Surely is SOC 2 Type II compliant, end-to-end encrypted, and designed from the ground up to handle personally identifiable health information in accordance with New Zealand law. Patients and applicants are in control of their own health records throughout, and Surely does not retain that data once a request has been fulfilled.
Independent audit of security, availability & confidentiality
All data encrypted in transit with time-limited access links
Equipped to handle personally identifiable health information
Surely's platform is hosted on enterprise-grade cloud infrastructure with multiple availability zones. All data is encrypted at rest and in transit using industry-standard encryption protocols. Our infrastructure is continuously monitored for anomalous access patterns and availability.
Access to health records is governed by explicit, documented patient or applicant consent. Records are delivered via time-limited presigned URLs. Access expires automatically after delivery. We minimise unnecessary PII on public-facing endpoints.
Surely operates in accordance with all applicable New Zealand health information legislation and international security standards:
Surely connects to general practice Practice Management Systems via a standards-based, authenticated FHIR integration. Practice credentials are never stored by Surely. Tokens are issued per-request and scoped precisely to the patient's authorised consent event. No data beyond the consented scope is accessed or retained.
Surely does not retain health record data. Once a request has been fulfilled and delivery is confirmed, access is revoked and the data is automatically and permanently deleted from the system within a defined number of days. Audit logs are maintained separately and retained for compliance purposes.
If you discover a security vulnerability in Surely's platform, please report it responsibly to hello@surely.nz. We will acknowledge receipt within 48 hours and work to resolve confirmed vulnerabilities promptly.
For security enquiries, contact us at hello@surely.nz or write to Surely Ltd, Level 4, 40 Taranaki Street, Wellington 6011, New Zealand.