Australian data sovereignty
Customer and patient data is stored exclusively in Australia (AWS Sydney, ap-southeast-2) and never routed through servers offshore. Compliant with the Privacy Act 1988 (Cth), the Australian Privacy Principles, and state health-records legislation.
Human oversight, always
Decision-making authority stays with the practitioner or operator — our agents handle administration only. Escalation to a human is always available, and every automated action can be reviewed, modified or reversed.
Data minimisation
We collect only what is strictly necessary to deliver the service. We never use customer or patient data to train AI models, and our enterprise AI providers are contractually prohibited from doing so.
Responsible-AI governance
Our practices are aligned with the AI Governance Professional (AIGP) standards published by the IAPP. We run periodic algorithmic audits, maintain an incident register, and reassess privacy and security at least annually.
Security anchored on Essential 8
Auresta Secure delivers sovereign, Australian-hosted Managed Detection & Response built on the ASD Essential 8 — the same security bar we hold ourselves to across every product.
Transparency by default
We always disclose when someone is interacting with an AI agent. Identities are clear in greetings and interfaces, and operators see a full log of every call, booking and message an agent handles.
Aligned with
The frameworks Australian businesses are held to.
Read the detail.
Our full commitments are public. Dig into the charter and policies, or talk to us about a deeper security and compliance review.