Security

Security at Consulta

Clinics trust Consulta with sensitive health information. Security is not fine print for us: it shapes how the platform is hosted, how access works, and how we respond when someone tells us something is wrong.

Illustration of a shield guarding a stack of patient records

Securing your data

Hosted in Australia

Patient and clinic records are hosted in Sydney, Australia on independently certified infrastructure: AWS (ISO 27001, IRAP-assessed) and Supabase (ISO 27001, SOC 2 Type II).

Encrypted everywhere

All traffic is encrypted in transit (TLS), and records are encrypted at rest, as are backups.

Access enforced in the database

Row-level security scopes each clinic's access to its own records at the database layer, not merely in application code, with role-based access within each clinic.

Multi-factor authentication

Every clinic, practitioner and administrator account must enrol multi-factor authentication before portal access.

Payments handled by Stripe

Every card payment is processed by Stripe (PCI-DSS Level 1). Card and bank account details never touch Consulta's systems.

Monitored around the clock

The failures that matter alert the founders automatically, and our live status page runs its checks against the production systems when you load it.

Reviewed adversarially

The platform undergoes internal adversarial security review, and security findings are remediated with priority over feature work.

Your records stay yours

Clinics hold standing self-service export of their records from their own portal, so continuity of your records does not depend on Consulta's cooperation.

Reporting a vulnerability

If you believe you have found a security vulnerability in Consulta, we want to hear about it. Email admin@consultahealth.com.au with enough detail to reproduce the issue: the affected URL or endpoint, the steps, and what you observed. Reports go directly to the founders, not a queue.

We target acknowledging your report within 72 hours, will keep you informed as we investigate, and will tell you when the issue is fixed. We ask that you give us reasonable time to remediate before any public disclosure.

Good-faith research

Consulta will not initiate legal action solely on account of good-faith security research that complies with this policy: research that stays within systems Consulta controls, makes every effort to avoid accessing, modifying or destroying data that is not yours, does not degrade the service for others, and does not use social engineering, physical attacks or spam. If you encounter personal or health information in the course of research, stop, do not retain it, and report it to us immediately. This statement cannot bind third parties. We do not currently operate a paid bug bounty.

Machine-readable contact details: /.well-known/security.txt · Updated 28 August 2026