🔐
Encryption everywhere

All data encrypted at rest (AES-256) and in transit (TLS 1.2+). Database, S3 storage, and secrets all encrypted with AWS KMS.

🏰
Network isolation

Database and application servers in private network subnets with no direct internet access. All cloud service calls route through private endpoints.

🎭
Identity de-identification

Participant identifiers tokenised by DeIDProxy before any AI API call. Raw identifiers never leave Australian infrastructure.

📋
Immutable audit trail

Every supervisor override and AI transmission logged immutably. Access logs retained 90 days. AI transmission metadata retained 3 years.

Infrastructure security

NoteGate is hosted exclusively on AWS ap-southeast-2 (Sydney). The following controls are active across all production infrastructure.

Database (RDS)
Relational database in private subnet. No public access. AES-256 encryption. 7-day automated backups. Deletion protection enabled. Multi-AZ available. Active
Object storage (S3)
Region-deny bucket policy blocks all access from outside ap-southeast-2. HTTPS-only policy enforced. Versioning enabled on document bucket. Active
Application (Container infrastructure)
Application containers run in private subnets. No direct internet access. Secrets injected from an encrypted secrets store at runtime — never stored in container images. Active
Secrets management
All API keys, database credentials, and webhook secrets stored in an encrypted secrets vault — never in source code or container images. Active
Network
All internal cloud service calls route through private network endpoints — never traverse the public internet. ALB with HTTPS-only listeners. HTTP redirects to HTTPS. TLS 1.2 minimum. Active
CDN (CloudFront)
Frontend served via CloudFront with ACM certificate. Security headers enforced. HTTPS-only. HTTP/2 and HTTP/3 enabled. Active
Container images
Container images are scanned for vulnerabilities on every build. Containers run with minimal privileges. Active

Application security

AI security

The Anthropic Claude API is used for note validation. The following controls are specific to AI security:

Notifiable Data Breaches

NoteGate is subject to the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988 (Cth). In the event of an eligible data breach:

Vulnerability disclosure

If you discover a security vulnerability in NoteGate, please report it responsibly:

We do not currently operate a bug bounty programme but we recognise responsible disclosure and will acknowledge contributors where appropriate.

Security enquiries

For security questions, vulnerability reports, or incident notifications:

security@notegate.com.au
AgenticX Australia · ABN: 27 680 398 305
Queensland, Australia

For urgent security incidents affecting participant data, include "URGENT" in the subject line. We monitor this address 7 days a week.