Industries · Health
We build clinical software ourselves. That changes the conversation.
Aurii, our own clinical-software venture, runs on Azure in Australia. Health obligations are our daily work, not a checklist we read once.
Health information is sensitive information under the Australian Privacy Principles, and everything around it is held to a higher bar: who can see a record, where it is stored, and whether the trail would survive scrutiny. Software that touches clinical work inherits all of it.
We carry those obligations in our own product. Aurii, our clinical-software venture, runs on Azure in the Australia East region: Container Apps, PostgreSQL with row-level security isolating tenant health data, Key Vault for secrets, and tamper-evident audit trails throughout. We build for clients to the same standard.
What you carry, and what we do about it.
Health records are sensitive information under the APPs: collection, use, and disclosure all sit at the strictest end of the Privacy Act.
We map the data you hold and where it lives, review the gaps against the Australian Privacy Principles, and leave you ready for the 2026 Privacy Act reforms.
Privacy Act / APP upliftClinical software carries clinical-grade obligations: access discipline, auditability, and data that never leaks across tenants.
We build it ourselves. Aurii isolates tenant health data with PostgreSQL row-level security and keeps tamper-evident audit trails throughout, and client builds get the same architecture.
See the Aurii buildWhere the data lives matters: Australian health data is expected to stay in Australian regions, and you will be asked to prove it.
We architect and run on Azure in Australian regions, on the stack we operate in production: Container Apps, PostgreSQL, Key Vault, and delivery pipelines with secrets kept out of code.
Cloud engineering on AzureWhen something goes wrong the questions are immediate: who touched the record, when, and would you even see an attack underway?
We review your logging and alerting coverage, write an incident response playbook your team can run, and pressure-test it with a tabletop exercise.
Detection & response advisory
The obligations in play
- Privacy Act 1988, health information
- Health information is sensitive information under the APPs, with a higher bar for collection, use, and disclosure.
- Notifiable Data Breaches scheme
- Breaches likely to cause serious harm must be assessed and notified to the OAIC and affected individuals.
- State health-records regimes
- New South Wales and Victoria layer their own health-privacy statutes over the Commonwealth regime.
- My Health Records Act 2012
- Additional obligations apply where systems connect to My Health Record.
This list orients the engineering work. It is not legal advice; your advisers own the interpretation.
The build behind this page
Aurii
Our own clinical-software venture: voice-driven clinical notes, letters, and billing for Australian private-hospital specialists. Built end to end by Black Shard on Azure in the Australia East region, with row-level security on tenant data and tamper-evident audit trails.
See the workThe services behind this page.
Software engineering
Engineering for the systems a business runs on: web, native mobile, portals, and the platform underneath.
Read more
Compliance readiness
Get audit-ready against the frameworks Australian businesses are actually asked for.
Read more
Secure development
Line-level code review, threat modelling, and security architecture from a team that ships production code.
Read more
Build clinical software you can defend.
Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

