Public-sector due diligence

Designed for controlled public-sector deployment.

Before any live application data is processed, PlanScout and the participating local government must agree the architecture, data flows, access controls, retention arrangements, model-provider boundaries and contractual responsibilities.

Historical validation can begin with synthetic or de-identified material before any live-data or production decision is considered.

Deployment assurance

Controls scale with the deployment stage.

Stage 1

Public synthetic demonstration

  • fictional data only
  • no genuine application uploads
  • demonstrates applicant and reviewer experiences
  • does not represent production security certification

Stage 2

Historical or de-identified backtest

  • controlled access method agreed
  • NDA and data-handling terms
  • approved users
  • agreed retention and deletion
  • no production-system write-back
  • no applicant communication
  • no statutory action

Stage 3

Live operational use

  • authentication and role-based authorisation
  • tenant separation
  • hosting, data location and encryption
  • audit logging, backup and recovery
  • subprocessors and incident response
  • retention, deletion and records export
  • support access and business continuity

Live operational use proceeds only after the participating local government approves the architecture, controls and contractual responsibilities.

Honest disclosure

What is in place today, and what is not.

In place for a historical backtest

  • A written evaluation agreement before any data is provided
  • Completed historical applications only; no live decision is affected
  • Access limited to the named parties in that agreement
  • Agreed retention period and documented data return or deletion
  • Source-linked review history recorded against every configured requirement
  • No applicant-facing service and no public exposure during the backtest

Not yet in place, and not claimed

  • No independent penetration test completed
  • No SOC 2 or ISO 27001 certification
  • No single sign-on or council identity integration
  • No formal service levels or support hours
  • No disaster recovery or restoration testing
  • No accessibility testing against WCAG 2.2 AA

These form part of the expected production assurance baseline. A council may require selected controls earlier, depending on its risk assessment, data classification and evaluation approach.

Synthetic product demonstration

Demonstrated in the synthetic environment

Public demo routes are product experiences, not evidence of authenticated role-based access. Controls are listed as current only where the repository supports that claim.

Synthetic workflow capabilities

Source-linked human review history

Demonstrated

The synthetic reviewer demonstration records requirement outcomes, reviewer identity, notes, timestamps and source references in local demo state.

Demonstration basis: Implemented in the synthetic reviewer demonstration data model.

Document and report export

Demonstrated

The synthetic demonstration provides downloadable source documents and PDF outputs.

Demonstration basis: Implemented in the public synthetic demonstration.

No automated statutory action

Demonstrated

The demonstrated workflow does not approve, refuse, issue or submit a statutory decision.

Demonstration basis: Implemented workflow boundary and available actions reviewed in source.

Backtest safeguards

Controls for a historical evaluation

  • NDA and agreed data-handling terms
  • synthetic or de-identified material preferred
  • no production-system write-back
  • no applicant communication
  • no statutory action
  • named evaluation participants
  • agreed transfer method
  • agreed retention and deletion period
  • final report and data-disposal process

Historical evaluation controls do not automatically establish readiness for live operational use.

Deployment control matrix

The control basis changes at each deployment stage.

ControlPublic synthetic demoHistorical backtestLive operational use
AuthenticationNot representedAgreed access methodEnforced and verified
Role separationDemonstrated as UX onlyNamed evaluation usersEnforced
Tenant separationNot representedEngagement-specific controlsEnforced
Review historySynthetic demo stateAgreed evaluation recordProduction logging
Hosting and encryptionNot representedAgreed architectureVerified
Retention and deletionSynthetic data onlyContractually agreedConfigurable and verified
Source document accessSynthetic sourcesAgreed transfer and accessAuthorised access
Backup and recoveryNot representedAgreed where relevantVerified
SubprocessorsDemo providers disclosed where applicableContractually agreedApproved and maintained
Incident responseNot representedContractual escalationOperational process

Live operational use proceeds only after the participating local government approves the architecture, controls and contractual responsibilities.

Assurance areas

Designed for controlled evaluation before live deployment.

Human oversight

An authorised local government building surveyor or permit officer reviews the cited evidence and records the outcome. The permit authority retains responsibility for every professional and statutory action and decision.

Evaluation readiness question

Define who may confirm, dismiss or resolve findings and how those outcomes affect the official process.

Evidence and audit

The evidence workspace links each configured requirement to the source document, page, extracted value, status, rule version and reviewer outcome.

Evaluation readiness question

Agree the audit fields, export needs and relationship to the official record before live operation.

Data boundaries

Any use of genuine council application data, including a historical backtest, must be configured and contracted so that customer application documents are not used for general model training.

Evaluation readiness question

Document data flows, service boundaries and permitted uses in the evaluation architecture and written agreement.

Controlled access

Evaluation access, user roles and the treatment of applicant information must be agreed before live operation.

Evaluation readiness question

Confirm authorised users, support access, role separation and account lifecycle responsibilities.

Retention and deletion

Retention periods, export requirements and secure deletion must be documented in the written evaluation agreement.

Evaluation readiness question

Set the retention period for each evaluation stage and verify the agreed exit process.

Rule governance

PlanScout separates statewide prescribed requirements, statutory-form relationships, local government intake requirements, cross-document consistency checks, professional judgement boundaries and external-agency dependencies.

Evaluation readiness question

Confirm the source type, effective dates, local applicability, approval status and reviewer-confirmation requirement for each configured item.

Versioned rule and terminology governance

Each configured item supports the fields needed to distinguish its canonical meaning, local presentation, authority and period of applicability.

Local-government configuration does not convert an operational checklist item into a statutory requirement. The evidence workspace must preserve the distinction.

  • canonical ID
  • source type
  • statutory code where applicable
  • canonical name
  • local display name
  • local aliases
  • source label
  • source URL
  • effective-from date
  • effective-to date
  • rule version
  • local applicability
  • approval status
  • reviewer-confirmation requirement

Important assurance boundary

Do not interpret this overview as a security certification or legal compliance statement. Final controls depend on the agreed evaluation architecture and contract. Council procurement, legal, privacy and vendor-assurance requirements continue to apply.

Request a workflow review