Skip to main content
Enterprise-Grade Security

Security & Compliance

Briefly. is built with security at its core. We protect your patient data with enterprise-grade encryption, mapped safeguards, and 24/7 monitoring.

Compliance & Assurance

Security controls mapped to healthcare data protection standards

In Progress

Healthcare Privacy Safeguards

We implement administrative, physical, and technical controls designed around healthcare privacy and security standards to protect sensitive health information.

Available

Business Associate Agreement

BAA available for all healthcare organizations. Clearly defines our responsibilities in protecting your patient data.

In Progress

SOC 2 Type II

Our SOC 2 Type II independent assurance program is in progress across availability, confidentiality, and privacy controls.

Active

Secure Data Residency

Data stored in your designated region with controls aligned to applicable healthcare privacy standards.

Healthcare Data Protection

Purpose-Built for Clinicians

Patient data stored securely. Controls are mapped to applicable healthcare privacy standards.

Healthcare Privacy Safeguards
No Patient Data in LLM Training
End-to-End Encryption
4 Regions
AU, NZ, US, EU
Zero
Patient Data in LLM Training
AES-256
Encryption Standard
30 Days
Auto Data Deletion

Frequently Asked Questions

Where is my data stored?

Patient records are stored in your designated region (AU, NZ, US, or EU). Some backend processing — such as transcription and letter generation — uses secure providers under data protection agreements.

Is patient data used for model training?

No. Patient data is never sent to language models for training. Your clinical data is processed securely and never retained by third-party providers. Briefly processes your data to generate letters and then it is not used for any other purpose.

What privacy laws apply to my data?

Briefly Health Limited is registered in New Zealand. Your data is subject to the privacy laws applicable to your region. For Australian users, this includes the Privacy Act 1988 and all 13 Australian Privacy Principles. For NZ users, the Privacy Act 2020 applies.

Security Architecture

Multi-layered protection for your sensitive patient data

End-to-End Encryption

AES-256 encryption for data at rest and TLS 1.3 for data in transit. Industry-leading encryption standards protect every byte.

  • AES-256-GCM encryption at rest
  • TLS 1.3 for all network communication
  • Encrypted database backups
  • Hardware Security Modules (HSM) for key management

Secure Data Storage

Multi-layered data protection with regular backups, disaster recovery, and 99.9% uptime SLA.

  • Automated daily encrypted backups
  • Point-in-time recovery capability
  • Multi-region disaster recovery
  • Immutable audit logs

Access Controls

Role-based access control (RBAC) and multi-factor authentication (MFA) ensure only authorized access.

  • Mandatory MFA for all accounts
  • Role-based permissions (RBAC)
  • Single Sign-On (SSO) support
  • Session management and timeout

Continuous Monitoring

24/7 security monitoring with real-time threat detection and automated incident response.

  • 24/7 security operations center
  • Real-time intrusion detection
  • Automated threat response
  • Quarterly penetration testing

Infrastructure & Operations

Enterprise infrastructure with healthcare-grade reliability

Cloud Infrastructure

Hosted on AWS with enterprise-grade security across multiple regions (AU, NZ, US, EU).

Zero Data Training

Your patient data is never used for model training. Complete data isolation guaranteed.

Audit Logging

Immutable audit trails for all system access and data modifications. Audit-ready traceability.

Incident Response

Documented incident response plan with <1 hour notification SLA for security events.

Secure Development Practices

Security is embedded in every stage of our development process

Secure Software Development Lifecycle (SSDLC)
Regular third-party security audits
Automated vulnerability scanning
Code review and static analysis
Dependency security monitoring
Regular security training for all staff
Responsible disclosure program
Annual penetration testing
256-bit
AES Encryption
99.9%
Uptime SLA
24/7
Security Monitoring
0
Data Breaches

Security Inquiries

Need detailed security documentation, want to report a vulnerability, or have questions about our compliance?

Contact Our Security Team
security@briefly.health

We take security reports seriously and respond promptly.

For enterprise security documentation:
Request our security whitepaper, SOC 2 report, penetration test results, or Business Associate Agreement.

For vulnerability disclosure:
We welcome responsible disclosure. Security researchers who report valid vulnerabilities will be acknowledged in our security hall of fame.