· Company · Triagents Team
Sovereignty by design: hosting and the Privacy Act
Patient data does not leave the country it was collected in. Here's how the platform enforces that — by infrastructure, not by promise.
The most frequent question we get from clinic directors isn’t about the AI — it’s about where the data lives. The answer is short: in the same jurisdiction as the clinic, on infrastructure that physically cannot cross borders.
The setup
- Australian clinics → sovereign Australian infrastructure
- United States clinics → US-based infrastructure
- United Kingdom clinics → UK or EU infrastructure
Each region runs an independent deployment. There is no central data plane. There is no “sync to primary”. Logs, backups, recordings, transcripts — all stay in-region.
Enforced by infrastructure
This isn’t a policy we ask engineers to remember. The deployments are operationally separate: isolated accounts, separate networks, separate trust boundaries. A service running in the Australian region does not have credentials to read from the US region and vice versa. There is no path by which an engineer could move data across regions even if they wanted to.
When a customer provisions a new clinic, the region is fixed at provisioning. To move it would require an explicit data-migration request that triggers a documented procedure with the customer’s consent at every step.
What the Privacy Act actually requires
Australian Privacy Principle 8 governs the cross-border disclosure of personal information. Healthcare information attracts particular scrutiny under the Notifiable Data Breaches scheme (Part IIIC). A practical, defensible implementation is to ensure cross-border flow simply cannot occur — which is what our infrastructure topology guarantees.
What about vendor processors?
Every processor that touches the data — telephony carriers, SMS providers, payment processors — is contractually bound to the same residency requirement, and we will not engage a vendor that cannot meet it. The list is short on purpose.