Skip to content
Corella

Security & data handling

Care data deserves better than a shared database.

This page is the plain-English version of how Corella handles your organisation’s data — no acronym soup, no badge wall. If you want more detail than what’s here, ask us and you’ll get a straight answer.

The structural difference

Isolation isn't a setting. It's the architecture.

Every Corella provider gets their own instance: their own application, their own database, their own subdomain, their own branding. The wall between your data and anyone else's isn't a permission check — it's separate infrastructure.

The usual model mixes every organisation’s records in one shared database; Corella keeps each provider’s records in their own isolated instance, database and addressThe usual modelproviderproviderproviderproviderproviderone shared databaseevery organisation’s data,one table apartvsCorellaprovider Aown dbown addressprovider Bown dbown addressprovider Cown dbown addressone isolated instance, database andsubdomain per provider — Sydney, Australia

In practice

What we do, in plain English.

One database per provider

Your instance runs against its own database with its own credentials. There is no shared table, no tenant column, no 'filtered view' of a communal pool — your data and another organisation's data are structurally separate.

Hosted in Sydney, Australia

Your instance, its database and your uploaded files live in Australian data centres (DigitalOcean, Sydney). Care records don't leave the country to be stored.

Where the AI processing happens

Corella's AI features are off until your organisation turns them on. When they're on, the text being analysed is sent to our AI provider in the United States. For a client summary that means conditions, allergies, behaviour support notes, recent incidents, recent progress notes and the office-only notes on that person's record — the most sensitive thing Corella sends anywhere, which is why it belongs on this page and not in a footnote. What we can tell you about it is the part that is contractual rather than a guess about somebody else's servers: the provider's commercial terms prohibit training models on customer content, so nothing you send is used to train anybody's model. Your records still live in Sydney; the analysis doesn't happen in Sydney. If you want the provider's data-handling terms before you switch it on, ask and we'll send them.

Voice notes and meeting recordings — where the audio goes

Dictation and meeting recording are separate switches, both off until you turn them on. When they're on, the audio is transcribed by a specialist provider in the European Union — there is no Australian region for this, and we won't pretend the audio stays onshore. As soon as the text comes back, your instance instructs that service to delete both the recording and its copy of the text — on the meeting path, on the dictation path, and on the one that matters most, a recording abandoned part-way. Corella does not keep the recording. Only the resulting text is kept, in your organisation's own Corella database in Sydney. Because this is a cross-border disclosure, you should name speech processing in your own privacy policy and participant agreements — and Corella drafts that wording for you: Settings → Voice & meetings hands you a copy-ready privacy-policy clause, a service-agreement clause, and the sentence staff say before recording a meeting, each filled in with your organisation's details. The transcription provider's terms are available on request.

Roles with real walls

Four built-in staff levels scope what people see and do, and an organisation can build its own roles on top of them — starting from a built-in level and choosing area by area how far it reaches, so a senior clinician can keep the clinical picture without seeing invoicing. Money and billing is the one area enforced that way today. Support workers only see clients they're rostered with, and only the need-to-know essentials — office-only fields and one-way private notes stay with the office.

Files behind the login

Documents and photos are stored per-organisation and served only through your instance's authenticated proxy — there are no public file links to leak.

Backups you could actually use

Databases are backed up daily with point-in-time recovery. Backups are the platform's job, done on managed infrastructure — not a cron job on a box in a cupboard.

An audit log of who did what

Actions across the system are recorded — who created, changed or approved what, and when. When a question comes up months later, the answer is in the log, not in memory.

Watched for errors

Every instance reports errors to monitoring the moment they happen, and uptime checks page us if your instance stops answering. Problems get found by us, not by your Monday morning.

Sessions that re-check themselves

Logins re-verify a person's role and active status against the database on every sensitive action — deactivating a departed staff member cuts their access, immediately.

What you won’t find here: badges we don’t hold.

We don’t display certification logos we haven’t earned, and we won’t imply compliance frameworks by decoration. What we will do is answer any question about how your data is stored, who can access it, and how you’d get it back — directly, from the people who run the platform.

Ask us anything about data handling

See your organisation in Corella.

A 30-minute walkthrough with the people who built it — your workflows, your terminology, not a canned demo.