Security

Your billing and patient data, protected.

FreshClaim protects all billing and patient data with AES-256 encryption, ISO 27001-certified infrastructure, and Australian-only data storage.

Infrastructure

Servers in high-security data centres in Sydney, validated as Level 1 under the Payment Card Industry Data Security Standard, and compliant with ISO 27001 and IRAP security practices. Multiple availability zones for redundancy, with no single point of failure.

Payment processing by Stripe, who are also PCI DSS Level 1; we never store card details. Authentication by Auth0; we never store or ask for passwords, and two-factor authentication is available.

Encryption

All connections to and from FreshClaim servers run over SSL/TLS with 256-bit encryption.

All sensitive data is encrypted with AES-256-GCM before it is stored, and all data is encrypted at rest.

Operations

Systems monitored around the clock by internal and third-party services, alerting operations staff instantly. Least-privilege access with mandatory two-factor authentication for all staff and internal systems. Databases on a private network, unreachable from the public internet.

Scheduled maintenance is announced ahead of time by email. Any security incident is reported to Services Australia and to customers within 12 hours of our becoming aware of it.

Data integrity

All data stored within Australia; all staff are Australian citizens or permanent residents. Customer data is accessible only to a small, screened group.

Application data is backed up daily and kept for a year, with a tested restore process, and stored across multiple availability zones.

Questions about our security policies or infrastructure?

We’re happy to go into the detail.

Get in touch