt & supported locally
- Encrypted dataIn transit & at rest
- Controlled accessRole-based permissions
- Human oversightDefined escalation pathways
- HIPAAPrivacy aligned
- AHPRAWorkflow aware
- SOC 2Aligned principles
- NISTSecurity principles
- Essential EightAustralian guidance
- ACSCAustralian guidance
Cybersecurity leadership
Cybersecurity and clinical governance expertise inside the founding team.
IWIan Wilson
Co-Founder and Chief Technology Officer
AI infrastructure · Cybersecurity · Platform architecture
Pillar's technical leadership includes hands-on experience across AI infrastructure, cybersecurity, cloud architecture and enterprise systems supporting mission-critical environments.
That expertise shapes how Pillar approaches access control, infrastructure, integrations and AI governance from the first line of code — not as a checklist added once the platform is built.
Secure architecture
AI governance
Cloud infrastructure
Access control design
Audit & logging systems
Health-data privacy
Integration security
Incident response
Professional experience demonstrates the cybersecurity expertise within Pillar's technical leadership and does not, on its own, independently certify the Pillar platform.
From expertise to architecture
Security experience means more when it changes how you build.
01
Patient data
- Calls, messages, bookings
- Collected only for the clinic's use
02
Access & encryption
- Encrypted in transit and at rest
- Key management separated from application access
03
Pillar Brain
- Clinic-controlled knowledge
- Scoped to the clinic that owns it
04
Bounded agent action
- Least-privilege practice-management permissions
- Logged and auditable
05 · Human checkpoint
Human oversight
- Escalation for anything clinical or sensitive
- A person, not a policy, makes the judgement call
Controlled intelligence. Not unconstrained autonomy.
01
Data residency
Patient data is stored and processed in Australia, aligned with the Privacy Act 1988 and the Australian Privacy Principles.
02
Encryption
In transit and at rest, with key management separated from application access.
03
Access control
Role-based access for your team, scoped to the narrowest practice-management permissions needed to read availability and write bookings, and revocable immediately.
04
Audit trail
Every conversation, decision and write-back is logged and exportable.
05
AI governance
Pillar is designed around clinic-controlled knowledge, defined workflows and human escalation rather than unconstrained autonomous AI. Agents act within boundaries configured with your clinic.
06
Human oversight
Every agent has escalation rules. Clinical, sensitive or uncertain conversations are routed to a person with the context attached.
- Role-based access for your team, revocable immediately
- No patient data used to train third-party foundation models
- Breach response and notification obligations documented before go-live
- Data export and deletion on request, without penalty
From inside the practice
Guardrails matter most to the people responsible. This is how they describe them.
Clear boundaries, consistent communication and escalation to a person when a conversation needs one.

“In psychology, technology has to know its boundaries. It's not just about answering quickly — patient privacy, appropriate escalation and knowing when a conversation needs a person matter. That's what makes the way Pillar has been designed important to us.”
The biggest changes
01
Clear boundaries
Administrative conversations can be handled while professional and sensitive matters remain with people.
02
Consistent communication
Patients receive responses based on the practice's approved information and workflows.
03
Human escalation
Conversations requiring a person are routed rather than AI attempting to answer everything.
Security principles
Built with recognised principles in mind.
- Privacy Act & APPsAustralian privacy principles
- ISO 27001Information security
- NIST CSFCybersecurity framework
- Essential EightACSC mitigation strategies
- ACSC ISMInformation security manual
- AHPRA obligationsPractitioner governance
Pillar's approach is informed by the principles behind the Privacy Act and Australian Privacy Principles, ISO 27001, the NIST Cybersecurity Framework, the Essential Eight and the ACSC Information Security Manual. Pillar does not currently hold formal certification or independent audit against any of these frameworks, and we will not imply otherwise. Where formal certification or independent audit is achieved, it will be published here. AHPRA regulates practitioners and their professional obligations — it does not certify software, and Pillar makes no claim of AHPRA approval.
A deliberate boundary
Administrative support, not a My Health Record system.
Pillar manages communication, scheduling and approved operational workflows — it is not a My Health Record–connected clinical record system, and it does not diagnose, prescribe or replace clinical judgement. Clinical decisions remain with qualified, AHPRA-regulated practitioners at all times.
Technical detail
Want to go deeper?
Where is patient data stored?
Patient data is stored and processed in Australia, aligned with the Privacy Act 1988 and the Australian Privacy Principles.
Who can access our clinic's information?
Access is restricted to authorised Pillar personnel who need it to deliver or support the service, using role-based access that your clinic can review and revoke at any time.
Does Pillar train AI models on our patient data?
No. Patient data is not used to train third-party foundation models.
How are practice-management integrations secured?
Pillar holds the narrowest practice-management permissions needed to read availability and write bookings in systems like your practice management system — nothing broader.
What happens when something needs a human?
Every agent operates inside boundaries configured with your clinic. Clinical questions, sensitive situations and anything outside those boundaries are escalated to your team with the context attached.
Can our clinic control what Pillar is allowed to say or do?
Yes. Your clinic's knowledge, tone, escalation rules, booking logic and the actions an agent may take are configured with you and can be changed at any time.
Is Pillar a My Health Record system?
No. Pillar is an administrative and communication layer for allied health clinics. It is not connected to My Health Record and does not function as a clinical record system.
What security frameworks inform Pillar's approach?
Pillar's design is informed by the Privacy Act and Australian Privacy Principles, ISO 27001, the NIST Cybersecurity Framework, the Essential Eight and the ACSC Information Security Manual, through our technical leadership's practical experience with them. Pillar does not hold certification against these frameworks.
What is retained, and for how long?
Interaction data is retained for the period agreed with the clinic and deleted on request or at the end of the agreement, other than records we are legally required to keep.
Who do we contact about a privacy complaint or breach?
Patients should contact their clinic in the first instance. Clinics and individuals may contact us directly to request access, correction or deletion, or to make a privacy complaint; unresolved complaints may be escalated to the Office of the Australian Information Commissioner.
Security you can understand.
People you can actually talk to.
Talk directly with our team about security, privacy, integrations, or how Pillar would operate inside your clinic — including your privacy impact assessment or vendor review.
