✦ For larger providers and enterprise clients

Enterprise requirements, answered by people who build it

Single sign-on with your own identity provider. Data that never leaves Australia. Integrations built for you rather than filed as a feature request. And a straight answer about what we don't have yet.

Identity and access

Your staff sign in with the account you already control

If your organisation runs Microsoft Entra ID, Google Workspace or Okta, RTO Grow connects to it. Your identity provider stays the source of truth for who works there β€” we never become a second, stale list of your people.

πŸ”

Single sign-on (SAML 2.0)

Available on request. Your IT sends us the metadata for your identity provider and we register it against your email domain β€” usually within a business day. Staff then get a "Continue with single sign-on" option on the login page.

πŸ›‘οΈ

Your MFA policy, not ours

When your staff sign in through single sign-on, your Conditional Access, MFA and device policies are enforced by your identity provider before they reach us β€” we never see a password or a second factor on that path. Single sign-on does not yet disable password sign-in: a staff member who also has an RTO Grow password can still use it. Ask us and we'll remove their password login so SSO is the only way in.

βœ‰οΈ

Invite-only, always

A valid company login that hasn't been invited into your workspace is refused: no workspace membership, no role, and no staff or student record is created. (Our authentication provider records the attempted identity, as any IdP-connected system does; it carries no access to anything.) Sign-in authenticates people; it never provisions them.

⏻

Off in one action

Disable someone in your identity provider and they can no longer sign in here (an existing session ends at token expiry β€” see the note below). Removing them from the workspace is immediate and severs every staff sign-in route at once, password and SSO together.

Scope, stated plainly: this covers staff logins. Students sign in with emailed magic links, which land in the corporate mailbox your own MFA already protects. Single logout (SLO) is not supported by our authentication provider β€” sessions are bounded by token lifetime and by workspace membership, which your administrators control.

Custom integrations

If we don't connect to it yet, that's a conversation, not a ticket

Most of what RTO Grow integrates with exists because a provider needed it. Payroll systems, employer portals, state funding platforms, your own website β€” the answer isn't "it's on the roadmap", it's a scope and a timeline.

1 Β· Tell us what it has to talk to

A call with the people who write the code β€” not an account manager relaying requirements to an offshore team. That's most of why this moves quickly.

2 Β· Scope back in days

You get a scope and a timeline within days, including an honest "this isn't worth building" when that's the real answer. You won't wait a quarter to find out whether it's possible.

3 Β· Built, reviewed, shipped

Every change is reviewed before release, and risky ones ship behind a feature flag we can switch off for your organisation without rolling back the release.

Reasonable customer-specific integration work is included on our high-volume plans, from $2,500 a month. On smaller plans it is scoped and quoted before anything starts β€” and the integrations already on the platform are never per-connector add-ons.

Where your data lives

In Australia β€” and we'll name every vendor that touches it

Application, database, files and email all run from Sydney. We don't sell your data and we don't use it to train AI models. The full subprocessor list is public on our integrations page rather than something you have to request under NDA.

See the full vendor list
Sydney.
Application, database, files, email

  • βœ“Database and file storage run on Supabase in AWS ap-southeast-2 (Sydney); Supabase publishes SOC 2 Type 2 and ISO 27001 reports β€” their certifications, covering the infrastructure underneath us, not a certification of RTO Grow
  • βœ“Transactional and bulk email via AWS SES in Sydney, with bounce and suppression handling
  • βœ“Every organisation's data is isolated at the database layer β€” enforced by the database itself, not just by application code
  • βœ“Append-only audit trails record every change to compliance-relevant records, including cross-organisation administrative actions
Procurement and due diligence

We answer the questionnaire. We don't stall it.

Security assessments are usually where small vendors go quiet for three weeks. Here you're talking to the people who can actually answer, and we'd rather tell you a gap up front than have your assessor find it.

  • βœ“Security and procurement documentation supplied on request, including how tenant isolation, audit trails and retention actually work β€” not marketing summaries
  • βœ“A written setup guide your IT team can follow to connect single sign-on, with our SAML endpoints and the exact attributes we need
  • βœ“One independently verifiable listing: we're on the NCVER AVETMISS Compliant Software Register (release 8.0, all states and territories) β€” check it without asking us. USI verification runs against the Australian Government's USI Registry System using its published web services
  • βœ“Full data export on any day you choose, in standard formats, guaranteed on exit as well as during the relationship

Working through a cyber assessment right now? Send us the questionnaire. We'll answer it directly, and flag anything we can't yet meet rather than wording around it.

Straight answers

What we don't have yet

Every vendor page tells you what it has. This is the other half. If one of these is a hard requirement for your organisation, tell us now β€” it's better for both of us than finding out at contract stage.

We are not ISO 27001 or SOC 2 certified

Our infrastructure provider is; we are not. We build to those controls β€” Australian hosting, database-enforced isolation, append-only audit trails, independent code review β€” but we will not imply a certificate we don't hold.

No scheduled penetration testing yet

Not on a formal cadence today. When a report exists we'll share it with customers under NDA. If your assessment requires one before signing, say so early and we'll talk about timing.

Multi-factor authentication for your own users is still coming

MFA is enforced today for RTO Grow staff on the administration surface. For your users, MFA arrives through your identity provider when you connect single sign-on β€” customer-managed MFA inside RTO Grow itself is on the near-term roadmap.

We also don't yet publish a VPAT or run a public status page β€” both written down as gaps rather than quietly omitted. We do hold a written incident-response plan (contacts, containment, evidence, notification, post-mortem) and will share it on request; being straight about its maturity, it hasn't been exercised in a tabletop yet.

Talk to us

Bring the hard questions

Tell us what your organisation runs, what your security team needs to see, and what has to connect. You'll get a straight answer about what works today, what we'd build, and what we can't do.

We'll respond within one business day. No spam, ever.