NDIS platforms hold highly sensitive information about vulnerable people, which makes account security non-negotiable. Rostery protects logins with app-based multi-factor authentication and supporting controls.
How it works
Users can secure their accounts with TOTP multi-factor authentication using an authenticator app, so a password alone isn't enough to get in. Account lockout defends against repeated failed login attempts, and a strong password policy raises the baseline for every account.
Why it matters for NDIS providers
A compromised account can expose participant data and damage trust and compliance. Layered authentication dramatically reduces the risk of unauthorised access.
- Stronger logins: TOTP MFA adds a second factor beyond the password.
- Brute-force defence: account lockout blocks repeated failed attempts.
- Better baseline: a strong password policy applies to all accounts.
What's included
- App-based MFA. Secure accounts with TOTP multi-factor authentication.
- Account lockout. Block repeated failed login attempts.
- Strong password policy. Raise the security baseline for every account.
- Protects participant data. Layered authentication reduces the risk of unauthorised access.
- Supports compliance. Strong access controls help meet your security obligations.
Who it's for
2FA / TOTP Authentication suits Australian NDIS, disability and aged-care providers of every size — from solo coordinators to multi-site organisations running multiple registered entities. Security teams, support workers and managers all work from the same live data across the Rostery web dashboard and the carer mobile app, so nothing falls through the cracks between the office and the field.
Getting started
2FA / TOTP Authentication is included in your Rostery plan and works the moment your data is in — there's no separate module to buy or set up. Start a free trial to try it on your own workflows, and use Rostery's "Smart Switch" data migration to bring your existing clients, staff, shifts and notes across from your current software in minutes. Our team can walk you through your specific participant types, funding mix and rostering complexity in a quick demo.
