Hosting, backups and isolation
Who this page is for: the IT contact asking where this runs, and the practice manager asking who else can see their referrals. (Answer: no other practice.)
Refera runs as managed cloud in Australia, with each practice’s referrals isolated in their own tenant partition - never mixed into a shared view with other practices. Access is limited to authorised practice users and tightly controlled Refera service or operator roles for defined operational purposes. You run it from the desks you already have.
Current recovery baseline: continuous point-in-time recovery on all three DynamoDB tables with a rolling 35-day window; versioning on all six Refera S3 buckets; and Object Lock on the source archive and audit buckets. These are same-account, Sydney-region controls with no S3 replication, cross-account vault or second-region recovery copy.
Each practice’s data, isolated by design
Section titled “Each practice’s data, isolated by design”Every practice has its own tenant. Each practice’s records live under their own tenant partition and are sealed in their own tamper-evident chain of custody, and every read is tenant-scoped by construction - the storage layer will only return records for the tenant making the request, so there is no code path that serves one practice another practice’s data. Australian data residency (ap-southeast-2, Sydney) is enforced by policy and proven by a re-runnable test, not just asserted - see Data residency.
The current data posture is explicit: practices share an encrypted DynamoDB table, with tenant ID in every key and authenticated server code scoping every operation. Refera does not claim a separate database, table or encryption key per practice.
Sign in with what you have
Section titled “Sign in with what you have”Email provides single-use, time-limited mailbox proof. A live API session requires either a user-verified WebAuthn passkey or that email proof combined with a current TOTP code from an enrolled authenticator app. Neither email nor TOTP works alone. Recovery proof is restricted to factor replacement and cannot open referral data. Factor changes revoke older sessions, and an unattended session locks after one hour. Single sign-on with an existing Microsoft 365 or Google directory remains roadmap work and cannot weaken that floor.
Every mailbox and site, one front door
Section titled “Every mailbox and site, one front door”Multiple referral mailboxes, several fax numbers and more than one location all feed the same queue - so a group with several sites or intake addresses sees one front door, not many.
Managed for you
Section titled “Managed for you”The connected console and API are served by a three-AZ AWS ECS/Fargate service behind an
AWS Application Load Balancer at portal.refera.au. Cloudflare supplies DNS for that host
without proxying referral or settings traffic. Cloud-managed means updates, backups and
monitoring are handled centrally; every release is gated before deploy, introduced through
a bounded ECS canary and checked again live - see
Releases and updates. Tenant isolation and Australian
data residency (ap-southeast-2) are the intended security posture, designed in from the
start rather than bolted on later - the full posture, including what is not yet earned, is
on Security posture.
Recovery points, stated precisely
Section titled “Recovery points, stated precisely”DynamoDB continuous point-in-time recovery is enabled on all three current tables. It provides a rolling 35-day recovery window rather than a once-a-night backup. All six Refera S3 buckets are versioned, so a new version is retained when an object changes. Object Lock is also enabled on the source archive and audit buckets. The source archive defaults to governance-mode seven-year retention; the audit bucket has no bucket-wide default retention.
Those bucket controls are deployed; complete source-document lifecycle proof remains a separate patient-data readiness check.
These controls remain in the same AWS account and Sydney region. S3 replication is not configured. Refera does not claim a cross-account backup vault, a second-region recovery copy or a completed quarterly restore-drill programme. Those controls become customer commitments only after they are implemented and evidenced.
Did this answer your question?
Thanks - that helps us make these docs better.
Refera tracks referral admin only. It does not triage patients.
Examples are fictional and contain no patient information. Practice staff approve every external action. Refera never auto-sends or independently contacts patients.
Refera homeStart account setupOpen ReferaPrivacyTerms
[email protected]AI-assisted product and setup support. For a person, use the contact form or email.