Security & Compliance
Briefly. is built with security at its core. We protect your patient data with enterprise-grade encryption, mapped safeguards, and continuous automated monitoring.
Compliance & Assurance
Security controls mapped to healthcare data protection standards
Healthcare Privacy Safeguards
We implement administrative, physical, and technical controls designed around healthcare privacy and security standards to protect sensitive health information.
Business Associate Agreement
BAA available for all healthcare organizations. Clearly defines our responsibilities in protecting your patient data.
SOC 2 Type II
Our SOC 2 Type II independent assurance program is in progress across availability, confidentiality, and privacy controls.
Secure Data Residency
Data stored in your designated region with controls aligned to applicable healthcare privacy standards.
Purpose-Built for Clinicians
Patient data stored securely. Controls are mapped to applicable healthcare privacy standards.
Frequently Asked Questions
Where is my data stored?
Patient records are stored in your designated region (AU, NZ, US, or EU). Some backend processing — such as transcription and letter generation — uses secure providers under data protection agreements.
Is patient data used for model training?
No. Patient data is never sent to language models for training. Your clinical data is processed securely and never retained by third-party providers. Briefly processes your data to generate letters and then it is not used for any other purpose.
What privacy laws apply to my data?
Briefly Health Limited is registered in New Zealand. Your data is subject to the privacy laws applicable to your region. For Australian users, this includes the Privacy Act 1988 and all 13 Australian Privacy Principles. For NZ users, the Privacy Act 2020 applies.
Security Architecture
Multi-layered protection for your sensitive patient data
End-to-End Encryption
AES-256 encryption for data at rest and TLS 1.3 for data in transit. Industry-leading encryption standards protect every byte.
- AES-256-GCM encryption at rest
- TLS 1.3 for all network communication
- Encrypted database backups, purged within 30 days of deletion
- Per-user envelope encryption with rotating keys
Secure Data Storage
Briefly is a 30-day processing workspace, not your medical record. Letters are deleted from Briefly after 30 days. Export to file them in your practice’s record system.
- Access-controlled storage, scoped to your practice
- Automatic deletion of recordings and letters after 30 days
- Convenience export in PDF, DOCX, and JSON for filing in your own system
- Immutable audit logs
Access Controls
Role-based access control (RBAC) and multi-factor authentication (MFA) ensure only authorized access.
- Mandatory MFA for all accounts
- Role-based permissions (RBAC)
- Single Sign-On (SSO) support
- Session management and timeout
Continuous Monitoring
Continuous automated monitoring with anomaly alerting and immutable audit-trail review.
- Continuous error and uptime monitoring (Sentry, UptimeRobot)
- Anomaly alerts to engineering on call
- Immutable audit log of every data access
- Annual independent security review (planned for first audit cycle)
Infrastructure & Operations
Enterprise infrastructure with healthcare-grade reliability
Cloud Infrastructure
Hosted on AWS-backed infrastructure (via Vercel and Supabase) in regional data centres. Multi-region availability for US/EU on enterprise plans.
Zero Data Training
Your patient data is never used for model training. Complete data isolation guaranteed.
Audit Logging
Immutable audit trails for all system access and data modifications. Audit-ready traceability.
Incident Response
Documented incident response plan with prompt customer notification for security events.
Secure Development Practices
Security is embedded in every stage of our development process
Security Inquiries
Need detailed security documentation, want to report a vulnerability, or have questions about our compliance?
We take security reports seriously and respond promptly.
For enterprise security documentation:
Request our security whitepaper, SOC 2 report, penetration test results, or Business Associate Agreement.
For vulnerability disclosure:
We welcome responsible disclosure. Security researchers who report valid vulnerabilities will be acknowledged in our security hall of fame.