Skip to main content

Security & data handling

If you are a psychologist considering Wenara, you are accountable for your clinical record and your patients’ privacy. This page tells you exactly where data lives, who can see it, and what the AI is and is not permitted to do — so you can make that judgement rather than take our word for it.

The short version

Your patients' data stays in Australia

Application hosting runs in Sydney and the database is provisioned in ap-southeast-2 (Sydney). There is one exception today, and it is the AI processing step — see what the AI does below. We are not vague about it because it is the question that matters most.

AI never writes to your clinical record

Every AI output — session notes, GP letters, treatment plans, between-session plans — lands as a draft in a review queue. Nothing enters the record or reaches a patient as clinical content until you read it and sign it. You are the author of record, always. This is enforced in the system architecture, not in a setting someone can switch off.

AI prompts and outputs are not retained by the model provider

Every AI request is sent with zero-data-retention enabled. The content of your sessions is not stored by the model provider and is not used to train models.

Patient records are isolated at the database level

Row-level security is enabled on every clinical table, with no bypass rules. A query for one practice’s data cannot return another’s, and this is enforced by the database itself rather than by application code that could contain a bug.

The audit log cannot be altered — including by us

Every access and change to clinical data is recorded. The audit log is append-only, enforced by a database trigger that rejects edits and deletions from every account including our own administrative access. If someone looked at a record, that fact is permanent.

Patients control what their psychologist reads

In the patient app, each check-in reflection can be kept private or shared. Structured data (mood, sleep, scores) is always visible to the treating psychologist; free-text reflections are the patient’s choice. Consent is captured per purpose and versioned.

What the AI does, precisely

Wenara uses large language models for clinical drafting and summarisation. Being specific about the boundaries:

  • Identifying details are removed before AI processing. Patient and practitioner names are replaced with placeholders before any content is sent to the model, and restored afterwards in your draft.
  • The AI does not diagnose. Drafting prompts explicitly prohibit diagnostic statements, medication recommendations, and fabricating content not present in the source material.
  • Session content is treated as data, not instruction. Transcripts, check-in text and patient messages are fenced before reaching the model, so content inside them cannot redirect what the AI does. This is regression-tested.
  • AI output quality is measured, not assumed. A sample of drafts is scored nightly against a clinical rubric covering safety-rule adherence, documentation quality and tone, so quality drift is visible rather than anecdotal.
  • Model processing currently happens in the United States, disclosed as an overseas disclosure under Australian Privacy Principle 8 in our Privacy Policy. Moving this processing into an Australian region is in progress — see below.

Access and authentication

  • Two-factor authentication is available on practitioner accounts.
  • Sensitive actions — exporting your full practice record, creating API credentials — require a fresh two-factor check at the moment of use, not just a logged-in session.
  • Sessions time out after inactivity, and deactivating an account revokes it immediately.
  • Deleting a clinical document marks it deleted and retains it for recovery rather than destroying it, because a mis-click should not be able to erase part of a clinical record.

What we haven’t done yet

This section exists on purpose. A security page that lists only strengths is not useful for making a decision.

  • We do not hold ISO 27001, SOC 2 or HDS certification. We are a small company and have not been through a formal audit. We are not going to imply otherwise. If your practice or insurer requires certification, Wenara is not the right fit yet.
  • AI processing is not yet in an Australian region. It runs in the US today under APP 8 disclosure with zero retention. Migrating to Australian-region model hosting is active work, and when it lands, no patient data will leave Australia at any point.
  • We are in pilot. Wenara is being used by a small number of Australian practices under active development. That means fast fixes and direct access to us — and also that you are early, with the risk that implies.

Your obligations, and ours

Under AHPRA guidance you remain responsible for any AI used in your practice: for checking every AI-generated record before it becomes your note, and for obtaining your patient’s consent to AI-assisted documentation. Wenara is built to make that straightforward — drafts wait for you, consent is captured and versioned, and the audit trail shows what was AI-drafted versus what you wrote — but the professional judgement is yours and the architecture deliberately does not let us take it from you.

Wenara is not an emergency service and does not provide crisis care. The patient app surfaces crisis helplines where relevant; it does not assess or manage risk. See our Privacy Policy for the full detail.

Questions

Security and privacy questions go to privacy@wenara.health and we will answer them specifically. If you want to see how something works before trusting it, ask — the answer is usually a screen we can show you.

Related: Privacy Policy · Terms of Service