Sovereignty

Patient data is hosted
in the clinic's country.

Australian clinics are hosted on sovereign Australian infrastructure. United States clinics on US-based infrastructure. UK clinics on UK-based infrastructure. Logs, backups, recordings and transcripts are stored in the same country. The region is fixed at clinic provisioning and cannot be moved without an explicit data-migration request from the customer.

When we run vendor processors (telephony carriers, payment processors), they are bound by contract to the same residency requirement. We will not engage a vendor that cannot meet the customer's country. Hosting location settles where data sits; who can access it, how long it is kept and how it is encrypted are separate controls, set out below.

See our Privacy Policy for the detailed APP statement.

Compliance

The frameworks we operate against.

Australian Privacy Act 1988 (Cth): including the Australian Privacy Principles and the Notifiable Data Breaches scheme.

HIPAA, for customers in the United States. Business Associate Agreements signed before any covered data is processed.

UK GDPR / EU GDPR, for customers in the UK and EU, with Standard Contractual Clauses where applicable.

Controls

The floor, in specifics.

Encryption

In transit and at rest

TLS 1.2+ for all network traffic. AES-256 for data at rest. No data leaves a managed boundary without encryption.

Access control

Least privilege by default

Role-based access; MFA enforced on every administrative account. Audit log of every access and every change.

Network

Private by default

Services run in private subnets. Public endpoints are limited, rate-limited and WAF-protected.

Monitoring

Continuous and reviewed

Logging, anomaly detection, and on-call response. Security review of operational events at least weekly.

Backup & recovery

Tested, not assumed

Encrypted backups with point-in-time recovery. Restoration tested quarterly against the runbook.

Vulnerability management

Patch, scan, test

Automated dependency scanning, infrastructure scanning, and annual independent penetration testing.

Incident response

What happens if something goes wrong.

We run a documented incident response playbook with on-call coverage. If a notifiable data breach occurs, we notify the affected clinic within 24 hours and meet the obligations of Part IIIC of the Privacy Act 1988 (Cth) for notification to affected individuals and to the OAIC.

Customers can report a security concern through our contact form. Responsible disclosure: see the policy in the response we send.

Security FAQ

What procurement asks.

Where is patient data hosted?+
In the country the clinic operates in. Australian clinics are hosted on sovereign Australian infrastructure, United States clinics on US-based infrastructure, and UK clinics on UK-based infrastructure. Logs, backups, recordings and transcripts are stored in the same country. The region is fixed at clinic provisioning and cannot be moved without an explicit data-migration request from the customer. Vendor processors such as telephony carriers are bound by contract to the same residency requirement, and we will not engage one that cannot meet it. Hosting location is one control among several: access, retention, encryption and audit are set out separately below.
Is our data used to train AI models?+
Not without your prior written consent. Triagents does not use, and does not permit any third party including our AI service providers to use, Customer Data or any identifiable personal or health information to develop, improve or train the software or any AI model unless the customer has consented in writing. Aggregated, de-identified operational data, which does not identify and cannot reasonably be used to identify the clinic or any individual and contains no personal or health information, is used to provide analytics, reporting and benchmarking to the customer and to operate, secure and improve the software; without that, the reporting functions could not exist. Any consent given can be withdrawn by written notice with prospective effect.
Is Triagents HIPAA compliant?+
For customers in the United States, yes: we operate against HIPAA and sign a Business Associate Agreement before any covered data is processed. Australian customers are covered by the Privacy Act 1988 (Cth), including the Australian Privacy Principles and the Notifiable Data Breaches scheme. UK and EU customers are covered by UK GDPR and EU GDPR, with Standard Contractual Clauses where applicable.
How is patient data encrypted?+
TLS 1.2 or above for all network traffic and AES-256 for data at rest. No data leaves a managed boundary unencrypted. Access is role-based and least-privilege by default, MFA is enforced on every administrative account, and every access and every change is written to an audit log.
What happens if there is a data breach?+
We run a documented incident response playbook with on-call coverage. If a notifiable data breach occurs we notify the affected clinic within 24 hours and meet the obligations of Part IIIC of the Privacy Act 1988 (Cth) for notification to affected individuals and to the OAIC. Backups are encrypted with point-in-time recovery, and restoration is tested quarterly against the runbook rather than assumed to work.
Does Triagents make any clinical decisions?+
No. Triagents is strictly an administrative and operational layer: booking, intake, FAQs, routing and analytics. It does not diagnose, assess symptoms or make clinical decisions. When a call needs a clinician or a staff member, it transfers to a person with full context.
Get started

Book a radiology network assessment.
We'll map it to your network.

30 minutes with a solutions engineer. We model your call volume, centre count, and integrations, then show the AI agents running on your own scenarios, and answer everything compliance- and security-related upfront.