Trust

Privacy, security and Australian safeguards

Refera protects referral information with controls that practices can inspect, test and include in their own security review. This page explains those controls and links to the supporting detail.

  • Real-data build designed for Australian residency
  • Draft-first - nothing sent without human approval
  • Controls verified before live use
Start with the short version. See how Refera protects patient data in a clear, visual walkthrough.How your data is protected

Six promises

Six commitments you can verify

Each commitment maps to an enforced control or a control that must be proven before activation. Before any real referrals flow, the practice and Refera must execute a lawyer-reviewed data processing agreement.

Australian data residency

The licensed portal, API and pooled tenant store run in AWS Sydney, protected by explicit runtime and release-identity region denies; account-wide coverage is verified before live capture begins. The browser reaches portal.refera.au directly through an AWS load balancer to Refera's ECS/Fargate service. Real-referral Bedrock processing is not active and must pass published regional verification before use.

No clinical triage

Refera is administrative process-state software. Urgency is only ever the referrer's own words, quoted and attributed; attachments are noted, never interpreted. The extraction schema has no field a clinical judgement could occupy.

Draft-first, always

Nothing leaves Refera without a named staff member approving it. That approval step is also the error firewall: an extraction mistake cannot reach a GP or a record, because a person reviews every draft first.

No independent patient contact

No patient account or patient-facing Refera portal exists. Cancellation Fill can prepare generic appointment copy for an eligible record, but Refera never auto-sends or acts independently. Named practice staff approve and copy the draft, use their normal channel, then separately attest the offer and booking.

Export freedom

The authenticated workspace exports structured settings, referral records and available sealed events as tenant-scoped JSON, free at any time. Versioned, Object-Locked source-archive storage is deployed in AWS Sydney. Complete source retention, authenticated readback, restore, export and tenant-isolation proof must be proven before live capture begins.

Sealed audit trail

Every event is hash-chained and production writes use a server-held HMAC key. The current JSON export carries event content and chain heads but is not independently verifiable without a tenant-safe artifact; that artifact and any write-once anchor are not claimed as deployed.

The audit trail should become the practice's portable evidence. Refera's automated integrity checks are independently recomputable today. The deployed archive infrastructure does not activate a practice on its own. Complete source write, authenticated readback, restore, export and tenant-isolation proof must pass before real data.

Privacy Act 1988

The Australian Privacy Principles, mapped to controls

Health information is sensitive information under the Privacy Act 1988 (Cth). Refera's controls are designed to support practices' obligations under the Australian Privacy Principles and applicable state health-record laws. The table separates controls operating now from safeguards that must pass before real referral data can flow; a lawyer-reviewed data processing agreement is also required.

PrincipleRefera's control
APP 1 - open and transparent managementPublished privacy policy, a privacy impact assessment before launch naming every processor, and a nominated privacy contact.
APP 2 - anonymity and pseudonymityPatients deal with their practice, never with Refera. Identifiers remain available only where the referral workflow requires them; Refera does not claim a separate token vault.
APP 3 - collectionOnly what arrives in the referral the practice already receives, only on the practice's instruction - no enrichment, no other sources.
APP 4 - unsolicited informationThe locally tested HealthLink adapter holds and pages a synthetic message demonstrably addressed to another organisation before any downstream delivery or extraction; no live HealthLink receiver is enabled. Other real-data channels remain blocked until equivalent handling and a retention schedule are proven. No automated destruction is claimed today.
APP 5 - notificationThe practice's collection notice names Refera; template wording ships in the onboarding pack.
APP 6 - use and disclosureOne purpose only: the contracted service. No secondary use, no sale, no training AI on patient data, ever.
APP 7 - direct marketingNone. Patient information is never used for marketing. Cancellation Fill is a practice-controlled appointment administration workflow for explicit eligible records, with generic drafts, no automatic send and no independent Refera contact.
APP 8 - cross-border disclosureLicensed referral processing is pinned to AWS Sydney and verified in CloudTrail. Public website, onboarding and optional voice support contain business information only. Web voice names AI, recording and provider processing before any session or microphone request.
APP 9 - government identifiersMedicare and provider numbers are data on the referral, never Refera's own identifiers.
APP 10 - qualityThe workspace shows extracted fields beside a verbatim source excerpt and attachment metadata. Before live capture begins, source-document retention, authenticated retrieval, restore/readback and complete export must be proven end to end.
APP 11 - securityEncrypted pooled DynamoDB storage, tenant-partitioned access, server-held seal keys, no patient data in logs, and detection on before real data.
APP 11.2 - destructionAn authenticated owner can record an assisted closure request. Refera confirms export, deletion scope and applicable legal, security and backup retention before any removal; no browser action promises immediate deletion.
APP 12 - accessAccess requests go to the practice. Authenticated structured export is free at any time. Object-Locked source-archive storage is deployed in AWS Sydney; complete authenticated retrieval, restore and export are verified before live capture begins.
APP 13 - correctionCorrections are sealed as new events with the prior value preserved in append-only history, never quietly rewritten.

Beyond the APPs

State law, My Health Record and breaches

Three questions practices ask early, answered in a sentence each - and in full in the compliance guide.

State health-records law

Victoria, NSW and the ACT each add health-record privacy requirements. Refera's controls are designed to support those obligations; the applicable jurisdiction and the lawyer-reviewed agreement are confirmed with each practice before real referrals flow.

My Health Record

Refera does not connect to, read from or write to the My Health Record system, holds no My Health Record data, and has no registered role under the My Health Records Act 2012. The front door is the practice's own - a national repository is not part of it.

If a breach ever happens

A written plan under the Notifiable Data Breaches scheme: contain and escalate immediately, assess within the statutory ceiling, and notify the OAIC and individuals as the Privacy Act requires. Affected practices receive an initial notice on the counsel-approved clock in the executed DPA; no fixed public timing is active until that allocation is agreed.

Sub-processors

Current sub-processors

This public register identifies current and planned providers. Before real referrals flow, the executed lawyer-reviewed data processing agreement must name the permitted scope and the process for any change.

Sub-processorLocation and scopeWhat it sees
Amazon Web ServicesDesigned for Sydney (ap-southeast-2), region-pinned by policy before real dataAll platform infrastructure - compute, database, storage, keys, logs. AWS publishes ISO/IEC 27001, 27017, 27018 and 27701 coverage for its in-scope services; those certifications belong to AWS, not Refera.
Amazon Bedrock (within AWS)Planned Sydney endpoint using direct single-region invocation, unless an exact AU-only inference profile is later evidenced and activatedAfter activation only, raw referral text and a required image may be processed synchronously by a pinned Bedrock model. Exact retention, provider access and destination regions must be evidenced before activation. No real referral data is sent today.
CloudflareGlobal edge networkPublic website, docs, status, analytics, business-only onboarding/authentication relays, dedicated business billing API and private automated release checks. Billing requests may contain practice identity, plan, cycle, subscription and invoice context, but no referral or patient material. Cloudflare holds a DNS-only record for the licensed referral API; it does not proxy that traffic, which terminates at the AWS load balancer.
StripeGlobal payment platformBusiness identity, subscription, invoice and payment information. No referral or patient material.
ResendTransactional email deliveryAccount, agreement and sign-in email plus authorised Refera post-guard voice follow-up email. Voice email contains only fixed generic intent and limited call metadata, never raw transcript, free-text summary or caller name. No referral content.
Attio (retired)Former business CRM; no new eventsHistorical business-only contact and lifecycle records may remain until provider-confirmed export, closure and deletion evidence is complete. No assistant or voice transcript, referral or patient material was permitted. Refera does not treat cancellation of the paid plan as deletion evidence.
OpenRouterPublic/support model gatewayBounded product-request category, trusted Refera documentation extracts and bounded support-state enums/counts only. No visitor-authored question or history, contact or practice identity, arbitrary page context, referral or patient material. It is not used to summarise or persist conversations.
SlackBusiness follow-up and operational notificationsExplicit business contact and practice metadata for requested follow-up, business signup and billing state, bounded voice intent, and platform or release-health alerts. Cloudflare D1 holds the durable business-event and delivery-state record. Assistant questions and replies, raw voice audio and transcript, free-text provider summaries, referral and patient material are prohibited.
ElevenLabsProvider-operated AI voice infrastructureBusiness sales and support audio is temporarily saved by ElevenLabs after explicit disclosure and consent so the privacy-filtered summary and required notifications can complete. Refera targets deletion of the provider conversation within four hours after required delivery and verifies absence. Provider retention is capped at one day as a fail-safe; under the provider's policy, deleted data may remain in backups for up to 30 days. Refera does not copy or retain raw audio or transcript. ElevenLabs publishes ISO/IEC 27001 and SOC 2 Type II assurance; those provider assurances belong to ElevenLabs, not Refera. No patient, referral or clinical information.
TwilioRetained fallback telephone carrierBusiness call audio and routing metadata for sales and product support only. This is not a patient or referral line.
TelnyxCandidate customer-visible business telephone carrierBusiness call audio and routing metadata for sales and product support only. Use begins only after Refera verifies and publishes the active line. This is not a patient or referral line.
Browser push providersApple, Google, Mozilla or Microsoft delivery infrastructureAn optional browser subscription endpoint, delivery timing and an encrypted generic count-only payload. No patient, referrer, referral, practice or clinical content.
Referral data stays on the approved AWS path. Business, billing and support providers are not permitted to receive referral or patient material. Voice starts only after consent and microphone approval; Refera keeps the requested business summary, not a copy of the raw audio or transcript.
Text assistant capture is metadata-only. Cloudflare D1 may retain an explicit business contact name, work email, practice details and one bounded request category; Slack may receive the matching follow-up card. Neither receives the assistant question, reply, conversation history or an AI-generated summary. Attio is retired and receives no new events.
Twilio remains the fallback carrier. Telnyx is the candidate carrier for a customer-visible business line, shown only after Refera verifies and publishes the active line. The practice contracts its own mailbox and fax-to-email providers directly.

Updates and rollback

Kept current without interrupting the practice

Refera is cloud-managed, so updates happen centrally. Every release must preserve the no-triage boundary, the data wall and the practice's working day.

Security fixes first

Validated security fixes are patched the same day where possible. Interface improvements are grouped so practices are not interrupted by constant churn.

Every release is verified

Product, security, accessibility, desktop and mobile checks must pass before release. Live health checks then confirm the site, documentation, sign-in and workspace are responding correctly.

Rollback is built in

Public and documentation surfaces use versioned edge deployments; the licensed portal and API use health-checked ECS task revisions and can return to the previous proven revision.

One verified update path. The web app and installed PWA are the supported update path today. The iOS and Android wrappers remain unpublished until connected native authentication, AWS APNs/FCM delivery, signing and real-device release evidence pass the same standard.

Security roadmap

Built to a published bar

Security at Refera is engineering, not badges: a public roadmap of controls, each one landing before the data that needs it.

Today - account-first setup. New practices enter the connected workspace with capture off. Public product visuals use fictional examples and contain no patient information. Real patient data flows only after the connection and service checks pass.
At launch - required safeguards. Essential Eight alignment engineered to the published bar, an independent penetration test, a privacy impact assessment, executed data processing agreements, insurance, and TGA-experienced counsel signing off the intended-purpose statement.
At growth - ISO 27001. Certification of the management system joins the roadmap as the team and customer base grow.
Government and hospital work - IRAP. Assessed when a contract calls for it.
Certificates link to certificates. When a rung on this roadmap is independently certified, this page links to the certificate itself - every claim here stays verifiable, never decorative.