Enterprise-grade.
Hosted in your country.
Built with the seriousness a medical platform demands. Compliance, sovereignty, and uptime aren't features, they're the floor.
Patient data is hosted
in the clinic's country.
Australian clinics are hosted on sovereign Australian infrastructure. United States clinics on US-based infrastructure. UK clinics on UK-based infrastructure. Logs, backups, recordings and transcripts are stored in the same country. The region is fixed at clinic provisioning and cannot be moved without an explicit data-migration request from the customer.
When we run vendor processors (telephony carriers, payment processors), they are bound by contract to the same residency requirement. We will not engage a vendor that cannot meet the customer's country. Hosting location settles where data sits; who can access it, how long it is kept and how it is encrypted are separate controls, set out below.
See our Privacy Policy for the detailed APP statement.
The frameworks we operate against.
Australian Privacy Act 1988 (Cth): including the Australian Privacy Principles and the Notifiable Data Breaches scheme.
HIPAA, for customers in the United States. Business Associate Agreements signed before any covered data is processed.
UK GDPR / EU GDPR, for customers in the UK and EU, with Standard Contractual Clauses where applicable.
The floor, in specifics.
Encryption
In transit and at rest
TLS 1.2+ for all network traffic. AES-256 for data at rest. No data leaves a managed boundary without encryption.
Access control
Least privilege by default
Role-based access; MFA enforced on every administrative account. Audit log of every access and every change.
Network
Private by default
Services run in private subnets. Public endpoints are limited, rate-limited and WAF-protected.
Monitoring
Continuous and reviewed
Logging, anomaly detection, and on-call response. Security review of operational events at least weekly.
Backup & recovery
Tested, not assumed
Encrypted backups with point-in-time recovery. Restoration tested quarterly against the runbook.
Vulnerability management
Patch, scan, test
Automated dependency scanning, infrastructure scanning, and annual independent penetration testing.
What happens if something goes wrong.
We run a documented incident response playbook with on-call coverage. If a notifiable data breach occurs, we notify the affected clinic within 24 hours and meet the obligations of Part IIIC of the Privacy Act 1988 (Cth) for notification to affected individuals and to the OAIC.
Customers can report a security concern through our contact form. Responsible disclosure: see the policy in the response we send.
What procurement asks.
Where is patient data hosted?+
Is our data used to train AI models?+
Is Triagents HIPAA compliant?+
How is patient data encrypted?+
What happens if there is a data breach?+
Does Triagents make any clinical decisions?+
From the blog
What we are learning, written down.
- What can AI agents actually do in radiology?Not AI reading scans. What an AI agent actually does across reception, booking, referrals, capacity and follow-up, and what it must never touch.
- We called 100 radiology practices after hours. Here is what answered.Original research: the same 100 radiology practices, rung on Sunday evening. Not one reached a person, and eleven were answered by an AI agent.
- We called 100 radiology practices. Here is what we found.Original research: we rang 100 Australian radiology practices and timed every call. Eight reached a person straight away; the median wait was 90 seconds.
Book a radiology network assessment.
We'll map it to your network.
30 minutes with a solutions engineer. We model your call volume, centre count, and integrations, then show the AI agents running on your own scenarios, and answer everything compliance- and security-related upfront.