Your own encryption key
Every person’s health data is encrypted at rest with AES-256-GCM using a data key that is unique to them, sealed by AWS Key Management Service. A stolen database, on its own, is just unreadable ciphertext.
We value your privacy
We use necessary cookies to make Bimble work. With your consent we also use cookies for analytics and marketing to understand how the site is used and to measure our campaigns. You can accept, reject, or choose what to allow. See our Privacy Policy for detail.
Security
Security is not a feature we added at the end. It is the foundation Bimble is built on. Here, in plain language, is exactly how your information is protected.
How it works
Six of the measures that keep your health information private, from the moment you record it to the moment you decide to remove it.
Every person’s health data is encrypted at rest with AES-256-GCM using a data key that is unique to them, sealed by AWS Key Management Service. A stolen database, on its own, is just unreadable ciphertext.
The key that protects everything cannot be exported, downloaded, or read by Bimble engineers. Every single use of it is logged in AWS CloudTrail.
No provider can see any of your data until you grant access, and you choose which categories each one sees. Change your mind and revoke it, and the next request is blocked.
Every practitioner is checked against the AHPRA register and their ABN is validated before they can ever receive access to a patient’s information.
Every connection between the app, our servers, our database, and our cache is protected with TLS, fronted by Cloudflare with strict transport security.
Data you record yourself can be deleted, which destroys the keys that make it readable. Encrypted backups are then purged on a rolling 30-day cycle, after which it is gone for good.
Trust Center
Bimble maintains a public Trust Center, powered by Vanta, where you can review our security posture, our compliance progress, and the controls behind it. We are undergoing a SOC 2 examination and monitor our controls continuously.
Security questions
No. Your health data is encrypted with a key that is unique to you, sealed by AWS KMS. The master key that protects those keys cannot be accessed by Bimble engineers, and every use of it is logged.
An attacker who obtained a copy of the database would get only ciphertext and encrypted data keys. Without access to AWS KMS, which requires separate credentials, that data cannot be read.
You do. No provider can access any of your data without a consent grant, and you choose which categories each provider or clinic can see. You can change or withdraw access at any time.
The health-tracking data you record yourself is yours, and you can delete it at any time, either individual entries or a whole category. Deleting it destroys the keys that make it readable, and encrypted backups are purged on a rolling 30-day cycle, after which it cannot be recovered.
Records of care provided by a health professional, such as telehealth consultations and referrals, must be kept for the minimum periods required by law. Because your account can hold both your own data and these records, we do not currently offer full account deletion. You can delete your tracking data, revoke provider access, and ask us to deactivate your account. Our Privacy Policy explains this in full.