Security and Legal

Surely is designed with your privacy and data security as the highest priority. Built on enterprise-grade infrastructure and it complies with industry-leading standards to safeguard your health information at every stage.

What are the security standards?

Surely runs on Eightwire — a secure, government-trusted data exchange platform that meets SOC 2 compliance standards. It uses full encryption, supports classified health data, and maintains a complete, auditable log of all system activity.

SOC 2 Certified

Surely has undergone independent audits to verify compliance with strict international standards for data security, confidentiality, and system reliability.

Powered by Eightwire

The technology behind Surely is relied on by over 100 healthcare, government, and private organisations across New Zealand — a proven foundation for handling sensitive health data safely.

End-to-End Encryption

All health information is fully encrypted both while being transmitted and when stored, preventing unauthorised access at any stage.

Temporary Access Windows

Shared health records are available only for a limited time (72 hours) before being permanently deleted. Furthermore, all past requests containing personal applicant details are securely redacted from the system to maintain ongoing privacy.

Zero Access by Surely Staff

Surely's own team does not have access to patient health records at any time, ensuring an additional layer of privacy and trust

Is Surely compliant with the Privacy Act 2020 / Health Information Privacy Code?

‍Yes. APP is built and operated in compliance with the Health Information Privacy Code 2020 and the Privacy Act 2020. All data exchanges are encrypted, auditable, and governed by clear consent protocols.

Who can become a “certified agency” in Surely?

Organisations must meet one of the following criteria:

Certified Healthcare Provider:
Registered with the Ministry of Health (e.g. hospitals, aged care, urgent care)

Authorised Government Agency:
Official entities such as ACC, Oranga Tamariki, or Te Whatu Ora

Verified Third Party:
Licensed insurance companies, brokers, or health service partners with appropriate consent models in place

Contact & Support

Need help or have a question?
Email us at support@surely.nz or reply to your original request email.
We’re here to help — whether you’re a patient, provider, or partner