Security
Blue Merino works with sensitive patient and consultation information, so privacy and security are built into the way the platform processes, stores and controls access to that information.
Information stays within secure Australian infrastructure and is protected by encryption, access controls and multiple layers of security.
Encrypted in transit (TLS) and encrypted at rest (AES-256-GCM)
Consultation audio is transmitted over an encrypted connection, transcribed on Blue Merino’s own infrastructure in Sydney, and deleted automatically once the transcript has been produced unless the clinic has opted to retain it for up to seven days. AI note generation is performed through AWS Bedrock, also in Sydney. Audio is never used for advertising, profiling or AI-model training.
Blue Merino’s production environment operates within Australian infrastructure. Consultation transcription takes place on Blue Merino’s own infrastructure in Sydney, while AI note generation uses AWS Bedrock in Sydney.
We use row-level security in the database to keep each clinic’s data completely separate.
Clinic content cannot be visible to any other clinic or service across the platform in Blue Merino’s environment.
Data access is scoped to the clinic and permissions control at the individual and role level.
Clinic A
Isolated database layer
Clinic B
Isolated database layer
Clinic C
Isolated database layer
Information is encrypted in transit using TLS and encrypted at rest using AES-256-GCM.
Cliniko API credentials are encrypted at rest and scoped to the relevant clinic or account.
Passwords are securely hashed and held to a strong minimum-length requirement.
Two-factor authentication and single-use backup codes are available for account protection. Access to sensitive features is restricted according to user role and permissions.
Security-relevant actions are written to an append-only audit log that cannot be altered after the fact.
The log records who performed an action, what occurred, which record it related to and when. Audit logs are retained for seven years.
Multiple layers of technical controls protect against common threats and reduce risk.
Blue Merino is designed around Australia’s Privacy Act 1988 (Cth), the Australian Privacy Principles, and the privacy obligations relevant to health information.
We support your clinic’s responsibilities for the handling of health information and record-keeping under relevant Australian law.
If you believe you’ve found a security vulnerability, please let us know privately so we can investigate and fix it before any details are made public.
Email security@bluemerino.com.au and give us a reasonable window to respond. We’ll work with you and acknowledge your help.
We’re here to help. Talk to the Blue Merino team any time about our security, compliance or data protection.