Single sign-on with your own identity provider. Data that never leaves Australia. Integrations built for you rather than filed as a feature request. And a straight answer about what we don't have yet.
If your organisation runs Microsoft Entra ID, Google Workspace or Okta, RTO Grow connects to it. Your identity provider stays the source of truth for who works there β we never become a second, stale list of your people.
Available on request. Your IT sends us the metadata for your identity provider and we register it against your email domain β usually within a business day. Staff then get a "Continue with single sign-on" option on the login page.
When your staff sign in through single sign-on, your Conditional Access, MFA and device policies are enforced by your identity provider before they reach us β we never see a password or a second factor on that path. Single sign-on does not yet disable password sign-in: a staff member who also has an RTO Grow password can still use it. Ask us and we'll remove their password login so SSO is the only way in.
A valid company login that hasn't been invited into your workspace is refused: no workspace membership, no role, and no staff or student record is created. (Our authentication provider records the attempted identity, as any IdP-connected system does; it carries no access to anything.) Sign-in authenticates people; it never provisions them.
Disable someone in your identity provider and they can no longer sign in here (an existing session ends at token expiry β see the note below). Removing them from the workspace is immediate and severs every staff sign-in route at once, password and SSO together.
Scope, stated plainly: this covers staff logins. Students sign in with emailed magic links, which land in the corporate mailbox your own MFA already protects. Single logout (SLO) is not supported by our authentication provider β sessions are bounded by token lifetime and by workspace membership, which your administrators control.
Most of what RTO Grow integrates with exists because a provider needed it. Payroll systems, employer portals, state funding platforms, your own website β the answer isn't "it's on the roadmap", it's a scope and a timeline.
A call with the people who write the code β not an account manager relaying requirements to an offshore team. That's most of why this moves quickly.
You get a scope and a timeline within days, including an honest "this isn't worth building" when that's the real answer. You won't wait a quarter to find out whether it's possible.
Every change is reviewed before release, and risky ones ship behind a feature flag we can switch off for your organisation without rolling back the release.
Reasonable customer-specific integration work is included on our high-volume plans, from $2,500 a month. On smaller plans it is scoped and quoted before anything starts β and the integrations already on the platform are never per-connector add-ons.
Application, database, files and email all run from Sydney. We don't sell your data and we don't use it to train AI models. The full subprocessor list is public on our integrations page rather than something you have to request under NDA.
See the full vendor listSecurity assessments are usually where small vendors go quiet for three weeks. Here you're talking to the people who can actually answer, and we'd rather tell you a gap up front than have your assessor find it.
Working through a cyber assessment right now? Send us the questionnaire. We'll answer it directly, and flag anything we can't yet meet rather than wording around it.
Every vendor page tells you what it has. This is the other half. If one of these is a hard requirement for your organisation, tell us now β it's better for both of us than finding out at contract stage.
Our infrastructure provider is; we are not. We build to those controls β Australian hosting, database-enforced isolation, append-only audit trails, independent code review β but we will not imply a certificate we don't hold.
Not on a formal cadence today. When a report exists we'll share it with customers under NDA. If your assessment requires one before signing, say so early and we'll talk about timing.
MFA is enforced today for RTO Grow staff on the administration surface. For your users, MFA arrives through your identity provider when you connect single sign-on β customer-managed MFA inside RTO Grow itself is on the near-term roadmap.
We also don't yet publish a VPAT or run a public status page β both written down as gaps rather than quietly omitted. We do hold a written incident-response plan (contacts, containment, evidence, notification, post-mortem) and will share it on request; being straight about its maturity, it hasn't been exercised in a tabletop yet.
Tell us what your organisation runs, what your security team needs to see, and what has to connect. You'll get a straight answer about what works today, what we'd build, and what we can't do.