Winner — Best WHS Training Program, 2026 Hunter Safety Awards

Trust Centre

Your data stays in Australia.
Your people stay unidentified.

Gentia is an end-to-end psychosocial safety management platform operated by balance2life Pty Ltd, an Australian company. Client data is stored in accredited data centres in Australia and is not transferred offshore. Personal details are removed before any AI processing, individual-level data is never stored in identifiable form, and client data is never used to train AI models. This page sets out how that works.

Security documentation is available on request. See the bottom of this page.

Data Residency

Where is our data stored?

In accredited data centres in Australia. It does not leave the country.

Australian data residency

All client data is held in accredited enterprise cloud data centres located in Australia. Data is not replicated, backed up or processed offshore.

Australian legal jurisdiction

Because the data stays in Australia, it remains subject to Australian law, including the Privacy Act 1988 (Cth). We will not transfer client data outside Australia without the client's written agreement.

Enterprise cloud infrastructure

The platform runs on enterprise cloud infrastructure with network segmentation, continuous monitoring, vulnerability management and automated threat detection.

Security Controls

How is our data protected?

Encrypted in transit and at rest

Data moving between your systems and Gentia is encrypted using TLS 1.2 or above. Data stored in the platform is encrypted at rest.

Least-privilege access

Access is granted only where it is required to perform a role, and no further. Permissions are reviewed on a scheduled basis, and every access event is logged.

Multi-factor authentication and session control

Multi-factor authentication is required for staff access. Role-based permissions, session management and privileged access management govern who can reach what, and for how long.

A full audit trail

Actions taken in the platform are recorded, so it is possible to reconstruct who accessed what, when, and what they changed.

Privacy by Design

Does Gentia identify individual employees?

No. Gentia assesses how work is designed and managed, not individual people.

This is a deliberate design decision rather than a policy applied afterwards. Psychosocial risk lives in the conditions of the work — workload, role clarity, support, span of control, how change is managed. Gentia is built to find risk in those conditions, which means it does not need to identify individuals in order to work.

Personal details are removed before AI processing

Names, email addresses, phone numbers and similar identifiers are detected and removed before data enters the analysis pipeline. Analysis is carried out on the pattern of work, not on identified people.

Individual-level data is never stored in identifiable form

Findings are produced and reported at team, group or organisational level.

Data minimisation and purpose limitation

We collect only what is needed to deliver the service, and use it only for the purpose it was provided for.

Not a surveillance or performance management tool

Gentia is not designed to monitor individuals, build cases against them, or support disciplinary, performance or termination decisions. Our Acceptable Use Policy prohibits using it that way.

AI Governance

How is AI governed, and is our data used to train it?

Your data is never used to train AI models. It remains exclusively yours.

No training on client data

Gentia does not train its models on client data, and does not permit client data to be used to train third-party models.

Expert in the loop

Every material finding is reviewed by a psychosocial safety specialist before it is relied on. AI increases speed, specificity and consistency. It does not replace expert judgment.

Traceable reasoning

Every finding traces back to the evidence it came from. Where the system is inferring rather than observing, it says so, and states what would confirm it.

Documented AI usage mapping

How AI models are used within the platform — for what purpose, over what data, with what controls — is documented and available on request.

Governance

What standards does Gentia align to?

Gentia's data governance and information security practices are designed and operated in alignment with recognised international frameworks: ISO/IEC 27001 and ISO/IEC 27002 for information security management, NIST for cyber security controls, and ITIL and COBIT for service management and IT governance. Our psychosocial safety practice is aligned to ISO 45003 and Australian work health and safety law across all eight jurisdictions.

Gentia does not currently hold ISO 27001 or SOC 2 certification. We describe our controls as aligned to these frameworks because that is accurate. We will say so plainly if and when certification is achieved, and not before.

  • ISO/IEC 27001 and 27002information security management
  • NIST Cybersecurity Frameworkcyber security controls
  • ITIL and COBITIT service management and governance
  • ISO 45003psychological health and safety at work
  • Privacy Act 1988 (Cth) and the Australian Privacy Principlesprivacy
  • Safe Work Australia Model Code of Practicepsychosocial hazard management

Operational Security

What about the people and processes behind it?

Background screening

Personnel are screened before they are given access to client environments.

Security awareness training

Staff complete security awareness training, and it is refreshed rather than treated as a one-off.

Incident response

A documented incident response plan sets out how a security incident is identified, contained, escalated and communicated. Where an incident is likely to result in serious harm, we notify affected clients and the Office of the Australian Information Commissioner in line with the Notifiable Data Breaches scheme.

Business continuity and disaster recovery

Documented plans cover continuity of service and recovery of data.

Secure development lifecycle

Security requirements are built into how the platform is designed, built, reviewed and released, rather than tested for at the end.

Third-party assessment

Our security posture is subject to independent third-party assessment.

What does this website collect?

Almost nothing.

This website uses strictly necessary cookies only. We do not use analytics cookies or tracking pixels. We do not run third-party advertising scripts. We do not profile visitors, and we do not share visitor data with advertising networks or data brokers. We do not sell personal information.

Full details are in our Privacy Policy.

Request security documentation

Procurement, security and privacy teams can request the following documents. Email hello@gentia.ai and tell us which you need.

  • Information Security Policy
  • Incident Response Plan
  • Business Continuity and Disaster Recovery Plan
  • Gentia Architecture Diagram
  • Privacy Policy
  • Cookie Policy
  • AI Usage Model Mapping
  • Master Service Agreement
  • Data Processing Addendum

Data Processing Agreements are available on request.

FAQ

Trust and security questions, answered.

In accredited enterprise cloud data centres located in Australia. Client data is not replicated, backed up or processed offshore, and it is not transferred outside Australia without the client's written agreement.

No. Gentia does not train its models on client data, and does not permit client data to be used to train third-party models. Your information remains exclusively yours.

No. Personal details are removed before any AI processing, and individual-level data is never stored in identifiable form. Findings are reported at team, group or organisational level. Gentia assesses how work is designed and managed, not individual people, and our Acceptable Use Policy prohibits using it as a performance management or surveillance tool.

No. Gentia's data governance and information security practices are designed and operated in alignment with ISO/IEC 27001 and ISO/IEC 27002, but Gentia does not currently hold certification. We describe our controls as aligned to these frameworks because that is accurate, and we will say so plainly if and when certification is achieved.

Yes. Data in transit is encrypted using TLS 1.2 or above, and data stored in the platform is encrypted at rest.

Access is granted on a least-privilege basis — only where it is required to perform a role. Multi-factor authentication is required for staff access, permissions are reviewed on a schedule, privileged access is separately managed, and every access event is logged.

A documented incident response plan governs how an incident is identified, contained, escalated and communicated. Where a breach is likely to result in serious harm, we notify affected clients and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth).

Gentia is operated by balance2life Pty Ltd, an Australian company, and handles personal information in accordance with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles. Where the GDPR applies, Gentia acts as data processor and the client organisation is the data controller.

You do. Client data remains the property of the client organisation, which also controls who can access it, who can be added or removed, and its retention and export.

Yes. Data Processing Agreements are available on request. Email hello@gentia.ai.

No. The site uses strictly necessary cookies only. There are no analytics cookies, no tracking pixels, no third-party advertising scripts, no visitor profiling and no data sharing with advertising networks.

Information Security Policy, Incident Response Plan, Business Continuity and Disaster Recovery Plan, Gentia Architecture Diagram, Privacy Policy, Cookie Policy, AI Usage Model Mapping, Master Service Agreement and Data Processing Addendum. Email hello@gentia.ai to request them.

No. Work health and safety duties sit with the organisation and cannot be transferred to a supplier or a software platform. Gentia helps you identify hazards, design and apply controls, and evidence what you have done. The duty remains yours.

Questions this page does not answer? Email hello@gentia.ai.