Evaluating the security of a health AI vendor

Each question carries the artefact to require in writing, and aurii's answer to it.

Written by the aurii team

Security answers belong in writing before a practice hands over consultation content, each with the artefact that evidences it.

A dimly lit data centre aisle running between rows of glass-fronted server cabinets under cool overhead lighting

Hosting and backups

Ask for the cloud regions holding primary storage and backups, when a restore was last run, and what was verified in the restored copy.

Australia East, in Sydney, is primary. Australia Southeast, in Melbourne, holds the geo-redundant backups and runs no compute. Where the data sits. A point-in-time restore ran on 5 September 2026 and the restored audit chains were verified end to end, with the output available on request to hello@aurii.com.au. Backup and recovery.

Encryption and key handling

Ask which fields carry application-layer encryption, which rely on platform encryption at rest, who holds the keys and in which country, and whether a rotation re-encrypts stored data.

Notes, letters, transcripts and audio rely on Azure platform encryption at rest in Australia East. Medicare numbers, Individual Healthcare Identifiers, multi-factor authentication secrets and prescriber credentials carry a second layer applied before the value reaches the database, each under its own data key wrapped by a key in Azure Key Vault, Australia East. Rotating the vault key rewraps the data keys and does not rewrite the encrypted values. How the keys are held.

Access logging and the audit trail

Ask which roles can reach patient content, including the vendor's own staff, what approval a support read requires, and whether a practice administrator can open a log whose entries cannot be altered after they are written.

Every action a practice user takes is written to a hash-chained audit log, and a practice administrator can recompute the chain: an altered entry breaks it. How the chain works. Changes made from the fleet-wide support console are written to the practice's own audit chain. Named accounts at aurii and at Black Shard hold fleet-wide access to production, and a practice cannot grant, extend or revoke that access. Vendor access.

Retention and deletion

Ask for the retention schedule and the deletion process as two documents, the period the software enforces on consult audio, and what survives a deletion request.

Consult audio carries a purge date 30 days after the session by default, and a daily sweep deletes it. Deletion runs on request. What is deleted and what the practice keeps.

Sub-processors and model training

Ask which companies sit in the path of consultation content, what each does, for the recipient's legal name, and for the contract clause covering training.

The sub-processor ledger lists each recipient by function. Your content is not used to train models. The drafting provider is named, with its contractual terms, in the data processing agreement supplied on request to hello@aurii.com.au.

Certification scope

Ask which legal entity holds each certificate, for its number, and for the scope statement. A certificate is issued to one company, and covers the product only where its scope says so.

SMB1001:2026 Gold (Level 3) is held by Black Shard Pty Ltd, which builds and runs the platform. Certifications and who holds them are listed on the trust page.

Breach notification

Ask what the vendor commits to notify, to whom, within how many hours, and where that commitment is written. Under the Notifiable Data Breaches scheme an eligible breach is notifiable to the Commissioner and to the affected individuals, and the obligation reaches the practice that holds the records.

Suspected exposure of patient identifiers is escalated to a director within 30 minutes. Where a breach is likely to result in serious harm, aurii notifies the affected practices and the Office of the Australian Information Commissioner. Where a breach is suspected and not established, the Privacy Act 1988 allows 30 days to complete the assessment, and aurii commits to no shorter window than the scheme sets. Incident response.

This is general information to help a practice evaluate vendors. It is not legal or security advice.

Start the free trial

Free 30-day trial. Create an account in the iPhone app or at app.aurii.com.au/signup. A card is added at signup on Stripe's checkout page; nothing is charged until the 30 days end.

hello@aurii.com.au