Trust & Security

OnRounds is built by physicians who understand the sensitivity of clinical data. Here's how we protect it.

Australian Data Sovereignty

All infrastructure runs exclusively in Microsoft Azure's Australia East (Sydney) region. Your data never leaves Australian borders.

Encryption Everywhere

TLS/SSL encryption protects all data in transit. Azure-managed encryption secures all data at rest across databases and storage.

Enterprise Authentication

Microsoft Entra ID provides single sign-on, multi-factor authentication, and centralised access control managed by your organisation.

Clinical Audit Trail

Every message, handover note, and shift record is retained with a soft-delete model — ensuring a complete audit trail for compliance.

No Third-Party Tracking

OnRounds contains no advertising SDKs, no third-party analytics, and no tracking technologies. Your clinical data stays private.

Physician-Led Design

Built by doctors who work in hospitals and understand the sensitivity of clinical communications and the realities of shift-based care.

Infrastructure

OnRounds is hosted entirely on Microsoft Azure, one of the world's most widely certified cloud platforms. We use the following Azure services, all provisioned within the Australia East (Sydney) region:

By hosting all infrastructure within Australia, we ensure complete data sovereignty. No data is replicated to, processed in, or transmitted through servers outside of Australia.

Authentication and Access Control

OnRounds delegates all authentication to Microsoft Entra ID (formerly Azure Active Directory). This provides enterprise-grade identity management including single sign-on (SSO) with your organisation's existing Microsoft 365 or Azure AD tenant, support for multi-factor authentication (MFA) as configured by your organisation, and centralised account provisioning and deprovisioning by your IT administrators.

OnRounds does not store passwords. Your authentication session is managed entirely by Microsoft's identity platform, and access tokens are validated on every API request.

Encryption

In Transit

All connections to OnRounds are encrypted with TLS (Transport Layer Security). This applies to the web application, the API, and push notification delivery. Unencrypted HTTP requests are automatically redirected to HTTPS.

At Rest

All data stored in Azure Cosmos DB and Azure Blob Storage is encrypted at rest using Azure-managed encryption keys. This is enabled by default on all Azure storage services and requires no user configuration.

Push Notification Security

OnRounds delivers push notifications using the Web Push protocol with VAPID (Voluntary Application Server Identification) keys. This is a standards-based approach that does not rely on third-party push notification services. Notification payloads are encrypted end-to-end between the OnRounds server and your browser using the keys exchanged during subscription. Push subscriptions are stored per device and are automatically invalidated when they expire or become unreachable.

Progressive Web App Security

OnRounds is delivered as a Progressive Web App (PWA), which runs within your browser's security sandbox. This means the application is subject to the same origin policy and browser security protections as any web application, it does not require installation from an app store and does not request access to device features beyond what is needed (camera for image sharing, notifications), and all code is delivered over HTTPS from our verified domain.

Data Retention and Audit

In healthcare environments, communication records may need to be reviewed for clinical governance, incident investigation, or regulatory compliance. OnRounds retains all messages, images, and handover notes using a soft-delete model — content may be hidden from the user interface but is never permanently erased from the database.

This approach ensures a complete, tamper-resistant audit trail that supports your organisation's compliance obligations.

Data Sharing

Docworks does not sell, rent, or share your data with any third party for marketing, advertising, or analytics purposes. The only third-party infrastructure provider involved is Microsoft Azure, which acts as a data processor under enterprise service agreements and does not access your data for its own purposes.

Compliance

OnRounds is designed to support compliance with the Australian Privacy Principles under the Privacy Act 1988 (Cth). Our infrastructure choices — Australian-only hosting, enterprise authentication, full encryption, and comprehensive audit trails — are specifically intended to meet the expectations of healthcare organisations and their regulatory obligations.

For detailed information about how we handle personal data, please refer to our Privacy Policy.

Questions

If you have questions about OnRounds' security practices or would like to discuss our approach with your IT or information security team, please get in touch.

Docworks — Security Inquiries

Email: support@docworks.com.au

Location: Shepparton, Victoria, Australia