Trust you can
check yourself.
No badge here is decoration. Every one links to the proof.
Every trust claim aurii makes — what we hold, what we build on, and what the law requires of us — with a link you can follow to the source for each one.
Every claim, linked to proof.
Follow any link to the issuing registry, the platform's own trust page, or the standard itself.
SMB1001:2026 Gold (Level 3)
Held by Black Shard Pty Ltd, the company that builds, hosts and secures aurii. Certified by CyberCert.
View on Black ShardYour clinical data lives in Australia
Audio, transcripts, the drafted records and their backups are hosted and encrypted in Australian regions — primary in Sydney, backup in Melbourne — record by record in Australian Key Vault.
See the architecture The platform we build onMicrosoft Azure — Australian regions
Azure's infrastructure is IRAP-assessed to PROTECTED and holds ISO 27001 and SOC 2 at the platform level.
Microsoft's IRAP assessment The AI engineEnterprise AI provider
aurii's drafting runs on an enterprise AI provider. It drafts only from your dictation; a named specialist reviews and signs every output.
How drafting works PaymentsProcessed by Stripe
Subscription payments are processed by Stripe, a PCI-DSS Level 1 service provider. Card details are handled entirely by Stripe — aurii never stores them.
Stripe's security The law we answer toPrivacy Act 1988 & the APPs
aurii is built to align with the Australian Privacy Act 1988 and the 13 Australian Privacy Principles, handling health information as sensitive information. Our Privacy Policy maps to each principle.
The APPs at the OAIC InteroperabilityHL7 v2 & Medical Objects connectivity
aurii sends and receives clinical messages over HL7 v2, with Medical Objects connectivity for secure delivery to Australian practices — so letters and results reach the right inbox, not a fax.
How it connects Clinical governanceAligned with RACGP guidance
aurii is designed around the RACGP's guidance on AI scribes — the clinician always reviews and signs the note. It is a documentation tool, not a diagnostic device, and stays outside the TGA's definition of a regulated medical device.
RACGP on AI scribesWho can touch your data.
The short list of providers in the path of your clinical data, what each does, and where.
Stripe never sees clinical data; it processes payment details only. The full, current list and our data-handling detail are set out in the Privacy Policy.
Bring the questions
your IT team will ask.
We built aurii to answer them — and to let you check every answer for yourself.
hello@aurii.com.au · SYD primary // MEL backup // always doctor-signed