Security & data handling

Safe claiming starts with a clear boundary.

Corella is a hosted connection between your authorised business AI assistant and the NDIA aggregator gateway. Nothing money-moving happens on trust alone: identity, access, validation, human approval, and audit evidence all sit in the path.

Hosted, not locally installed

Your team connects a supported business AI assistant to Corella's HTTPS endpoint and signs in. Corella's server, gateway credentials, and PRODA keys are never installed on provider computers.

OAuth and least privilege

Every request needs a signed access token tied to an active provider. Read access and claim access use separate scopes, and provider identity cannot be changed with a prompt, header, or tool input.

Human-approved submissions

Claims and service-booking changes start with a preview. The exact preview needs an explicit human approval and a single-use token before Corella sends it to the gateway.

Provider-isolated records

Gateway clients, approval state, and audit directories are separated by the provider identity in the signed token. Audit and usage records are encrypted at rest and available for controlled export.

AI assistant requirement

Business data terms only.

Participant data returned by a tool enters the connected AI assistant’s context. Pilot providers must use a business, enterprise, or API arrangement with a contractual no-training commitment. Consumer free tiers are not accepted for participant data.

Production baseline

Australian-region controls.

Production onboarding requires Australian-region hosting, HTTPS, encrypted durable audit storage, managed secrets, and a live cross-provider test proving the gateway selects the correct organisation’s downstream NDIA credentials.

Questions or a suspected incident?

Email hello@corella.au. We provide the detailed data-flow, retention, access, and incident process during pilot onboarding.