Skip to content
OneForce Care
Legal & trust

Security

A high-level overview of how OneForce Care protects customer, participant and worker information.

Last updated · 26 August 2026

OneForce Care is operated by Wondertree Studios Pty Ltd (ACN 699 886 498, ABN 82 699 886 498) of Level 10, 387 George Street, Sydney NSW 2000, Australia (“Wondertree”, “we”, “us”, “our”).

We use technical and organisational safeguards appropriate to the information handled by the Service and review them as risks and the Service change.

This page is a public overview. We do not publish infrastructure configurations, internal procedures or other information that could weaken our controls. Providers may request additional assurance information, subject to appropriate restrictions.

Security approach

Our safeguards include:

  • access controls, individual accounts and role-based permissions;
  • encryption for information in transit and at rest where appropriate;
  • security and activity logging;
  • backup, recovery and continuity measures; and
  • confidentiality and security requirements for authorised personnel and relevant service providers.

Customers are responsible for protecting their accounts, configuring permissions, maintaining required records and promptly reporting suspected misuse.

Data location

Primary Provider Data storage is maintained in Australia. Our Data residency page and Privacy Policy provide further information.

Incident response

We maintain an incident-response process. Notifications and assistance are handled under our Data Processing Addendum and applicable law.

Reporting a vulnerability

If you believe you have found a security vulnerability affecting OneForce Care, email hello@oneforce.com.au with a concise description and enough information for us to investigate.

Do not access, copy, alter or disclose data that is not yours, disrupt the Service, use destructive testing, or publicly disclose a suspected issue before we have had a reasonable opportunity to assess it. Reporting an issue does not authorise unlawful access or misuse.

Contact

Security questions and vulnerability reports can be sent to hello@oneforce.com.au.

Questions about this page? Contact us at hello@oneforce.com.au.