HALOSphere
• Security & clinical safety

Clinical-grade software demands clinical-grade accountability.

HALO Sphere users document patient care and account for Schedule 8 medicines — so security isn’t a layer added afterwards. The platform’s core features are accountability controls, and the program behind them is documented, measured against recognised frameworks, and operated on a verified cadence.

Framework-aligned

Controls mapped to ISO/IEC 27001:2022 with evidence, self-assessed at ACSC Essential Eight Maturity Level One — the bar Australian health buyers ask about first. Certification planned as customer demand requires.

  • ISO 27001:2022 Annex A control inventory
  • Essential Eight ML1 self-assessment
  • Nine approved security policies

Identity, done properly

Passkeys (Face ID / Touch ID) and authenticator MFA are first-class. The controlled-drug register requires fresh multi-factor step-up — and witnessed actions require the witness’s own credential, minting single-use cryptographic proof.

  • WebAuthn passkeys, cross-device
  • Mandatory step-up on the drug register
  • Two-person integrity with cryptographic proof

Everything on the record

Append-only audit ledgers cover logins, clinical actions, drug movements and admin activity — including who read or printed a record. Edits to patient care records are amendment-tracked field-by-field: old value, new value, who, why. Never silently overwritten.

  • Append-only signed drug register
  • Field-level amendment history
  • Org-scoped audit visibility

Recovery, rehearsed

Three independent backup layers: continuous point-in-time recovery, daily snapshots, and hourly complete copies to independent off-platform storage. Restores are tested and timed — not assumed.

  • Restore to any moment (PITR)
  • Hourly off-platform copies
  • Documented quarterly restore tests

Shipped safely

Every change goes branch → review → CI gates: type-safety plus a blocking vulnerability audit on production dependencies, with weekly automated patching. Destructive migrations fail the deploy; failed deploys never replace the running version.

  • Human review on every change
  • CI blocks high/critical advisories
  • Crash & deploy-failure alerting, verified

Australian privacy, first-class

Privacy handling structured on the Australian Privacy Principles with health information at the highest sensitivity tier. Clinical data custodianship stays with the healthcare organisation; 7-year clinical retention; AI features organise the user’s own text and never invent clinical content.

  • APP-aligned, NDB-scheme incident plan
  • Custodianship with your organisation
  • Written AI guardrails — no fabricated clinical content
• Data residency

Where your data lives — stated plainly.

We disclose hosting locations to customers as plainly as we document them internally. If a contract or tender requires onshore hosting, we treat that as a scoped migration conversation — not a wording exercise.

UNITED STATES

Primary application hosting and databases — all platform data, including clinical records — plus AI text processing and consult calling. Encrypted in transit and at rest.

AUSTRALIA

Consult-call transcription is processed entirely in-country (Sydney — storage and inference, with model-training opt-out enforced), and clinical terminology comes from Australia’s National Clinical Terminology Service.

EUROPEAN UNION

Address autocomplete and scene-weather lookups only — query strings and coordinates, never names, records or clinical content.

• Clinical safety

It documents care. It never directs it.

HALO Sphere is a tool that assists trained clinicians who retain full responsibility for clinical judgement. It does not diagnose, calculate doses autonomously, or assign triage categories — a position we hold in writing, engineer to, and re-assess against Australian therapeutic-goods regulation before every feature that goes near the line.

Named Clinical Safety Officer

A practising clinician owns clinical safety, with a live hazard log and review before every release.

Documented regulatory position

A written TGA software self-assessment concludes no component is a medical device — with explicit re-assessment triggers before any feature could change that.

Honest about maturity

ISO-aligned, not yet certified. External penetration testing is planned; internal hardening reviews run today. We only claim what’s live — in the product and on this page.

Want the detail?

The full security & clinical-safety documentation pack — control inventory, Essential Eight self-assessment, policies and the TGA self-assessment — is available on request (NDA where required).

Request the pack →

Security contact: hello@halosphere.com.au