
Security
Your patients' data is sacred. We treat it that way.
Security is built into every layer of SimpleRef. Focus on patient care, not IT.
Your records are hosted in Australia
Your patient and practice records are hosted on Australian servers, in Sydney. Two things are handled outside Australia, and we'd rather you heard it here than found it later. Stripe processes payments (billing details only — never clinical records). And when your team uploads a referral to AI Intake, that document is sent to Google's AI service for extraction, which is not hosted in Australia. AI Intake is included in every plan. Nothing is sent to Google unless someone uploads a document to it. If that trade-off isn't right for your practice, don't upload anything to AI Intake — no clinical document is sent to Google unless someone uploads it. Full detail in our Privacy Policy.
Only your team can see your data
Each practice's data sits in its own tenant, and server-side security rules check every read and write against the practice the signed-in user belongs to. Staff see only what their role allows, so admins, staff, and doctors each have appropriate access. You can also add multi-factor authentication for extra protection.
Everything is encrypted
Your data is encrypted when it is stored and when it is sent between your browser and our servers. Industry-standard encryption protects your information at every step.
Every action is logged
A full audit trail records who did what and when. A daily security digest reports on a defined set of rules — repeated failed logins, permission changes and similar events — so unusual activity is reviewed rather than discovered later. It gives you a record you can show when your practice is asked how patient data is handled.
We back up your data daily
Backups run automatically, at least daily, to Australian storage. Your retention period is configurable. If something goes wrong, we restore from the most recent backup — talk to us about the recovery window your practice needs.
Enterprise-grade infrastructure
SimpleRef runs on Google Cloud in Sydney, so physical security, network protection and hardware redundancy are handled by the same infrastructure that runs Google's own services. We do not publish an uptime figure or offer an uptime guarantee — see our Terms of Service for what we do commit to.
Technical details for IT teams
Encryption
AES-256 encryption at rest. TLS 1.2+ for all data in transit. Application-level AES-256-GCM encryption for sensitive credentials and backup data.
Access Control
Five role-based access control (RBAC) levels: Super Admin, Admin, Staff, Shared Staff, and Doctor. TOTP-based multi-factor authentication. Automatic 3-hour idle session timeout.
Application Security
Token-bucket rate limiting on sensitive endpoints. Request idempotency guards on critical operations. Brute-force lockout on repeated failed sign-ins.
Tenant Isolation
Database-level tenant isolation. Every practice's records live under their own tenant path, and server-side Firestore security rules — not client code — authorise each read and write against the caller's tenant.
Infrastructure
Hosted on Australian infrastructure. Secure identity platform for authentication. Daily automated backups with configurable data retention policies.
Questions?
Have security questions?
We're happy to discuss our security practices in detail.
Get in Touch