Encryption in transit and at rest
All traffic is encrypted using TLS. Stored data is encrypted at rest using industry-standard algorithms, with managed key rotation.
Health data carries obligations that ordinary business data does not. These are the technical controls built into the platform — the detail your security and governance teams will want to review during evaluation.
All traffic is encrypted using TLS. Stored data is encrypted at rest using industry-standard algorithms, with managed key rotation.
Permissions are tied to clinical role, department and facility, following the principle of least privilege. Access is granted by function, not by request.
Every record access, modification and export is logged with user, timestamp and context. Logs are retained and searchable for investigation.
Multi-factor authentication, session management, password policy enforcement and enterprise SSO integration via SAML.
Application, data and management planes are separated, with restricted administrative access paths and no direct database exposure.
Regular backups with tested restore procedures, defined recovery point and recovery time objectives agreed per deployment.
Redundant infrastructure and failover configuration so clinical operations continue through component failure or disruption.
Infrastructure and application monitoring with alerting on anomalous access patterns and failed authentication attempts.
Choose the region your data is stored and processed in, or keep it entirely on your own infrastructure under an on-premises deployment.
Security in a healthcare deployment is never entirely one party’s job. The split depends on your deployment model, and we document it explicitly in the service agreement rather than leaving it assumed.
Regulatory obligations differ substantially by jurisdiction, organisation type and the categories of data you process. Rather than list frameworks generically, we work through your specific requirements during procurement — what your regulator expects, what your governance process needs to see, and what contractual terms are required.
Bring your information governance or security lead to the evaluation. Contact our team to arrange a technical session and request the security documentation relevant to your deployment model.
We will walk your security team through the architecture, controls and shared responsibility model for your chosen deployment.