Santos Technology Santos Technology Pty Ltd
Menu
Start a conversation
Software and AI systems · Sydney, Australia

Building intelligent systems with precision, reliability and scale.

20+ systems delivered for more than 30 Australian businesses that demand accuracy, compliance and scalability. Built for organisations whose software carries a regulatory burden, and whose mistakes are notifiable.

Australian-hosted infrastructure Architected against the Privacy Act 1988 (Cth) WCAG 2.1 AA
SEC.01 // SECURITY

Security

Role based access, least privilege and MFA as defaults. Hardening aligned to the ACSC Essential Eight, with architecture referenced to ISO/IEC 27001.

posturehardened
mfaenforced
iso 27001referenced
PRF.02 // PERFORMANCE

Performance

Fast systems stay used. Sub second interactions, measured uptime, and infrastructure sized for the load you actually carry, not a demo load.

p95240 ms
uptimemeasured
capacityreal load
AUT.03 // AUTOMATION

Automation

AI assists where it is strongest: extraction, classification and drafting, with a human review layer and traceable outputs on anything that matters.

reviewhuman-in-loop
outputstraceable
scopeextract · classify
SCL.04 // SCALABILITY

Scalability

Built to grow without re platforming: more clients, more records, more jurisdictions, without the architecture becoming the constraint.

tenancyisolated
regionsmulti
replatformnot required
The work

Systems where the regulation is the requirement

Two platforms in production for regulated Australian sectors. Each was designed compliance first: the obligation shaped the architecture, not the other way around.

NDIS · Clinical operations

NDpro BSP, compliance as a by-product of normal work

A clinical operations platform for NDIS behaviour support: participant pathways, behaviour support plans, the restrictive practice and reportable incident register, workforce credentials, supervision and audit readiness. Every screen is a permission decision. Audit rows are written before sensitive data is served, so the evidence trail builds itself as practitioners work.

  • Three layer tenant isolation: signed JWT claims, Postgres row level security, deny by default object authorisation
  • Restrictive practice and incident register aligned to NDIS Commission reporting obligations
  • WCAG 2.1 AA enforced in the build pipeline, not audited after the fact
Health · Legal · Privacy

RedactDocs, de-identification with proof of what was covered

Medical record de-identification for sharing outside the circle of care. Patient identifiers are removed irreversibly, burned into the page rather than layered over live text, while clinicians' names stay legible so the document keeps its purpose. Every occurrence comes back in an audit report with page, position and classification.

  • Two independent detection layers, then adversarial verification that hunts for what escaped
  • Runs entirely on Australian soil. An architecture constraint, not a configuration
  • Surgical scope: the patient is de-identified, the clinical record stays useful
Next step

Have a workflow that has to survive an audit?

Tell us what it is. You'll get a considered reply from Ricardo within one business day.

Start a conversation
Services

What we build

Six offerings, one posture: understand the obligation first, then engineer the system. Engagements range from a focused advisory review to a full platform build.

Custom software development

Internal platforms, workflow systems and portals for organisations whose process doesn't fit off the shelf software, and never will.

Practice management Client portals Workflow engines

AI systems & automation

Document intelligence, extraction, classification and drafting assistance over your private corpus, with human review and traceable outputs built in rather than bolted on.

Retrieval over private corpora Human in the loop AI governance

Compliance-driven platforms

Systems where the regulatory obligation is the requirement: audit trails, retention schedules, consent handling and evidence of control as first class features.

APP 8 and 11 alignment NDB ready logging Defensible deletion

Web platforms & corporate websites

Fast, accessible, properly instrumented sites for professional firms who are judged on their digital front door. WCAG 2.1 AA as a floor, not an aspiration.

WCAG 2.1 AA Performance budgets Privacy respecting analytics

Systems integration & data migration

Connecting the tools you already run, and moving legacy data without losing lineage or breaking a retention obligation on the way through.

Legacy migration Data lineage API integration

Technical advisory

Architecture review, security posture and AI readiness assessments for boards and practice leaders who need a straight answer on risk.

Architecture review Security posture AI risk assessment
How we work

Obligation first, then architecture

Every engagement runs the same sequence. Skipping a step is how compliance software becomes a liability.

01

Map the obligations

Before any design, we identify what the law, the regulator and your contracts actually require of the system: Privacy Act, sector rules, retention schedules.

02

Design to the obligation

Architecture decisions follow from the obligations: data residency, access control, audit trails, where AI inference happens and what it may never touch.

03

Build with evidence

The system produces its own compliance evidence as it runs: logs you can hand to an auditor, not assemble in a panic after the fact.

04

Operate and harden

Deployment, monitoring and iteration against the ACSC Essential Eight, so the posture holds as the system and the threats evolve.

Start at stage 01

Two weeks inside your workflow, before anyone writes code.

You get a build plan, an accuracy baseline and a risk register — and you keep all three either way.

Start a conversation
The practice

Professional Engineering

Founder
Ricardo Santos, Founder and AI Systems Engineer at Santos Technology

Ricardo Santos

Founder & AI Systems Engineer

based
Sydney, NSW
entity
Santos Technology Pty Ltd
focus
Regulated sectors · AI systems
In his words

You work with the person who builds the system. There is no account layer, no handoff to a junior team, no telephone game between what you said and what got built.

I design and engineer software for organisations where accuracy isn't a preference: NDIS providers, legal and records teams, government contractors, and anyone handling sensitive personal information at volume. The work ranges from AI assisted document platforms to the compliance plumbing underneath them: audit trails, access control, data residency.

Staying small is the model, not a limitation. It means every system on this site was architected and built by the person you'll be emailing, and that person answers for it after launch.

No account managers No subcontracted build Accountable after launch
Start a conversation with Ricardo →
Contact

Start a conversation

Tell us what you're trying to build or fix. You'll get a considered reply from Ricardo within one business day, not an autoresponder.

A few sentences is plenty. Please don't include sensitive personal information in this form.

Or write directly: contact@santostech.com.au

Sending…

Thanks — your enquiry has been received. Ricardo will reply within one business day.

That didn't go through. Please email contact@santostech.com.au directly.

Sydney · founder-led Start a conversation