How aurii secures and stores clinical data
Production runs in Azure Australia East. Black Shard Pty Ltd, which builds and hosts aurii, is certified to SMB1001:2026 Gold by CyberCert.
Data residency
aurii runs on Microsoft Azure. Australia East, in Sydney, is the primary region. Every production resource holding clinical data runs there.
Encryption and key handling
Connections use TLS. At rest, Azure platform encryption covers every database and storage account holding clinical data, including notes, letters, transcripts and audio.
The audit chain
Every action is written to the audit log with the user account, the record and the timestamp.
- Each row stores a hash computed from the previous row's hash and a summary of the row, so the rows form one chain per practice. A per-practice write lock stops two actions forking it.
- The application's database role holds no update or delete permission on the audit log.
- An administrator re-computes the chain from the audit integrity page, and a scheduled job re-verifies it nightly. Any row altered, reordered or removed breaks every hash after it, and alerts fire on the break or a failed run.
- Nothing in aurii deletes the audit log. The seven-year record-keeping obligation sits with the practice, and account deletion runs on request.
Access and authentication
Access is scoped to the practice. Each membership carries one of four roles: owner, administrator, doctor and read only.
Row-level security in the database
Clinical tables enforce row-level security on the practice identifier, under a least-privilege application role. A query not scoped to one practice returns no rows.
Passkeys and one-time codes
Multi-factor authentication is required on every account, enforced at the edge before any clinical surface loads. aurii supports passkeys over WebAuthn and time-based one-time codes, with backup codes.
Vendor access
Backup and recovery
Database backups are retained for 35 days and replicated to Australia Southeast.
Incident response
- A suspected incident goes straight to the engineers who build and run aurii.
- Mail to hello@aurii.com.au and scheduled calls, on Australian business hours.
- Suspected exposure of patient identifiers is escalated to a director within 30 minutes. The director decides whether the breach is notifiable.
- If a breach is likely to result in serious harm, aurii notifies affected practices and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme. Where a breach is suspected, the Privacy Act 1988 allows 30 days for the assessment, as the privacy policy states.
- Report a security weakness to hello@aurii.com.au.
Certifications and frameworks
- Australian data residency Sydney primary, Melbourne backupsPlatform control · Aurii Pty Ltd
Patient records, files and backups are stored in Microsoft Azure Australia East, in Sydney, with backups in Australia Southeast, in Melbourne.
- AES-256 at rest · TLS 1.2+ in transit EncryptionPlatform control · Aurii Pty Ltd
Every database and file store holding clinical data is encrypted at rest with AES-256. Connections accept TLS 1.2 and 1.3, and older versions are refused.
- Multi-factor authentication on every account PasskeysPlatform control · Aurii Pty Ltd
A second factor is required before any clinical screen loads: a passkey over WebAuthn, or a one-time code.
- Australian Privacy Principles Privacy Act 1988 (Cth): designed to complySelf-assessed · Aurii Pty Ltd
Self-assessed against the 13 Australian Privacy Principles, 11 October 2026.
Principle by principle - Notifiable Data Breaches scheme ready Privacy Act 1988 (Cth), Part IIICSelf-assessed · Aurii Pty Ltd
Self-assessed against Part IIIC of the Privacy Act 1988 (Cth), 11 October 2026: escalation within 30 minutes, assessment within 30 days, notification where serious harm is likely.
Data breaches - HIPAA-aligned safeguards HIPAA Security RuleSelf-assessed · Aurii Pty Ltd
Self-assessed against the technical safeguards of the HIPAA Security Rule, 11 October 2026: unique user identity, multi-factor sign-in, session expiry, audit controls, integrity checks and encryption.
- GDPR-aligned Articles 5, 25, 28 and 32Self-assessed · Aurii Pty Ltd
Self-assessed against GDPR Articles 5, 25, 28 and 32, 11 October 2026. The data processing agreement is provided on request.
Request the agreement - Aligned with the NZ Health Information Privacy Code 2020 New ZealandSelf-assessed · Aurii Pty Ltd
Self-assessed against the 13 rules of the Health Information Privacy Code 2020 (New Zealand), 11 October 2026.
- SMB1001:2026 Gold Black Shard Pty Ltd · Certified by CyberCertHeld by Black Shard Pty Ltd
Black Shard Pty Ltd, which builds, hosts and secures aurii, is certified to SMB1001:2026 Gold (Level 3) by CyberCert, valid to June 2027.
View on Black Shard - Essential Eight Maturity Level 3 Black Shard Pty LtdHeld by Black Shard Pty Ltd
Black Shard Pty Ltd, which builds and hosts aurii, runs its own systems at Essential Eight Maturity Level 3, assessed September 2026.
View on Black Shard - Hosted on Microsoft Azure IRAP PROTECTED, ISO/IEC 27001, SOC 2 · held by MicrosoftHeld by Microsoft
Microsoft Azure, aurii's hosting platform, holds IRAP assessment to PROTECTED, ISO/IEC 27001, 27017 and 27018, SOC 1, 2 and 3, and CSA STAR. Held by Microsoft.
Microsoft's IRAP assessment - Medical Objects secure messaging HL7 v2 over mutual TLSLive integration
Signed letters reach the recipient's clinical software as HL7 v2 over mutual TLS, and the delivery acknowledgement returns to the letter in aurii.
Integrations
Hospital evaluation pack: hospital overview, subprocessor list, Australian Privacy Principles mapping, clinical safety position, data processing agreement and audit trail walkthrough.
Sending this to your IT team?
Leave your email and we'll send the data processing agreement and the security answers procurement asks for.