Skip to content

Trust Centre

Paranoid, professionally.

Everything about how Surgibud handles your data, in one place. We hold professional records about real operations on real people, and designed it the way you'd want your own surgeon's logbook designed: minimal data, strong crypto, and a healthy distrust of everyone — including ourselves.

  • NZ Privacy Act 2020
  • Health Information Privacy Code 2020
  • Australian Privacy Principles (Privacy Act 1988)
  • Data stored in Australia

Built around the privacy law that actually governs your patients — not US-style HIPAA.

No patient identifiers, by design

There is no field for a patient name, official patient number, or date of birth — anywhere. Cases are keyed by your own non-identifying codes like "WGN-001", and the terms of use require that nothing identifying is entered. The less identifying data a logbook holds, the less there is to leak.

Encryption that means it

PROM contact details (a first name and an email or phone number) are encrypted with AES-256-GCM at the application layer before they reach the database. The database holds only ciphertext. Surgibud staff cannot read them — and neither can anyone who steals the database.

Deletion is the default

Contact details are hard-deleted automatically the moment the last scheduled survey is sent, or instantly if the patient opts out. They exist only as long as they are useful to your patient.

Row-level security on every table

Database-enforced row-level security means each surgeon can only ever read their own data. This is enforced by PostgreSQL itself, not just application code.

Passwordless + passkeys

Sign-in uses one-time email codes — no password to reuse or breach. Add a passkey (WebAuthn) for phishing-resistant multi-factor authentication.

An audit log that cannot lie

Compliance events are written to an append-only audit log. Database triggers reject any update or delete. What happened, happened.

Data sovereignty

All data is stored securely in Sydney, Australia — close to home for NZ and Australian clinicians, and governed by the NZ Privacy Act 2020, the Health Information Privacy Code 2020, and the Australian Privacy Principles.

You own your data — and leaving is easy

Your logbook belongs to you. Export everything — cases, statistics, CPD — to PDF and structured data at any time, no questions asked. Delete any record, or your whole account, yourself. We earn your stay; we never trap it.

Yours alone, never used against you

Surgibud is a private professional record, not a surveillance system. Your data is never shared with employers, hospitals, colleges, or regulators. Nothing leaves your logbook unless you export it or share a specific case.

No trackers, no data sales, no model training

No advertising cookies, no third-party analytics, no selling data — and content sent to AI features is never used to train models. The business model is the subscription. That is the whole business model.

The stack, layer by layer

TransportHTTPS everywhere, TLS 1.2+ enforced
ApplicationSvelteKit on Cloudflare with strict Content-Security-Policy headers and WAF rate limiting
DatabasePostgreSQL on Supabase, stored securely in Sydney, Australia, row-level security on all tables
Patient contactsAES-256-GCM application-layer encryption, ephemeral storage
AuthenticationOne-time email codes + optional WebAuthn passkeys, server-side token validation on every request
AIAnthropic API, server-side only, rate-limited per user, zero retention for training
Email/SMSResend and Kudosity for transactional dispatch only
Retention10-year clinical record retention per NZ Health (Retention of Health Information) Regulations 1996, then automated purge

Responsible disclosure

Found a vulnerability? Please email [email protected] with details. We respond within 2 business days, fix confirmed issues promptly, and will happily credit you (or keep you anonymous — your call). Please don't test against accounts or data that aren't yours.

For the full legal detail, read the privacy policy and terms of service.

How we handle AI

AI that's optional, contained, and never trains on you.

AI features — form-filling from an op note, reflection enhancement — are entirely optional and switch off in one click. Don't want AI near your logbook? Turn it off completely: no extraction, no suggestions, nothing. Surgibud works beautifully either way.

Anything you do submit is processed by Anthropic's API on the server, never stored by us beyond a timestamp for rate-limiting, and never used to train models. And because Surgibud has no field for patient identifiers, there's nowhere for identifying data to land even if it slips into a pasted note — though we still advise removing identifiers before pasting.

Who else touches your data

A short, honest list of every service involved in running Surgibud — what they do, what they see, and where. No hidden fourth parties.

ServiceRoleWhat they seeWhere
SupabaseDatabase & authenticationYour account and case data (as processor)Sydney, Australia
CloudflareApp delivery, WAF & bot protectionRequest metadata, IP addresses — no health data storedGlobal edge
StripePaymentsYour card details directly (we never see them) + billing statusGlobal
AnthropicOptional AI featuresOnly content you submit; never stored by us, never used for trainingUS
ResendTransactional & PROM survey emailRecipient email + message content, for delivery onlyUS
KudosityPROM survey SMSRecipient phone + message content, for delivery onlyAustralia

Full detail and policy links are in the privacy policy.

If something goes wrong

You'll hear it from us.

In the unlikely event of a privacy breach, we assess and contain it immediately and notify affected users and the relevant authorities — the NZ Office of the Privacy Commissioner and/or the Australian OAIC — without undue delay, consistent with the NZ Privacy Act 2020 and the Australian Notifiable Data Breaches scheme.

Because Surgibud holds no patient names, birth dates, or official identifiers, the realistic blast radius of any breach is deliberately tiny — the safest data is the data we never collect.

Suspect a breach or have a concern? Email [email protected].

Your next case deserves a better logbook.

3 months free for everyone, no credit card to sign up. Free beyond that for trainees, fellows, and low-income countries.