Public-sector due diligence
Designed for controlled public-sector deployment.
Before any live application data is processed, PlanScout and the participating local government must agree the architecture, data flows, access controls, retention arrangements, model-provider boundaries and contractual responsibilities.
Historical validation can begin with synthetic or de-identified material before any live-data or production decision is considered.
Deployment assurance
Controls scale with the deployment stage.
Stage 1
Public synthetic demonstration
- fictional data only
- no genuine application uploads
- demonstrates applicant and reviewer experiences
- does not represent production security certification
Stage 2
Historical or de-identified backtest
- controlled access method agreed
- NDA and data-handling terms
- approved users
- agreed retention and deletion
- no production-system write-back
- no applicant communication
- no statutory action
Stage 3
Live operational use
- authentication and role-based authorisation
- tenant separation
- hosting, data location and encryption
- audit logging, backup and recovery
- subprocessors and incident response
- retention, deletion and records export
- support access and business continuity
Live operational use proceeds only after the participating local government approves the architecture, controls and contractual responsibilities.
Honest disclosure
What is in place today, and what is not.
In place for a historical backtest
- A written evaluation agreement before any data is provided
- Completed historical applications only; no live decision is affected
- Access limited to the named parties in that agreement
- Agreed retention period and documented data return or deletion
- Source-linked review history recorded against every configured requirement
- No applicant-facing service and no public exposure during the backtest
Not yet in place, and not claimed
- No independent penetration test completed
- No SOC 2 or ISO 27001 certification
- No single sign-on or council identity integration
- No formal service levels or support hours
- No disaster recovery or restoration testing
- No accessibility testing against WCAG 2.2 AA
These form part of the expected production assurance baseline. A council may require selected controls earlier, depending on its risk assessment, data classification and evaluation approach.
Synthetic product demonstration
Demonstrated in the synthetic environment
Public demo routes are product experiences, not evidence of authenticated role-based access. Controls are listed as current only where the repository supports that claim.
Synthetic workflow capabilities
Source-linked human review history
The synthetic reviewer demonstration records requirement outcomes, reviewer identity, notes, timestamps and source references in local demo state.
Demonstration basis: Implemented in the synthetic reviewer demonstration data model.
Document and report export
The synthetic demonstration provides downloadable source documents and PDF outputs.
Demonstration basis: Implemented in the public synthetic demonstration.
No automated statutory action
The demonstrated workflow does not approve, refuse, issue or submit a statutory decision.
Demonstration basis: Implemented workflow boundary and available actions reviewed in source.
Backtest safeguards
Controls for a historical evaluation
- NDA and agreed data-handling terms
- synthetic or de-identified material preferred
- no production-system write-back
- no applicant communication
- no statutory action
- named evaluation participants
- agreed transfer method
- agreed retention and deletion period
- final report and data-disposal process
Historical evaluation controls do not automatically establish readiness for live operational use.
Deployment control matrix
The control basis changes at each deployment stage.
| Control | Public synthetic demo | Historical backtest | Live operational use |
|---|---|---|---|
| Authentication | Not represented | Agreed access method | Enforced and verified |
| Role separation | Demonstrated as UX only | Named evaluation users | Enforced |
| Tenant separation | Not represented | Engagement-specific controls | Enforced |
| Review history | Synthetic demo state | Agreed evaluation record | Production logging |
| Hosting and encryption | Not represented | Agreed architecture | Verified |
| Retention and deletion | Synthetic data only | Contractually agreed | Configurable and verified |
| Source document access | Synthetic sources | Agreed transfer and access | Authorised access |
| Backup and recovery | Not represented | Agreed where relevant | Verified |
| Subprocessors | Demo providers disclosed where applicable | Contractually agreed | Approved and maintained |
| Incident response | Not represented | Contractual escalation | Operational process |
Live operational use proceeds only after the participating local government approves the architecture, controls and contractual responsibilities.
Assurance areas
Designed for controlled evaluation before live deployment.
Human oversight
An authorised local government building surveyor or permit officer reviews the cited evidence and records the outcome. The permit authority retains responsibility for every professional and statutory action and decision.
Evaluation readiness question
Define who may confirm, dismiss or resolve findings and how those outcomes affect the official process.
Evidence and audit
The evidence workspace links each configured requirement to the source document, page, extracted value, status, rule version and reviewer outcome.
Evaluation readiness question
Agree the audit fields, export needs and relationship to the official record before live operation.
Data boundaries
Any use of genuine council application data, including a historical backtest, must be configured and contracted so that customer application documents are not used for general model training.
Evaluation readiness question
Document data flows, service boundaries and permitted uses in the evaluation architecture and written agreement.
Controlled access
Evaluation access, user roles and the treatment of applicant information must be agreed before live operation.
Evaluation readiness question
Confirm authorised users, support access, role separation and account lifecycle responsibilities.
Retention and deletion
Retention periods, export requirements and secure deletion must be documented in the written evaluation agreement.
Evaluation readiness question
Set the retention period for each evaluation stage and verify the agreed exit process.
Rule governance
PlanScout separates statewide prescribed requirements, statutory-form relationships, local government intake requirements, cross-document consistency checks, professional judgement boundaries and external-agency dependencies.
Evaluation readiness question
Confirm the source type, effective dates, local applicability, approval status and reviewer-confirmation requirement for each configured item.
Versioned rule and terminology governance
Each configured item supports the fields needed to distinguish its canonical meaning, local presentation, authority and period of applicability.
Local-government configuration does not convert an operational checklist item into a statutory requirement. The evidence workspace must preserve the distinction.
- canonical ID
- source type
- statutory code where applicable
- canonical name
- local display name
- local aliases
- source label
- source URL
- effective-from date
- effective-to date
- rule version
- local applicability
- approval status
- reviewer-confirmation requirement
Important assurance boundary
Do not interpret this overview as a security certification or legal compliance statement. Final controls depend on the agreed evaluation architecture and contract. Council procurement, legal, privacy and vendor-assurance requirements continue to apply.
