Hemexa
← Back to home

Security

Last updated: 2 July 2026

Your health data is locked, verified, and never treated casually. This page explains how Hemexa protects your information in plain language. For how we collect and use personal information, see our Privacy Policy.

Our promise

  • Your results are yours. We do not sell your identifiable health information.
  • Every lab file is fingerprinted. You can verify that what we stored matches what you uploaded.
  • Finalised results are locked. They cannot be silently edited after finalisation.

How Hemexa Vault works

Hemexa Vault is the integrity layer behind your lab results in the member app. When you upload or import a file, we compute a cryptographic fingerprint (SHA-256) of the original file bytes and store it with your test record.

  1. Upload fingerprint. When your file arrives, we record a unique fingerprint before processing begins.
  2. Results lock. When your results are finalised, they are marked locked with a timestamp. Locked results cannot be modified.
  3. Encrypted storage and transfer. Data is encrypted in transit and at rest in our secure infrastructure. We use industry-standard encryption; no system is completely immune from attack, but we design for health data from the ground up.

Members can view file fingerprints and lock status on each test in the Hemexa app under Hemexa Vault.

What we never do

Health information is sensitive. We treat it as protected health information end to end and apply strict controls on where it can go:

  • We do not send identifiable health information to analytics platforms, error monitoring tools, or third-party AI services.
  • We do not log health results, lab values, or other protected health information in application logs.
  • When AI features process your data, we use de-identification controls so models receive clinical context without your name, contact details, or other personal identifiers.
  • We do not sell identifiable health information to advertisers or data brokers.

Our primary database (Supabase) is approved for health data storage. Other service providers receive only the data required for their function (for example, payment metadata to Stripe, not your lab results). See our Privacy Policy for the full list of subprocessors and overseas disclosure.

Australian privacy

Hemexa is an Australian company. We handle personal information and health information in accordance with applicable Australian privacy laws, including:

  • the Privacy Act 1988 (Cth)
  • the Australian Privacy Principles (APPs)
  • the Notifiable Data Breaches (NDB) scheme
  • state and territory health records legislation where relevant to your location

Where practicable, health data is hosted in Australian data centres. Some service providers may process limited personal information outside Australia; we take reasonable steps to protect information disclosed overseas. If a data breach is likely to cause serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the NDB scheme.

Live today

  • Every uploaded lab file gets a SHA-256 fingerprint so you can verify what we stored matches what you uploaded.
  • Finalised results are locked. They cannot be silently edited after finalisation.
  • Results fingerprint: a verification hash of your locked marker values (in addition to the file fingerprint).
  • Health data is encrypted in transit (TLS) and at rest in our primary database.
  • Account access uses secure authentication (Clerk) with server-side verification on sensitive actions.
  • We do not send identifiable health information to analytics, error monitoring, or third-party AI tools.
  • Application logs are designed to exclude health information and other sensitive data.

Rolling out

We publish commitments before they ship so you know what we are building. These features are on our roadmap:

  • Downloadable verification certificate (PDF) for each finalised test, shareable with your clinician.
  • Security activity log on your account: sign-ins, imports, and exports (no health data in log lines).
  • Public subprocessor transparency page listing our infrastructure and service providers.

Contact

If you have a security or privacy concern, contact our Privacy Officer:

Hemexa Pty Ltd
Email: privacy@hemexa.health
Address: International Tower 3, Level 17/300 Barangaroo Ave, Barangaroo NSW 2000

For privacy complaints, you may also contact the Office of the Australian Information Commissioner. See our Privacy Policy for full details.