Black Shard

Clinical voice software for Australian private-hospital specialists, built on Azure from the apps to the audit trail.

Clinical software spanning mobile, web, speech processing, OCR and a multi-tenant data platform.

Live · in production, operated by Black Shardaurii.com.auDownload on the App StoreBlack Shard Clinical software
Client
Aurii
Sector
Clinical software
Apps shipped
iOS, Android, web
Hosting region
Azure Australia East

A specialist speaks the consult at the bedside and Aurii drafts the clinical note, the letters and the billing inside the framework the practice already uses. We built the stack: the iOS and Android apps, the web app, the marketing site, the speech and OCR pipelines, the multi-tenant data layer, the migrations, the clinical messaging gateway.

The Azure stack

Aurii runs on Microsoft Azure in the Australia East region: Container Apps for the app server, PostgreSQL with row-level security for tenant data, Azure AI Speech for recognition, Key Vault for secrets, GitHub Actions with Workload Identity Federation for deploys. The clinical and privacy frame was designed for Australian obligations from the start.

What we built.

  • iOS and Android apps, and the web app
  • Azure Container Apps + PostgreSQL with tenant row-level security + Speech + Key Vault stack
  • Marketing site, brand identity, and onboarding pipeline
  • Tamper-evident audit trails and rate limiting throughout

How it is secured.

Tenant health data isolated with PostgreSQL row-level security, tamper-evident audit trails, and rate limiting, on Azure in Australia.

Inside the build.

One record from consult to claim

Aurii is the operating system for Australian private hospital specialists. The work starts with the spoken consult, and everything the specialist signs is drafted from the same patient record: the clinical note, letters, referrals, prescriptions, discharge summaries, procedure reports, the ward round and the handover.

The patient file holds the current admission, the referral on record and its validity window, investigations with trends and abnormal results flagged, medications, allergies and social history. One referral-validity calculation serves the patient card, the referrals list and the admission-time picker, so all three show the same expiry.

From the consult to a signed note

A signature is set up before the first consult is recorded. The spoken consult becomes a draft clinical note in the practice's fixed section order, and the specialist edits, approves and signs it. The sent document is rendered from the same section model as the signed note on screen.

A suggestion the platform makes shows its full clinical wording before the specialist can accept it, and an acceptance is permanent. An OCR scan prefills a new patient's identity fields and checks for a possible duplicate before the rest of intake is filled in.

Signed once, sent at once

Every clinical document goes through one finalise sequence. Once a letter, report or summary has been previewed, approved and signed, it goes to the destinations already chosen for it, unless the specialist saves it for later. Discharge summaries take their recipients from the practice's contacts and the patient's treating providers, and each recipient's delivery channel follows the same rules as a letter.

Secure clinical messaging runs through a gateway that parses, validates and acknowledges each inbound HL7 message before it reaches the inbox, where results, referrals and correspondence render with their attached PDF. Each new practice's messaging setup is captured in the app and provisioned from an operator queue. Templates carry the practice's own note and letter structures, and a template the specialist already has in Word or plain text imports in the browser without being retyped.

A recipient outside secure messaging gets a secure portal link, and each opening of it is recorded in the specialist's access trail. A patient can be shared with another practice on the platform, which then sees that patient under Shared with me.

Rounds, lists and procedures

A ward round runs from a list built from current admissions, with reusable templates for recurring rounds, and ends in a handover. Procedure bookings and procedure reports sit in the same record, next to the calendar and the notification feed.

Billing inside the workflow

Billing items are raised from the encounter. A Medicare number is checked and stored in one shape whether it is typed or scanned from a hospital sticker. Prescriptions render to an A4 paper script on the practice letterhead with the specialist's signature block.

Practices sign up online and start on a 14-day trial with a card on file.

Phone, web and desktop

The iOS app has been on the Australian App Store since 4 September 2026, and the same product runs in the browser and as a Windows desktop app. On a phone, recording carries on without a connection: audio and notes are held on the device and synced when the connection returns.

The app hides clinical content in the app switcher, resumes with a biometric check after a timeout, and caps each recording session at a set length.

Security in the data layer

Tenant data sits in one PostgreSQL database under row-level security. The application sets the tenant on each transaction and the database enforces it, so a query that omits its tenant filter still cannot read another practice's rows.

The audit log is append-only at the database role and hash-chained per tenant: each row's hash covers the row before it, so an altered or removed row breaks the chain. Clinical notes carry a content-hash chain of their own, and a nightly integrity job recomputes it and reports any mismatch. Each audit row is written in the same transaction as the data change it records. Staff sign in with a password and TOTP or with a passkey, can see and end their own sessions and trusted devices, and hold single-use backup codes for recovery. The API sits behind rate limiting.

Operated in production

Black Shard runs Aurii in production: releases, monitoring, the App Store listing and each practice's messaging onboarding. Deploys run from GitHub Actions to Azure through workload identity federation, so the pipeline holds no long-lived Azure credential, and a bad release rolls back by moving traffic to the previous Container Apps revision.

Start an engagement.

Tell us what you need built, reviewed or secured.

info@blackshard.com.au