Security architecture, data handling, sub-processors, and documentation. Transparent and always up to date. See /standards for clinical regulatory mapping.
AES-256
Encryption
99.9%
Uptime SLA
Australia
Data Residency
72 hrs
Breach Notice
No PHI stored or processed
Moirai tracks governance metadata, not patient data. No Protected Health Information enters the platform.
Built to organise evidence against Australian healthcare obligations, with a clear path to independent security certifications.
Australian Privacy Act 1988
OAIC APP Guidelines
RANZCR Ch. 9 Aligned
AHPRA AI guidance
TGA SaMD requirements
Safety & Quality Commission AI Clinical Use Guide
NIST Cybersecurity Framework
ISO 27001
Recognised standards
Every layer of the Moirai stack is designed with security as a constraint, not an afterthought.
Your governance data stays under your control. We store only what is needed and give you full export and deletion capabilities.
All governance data stored in Sydney, Australia (ap-southeast-2). Full Australian jurisdictional control.
Full export of your data in JSON and CSV formats at any time. Your data is yours.
Configurable retention policies. Data preserved for 30 days after account cancellation.
Your governance data is never shared with third parties beyond essential service providers listed below.
A transparent list of third-party services that process data on behalf of your practice.
| Provider | Purpose |
|---|---|
| Database, authentication, storage | |
| Hosting, edge network, serverless functions | |
| Payment processing, subscription billing | |
Sentry | Error tracking, performance monitoring |
PostHog | Product analytics, feature flags |
Resend | Transactional email delivery |
| AI-generated governance content (no patient data sent) |
Security documentation for your due diligence review. Available documents can be accessed directly; others are available on request.
Covers data handling, sub-processors, breach notification, and data subject rights.
View documentHow we collect, use, and protect your information under Australian privacy law.
View documentService terms, acceptable use, liability, and dispute resolution.
View documentDetailed breakdown of our security architecture, controls, and practices.
Third-party penetration testing results and remediation summary.
Request accessPre-filled SIG Lite, CAIQ, and custom security questionnaire responses.
Request accessBuilt on infrastructure trusted by millions of production applications.
99.9%
Uptime SLA
All systems operational
Real-time status monitoring
View current system status, historical uptime, and subscribe to incident notifications on our status page.
Visit status pageInfrastructure powered by
Found a vulnerability? We take security reports seriously and respond to every submission. Please disclose responsibly by emailing our security team directly.
security@moirai.healthCommon questions from security and compliance teams during vendor review.
No. Moirai tracks governance metadata only. Which AI tools are used, who approved them, what policies are in place, and how decisions were documented. No Protected Health Information (PHI) enters the platform.
All governance data is stored in Sydney, Australia (ap-southeast-2) on Supabase managed Postgres. Your data stays under Australian jurisdictional control at all times.
Yes. You can export your complete governance dataset in JSON and CSV formats at any time from the Settings page. Your data is yours.
We maintain a 24-hour incident response SLA. Under the Notifiable Data Breaches scheme, affected practices are notified within 72 hours. Every incident is followed by a post-incident review and disclosure.
Yes. Our DPA covers data handling, sub-processors, breach notification, international transfers, data subject rights, and audit provisions. It's available at moirai.health/legal/dpa.
Moirai is designed to support obligations under the Australian Privacy Act 1988 and OAIC Australian Privacy Principles. Clinical AI governance evidence is mapped against RANZCR Chapter 9, Ahpra AI guidance, TGA SaMD requirements, and the Safety & Quality Commission AI Clinical Use Guide. NIST CSF and ISO 27001 are on our roadmap.
Security questionnaire responses, penetration test summary, architecture diagrams. Or schedule a call with our team.