Security Architecture

Protection designed in from the architecture up

Health data carries obligations that ordinary business data does not. These are the technical controls built into the platform — the detail your security and governance teams will want to review during evaluation.

Controls built into the platform

Encryption in transit and at rest

All traffic is encrypted using TLS. Stored data is encrypted at rest using industry-standard algorithms, with managed key rotation.

Role-based access control

Permissions are tied to clinical role, department and facility, following the principle of least privilege. Access is granted by function, not by request.

Immutable audit trails

Every record access, modification and export is logged with user, timestamp and context. Logs are retained and searchable for investigation.

Authentication controls

Multi-factor authentication, session management, password policy enforcement and enterprise SSO integration via SAML.

Network segmentation

Application, data and management planes are separated, with restricted administrative access paths and no direct database exposure.

Backup and disaster recovery

Regular backups with tested restore procedures, defined recovery point and recovery time objectives agreed per deployment.

Business continuity

Redundant infrastructure and failover configuration so clinical operations continue through component failure or disruption.

Continuous monitoring

Infrastructure and application monitoring with alerting on anomalous access patterns and failed authentication attempts.

Data residency control

Choose the region your data is stored and processed in, or keep it entirely on your own infrastructure under an on-premises deployment.

Shared responsibility

Where our obligations end and yours begin

Security in a healthcare deployment is never entirely one party’s job. The split depends on your deployment model, and we document it explicitly in the service agreement rather than leaving it assumed.

MediNeura is responsible for

  • Platform application security and patching
  • Infrastructure security in cloud deployments
  • Encryption implementation and key management
  • Audit logging and monitoring capability
  • Vulnerability management in our codebase

Your organisation is responsible for

  • User account lifecycle and role assignment
  • Reviewing audit logs and access reports
  • Endpoint and device security
  • Staff training and acceptable use policy
  • Infrastructure operation in on-premises deployments

Discussing compliance requirements

Regulatory obligations differ substantially by jurisdiction, organisation type and the categories of data you process. Rather than list frameworks generically, we work through your specific requirements during procurement — what your regulator expects, what your governance process needs to see, and what contractual terms are required.

Bring your information governance or security lead to the evaluation. Contact our team to arrange a technical session and request the security documentation relevant to your deployment model.

Arrange a technical security review

We will walk your security team through the architecture, controls and shared responsibility model for your chosen deployment.