Your patient data, protected

Where your patient data goes, in plain English.

A clear view of where referral data is stored, how it is encrypted and which providers support the service.

  • Refera-controlled platform copies stay in Australia
  • Encrypted in transit and at rest
  • Referral data is not used to train base models
  • Every source channel stays visible
Refera-controlled storage and planned AI processing stay in Australia Refera-controlled storage and planned AI processing are shown inside Australia. Original mailbox and source-system copies remain governed by the practice's providers and configuration. Sydney, Australia

Encryption

Protected while it moves and while it is stored.

Refera uses encrypted transport for its network connections and encryption at rest for the referral data it stores. Its authorised service processes referral content only to provide capture, display and extraction.

While it moves
The Refera portal requires HTTPS. Approved connector traffic to Microsoft Graph, Gmail, TLS-only IMAP and AWS uses encrypted TLS transport; the public web edge accepts TLS 1.2 and TLS 1.3.
While it is stored
Referral records are protected by AWS server-side encryption in Sydney. DynamoDB encryption uses AWS Key Management Service, and stored source objects use AES-256 server-side encryption.
Before Refera receives it
The original sender-to-mailbox route remains governed by the practice's email provider. Refera records the source channel so the practice can see how each referral arrived.

Source matters. Microsoft 365, Gmail and IMAP protect the connection into Refera. HealthLink provides its own secure-messaging transport. Refera keeps that source visible on the referral record.

HealthLink secure messaging

Protected clinical-message transport

HealthLink states that messages are encrypted, delivery is acknowledged and email is not used for clinical-document transfer. Refera preserves HealthLink as the source channel; it does not relabel that transport as email. HealthLink's description.

Mailbox capture

Scoped mailbox connection

Refera can restrict access to one referral mailbox and encrypt the connection, processing and storage. The practice remains in control of which inbound channels it accepts.

Point 1 of 7

Refera's platform copies stay in Australia

Refera stores its platform copies in Amazon Web Services in Sydney. When Bedrock processing is enabled, it is restricted to approved AWS regions in Australia. The practice's original mailbox remains subject to its own provider settings.

Refera storage: AWS Sydney. Bedrock processing: approved Australian regions only.

Refera storage and approved AI processing inside Australia An outline of Australia containing two labelled boxes - Storage and AI - with storage pinned to Sydney and both inside the Australian boundary. Storage AI Sydney

Refera storage is pinned to Sydney; Bedrock processing is restricted to approved Australian regions.

Point 2 of 7

AI processing stays in approved Australian AWS regions

Refera's extraction path uses Amazon Bedrock in approved AWS regions in Australia. It is enabled for real referrals only after the document, residency and human-review controls pass their tests.

The same governed path applies to typed, scanned and handwritten referrals.

The reviewed Bedrock path stays inside the Australian boundary A boxed area labelled Australian AWS. Inside it, the planned referral path goes to Amazon Bedrock and back. A line to a public chatbot is crossed out. Approved Australian AWS region Referral Amazon Bedrock public chatbot not sent here

The extraction path stays inside the approved Australian AWS boundary.

Point 3 of 7

Referral data is not used to train base models

AWS states that Bedrock prompts and responses are not used to train base models or shared with model providers. AWS remains Refera's disclosed cloud service provider.

No base-model training. No model-provider access.

Referral content is not used to train a base model The reviewed path produces an answer while the route into a training library is blocked and model-provider access is denied. Referral AI Answer train a model model provider denied

The Bedrock path blocks base-model training and model-provider access.

Point 4 of 7

Refera's data plane is region-restricted

Infrastructure policy denies Refera storage and approved AI service actions outside Australian AWS regions. This protects the platform copies Refera controls.

Offshore service actions are denied and checked again before activation.

A region lock keeps data inside Australia An outline of Australia with a locked border. An arrow trying to leave the country is stopped at the border and stamped Denied. A closed padlock sits on the border. your data DENIED

An attempted offshore action is refused by infrastructure policy.

Point 5 of 7

Controls leave evidence

CloudTrail records covered AWS control activity, Refera seals product actions in the Ledger and an automated check verifies the deployed residency policy.

Infrastructure enforced. Activity logged. Product actions sealed.

Enforced, logged, audited and re-provable A shield beside three checks: product actions are sealed, covered AWS activity is recorded, and residency can be re-proven. Detection and paging must be verified before live capture starts. Product actions sealed tamper-evident ledger AWS activity recorded covered CloudTrail events Residency re-proven automated check, on demand PASS

The region policy, AWS activity and product actions can all be checked again.

Point 6 of 7

Designed around Australian privacy obligations

Refera maps its controls to the Australian Privacy Principles under the Privacy Act 1988. AWS publishes ISO/IEC 27001, 27017, 27018 and 27701 certification coverage for in-scope services. Refera's own ISO 27001 certification remains on the roadmap.

Australian privacy standards and certification status Three badges. First, controls mapped to the Privacy Act 1988 and Australian Privacy Principles. Second, AWS publishes ISO certification coverage for in-scope infrastructure. Third, Refera's own ISO 27001 is on the roadmap and not yet held. Privacy Act 1988 and the APPs AWS: ISO 27001 certified Refera: ISO 27001 on the roadmap

Provider certifications and Refera's own certification status are shown separately.

Point 7 of 7

Encryption that stands up to scrutiny

Stored source objects use AES-256 server-side encryption. Referral records in DynamoDB use AWS Key Management Service encryption at rest. Access requires an authorised service role and is recorded for audit.

AES-256 object encryption. AWS KMS-backed records. Scoped, auditable access.

Layered encryption at rest A source document protected by AES-256 and a database protected by AWS Key Management Service, both behind a scoped access lock and an audit trail. AES-256 Source object DynamoDB + KMS Scoped role encrypted · authorised · auditable

Source objects and structured records use separate encryption controls behind scoped access.

Summary

The protection model at a glance

The controls that matter most to a practice.

  • Refera copies stay in Australia. Storage is in AWS Sydney; activated Bedrock processing is restricted to approved Australian regions.
  • AI stays in Australia. Bedrock processing is restricted to approved Australian AWS regions.
  • No base-model training. Bedrock prompts and responses are not used to train base models.
  • Offshore actions denied. A region policy restricts Refera's controlled data services to Australia.
  • Controls are auditable. Covered AWS activity is recorded, product actions are sealed and residency can be re-checked.
  • Standards are clear. AWS certifications and Refera's own certification roadmap are identified separately.
  • Encrypted at rest and in transit. Refera publishes the transport, storage and access controls it uses.

Need the procurement detail? The Trust centre and data-residency guide cover providers, regions and control evidence.