Protecting data that cannot be re-collected
A breach in a national health system is not a service incident. These are the controls that protect patient data across every deployment we run.
Platform controls
Built into the platform rather than configured per installation, so every deployment inherits the same baseline.
Encryption in transit and at rest
SHA-256 encryption for stored data and TLS for all data in transit, including integration traffic between the platform and external national services.
Role-based access control
Access is granted by clinical and administrative role, scoped to facility and department, so a user sees only the records their function requires.
Full audit logging
Every record access, modification and export is logged with user, timestamp and context, and the log is retained for the period the contracting authority requires.
De-identification
GDPR-compliant de-identification for secondary use, so research, reporting and analytics run without exposing identifiable patient data.
Authentication
Integration with national identity providers and enterprise directories, with multi-factor authentication available for administrative and remote access.
Segregation between tenants
Multi-tenant deployments keep hospital instances logically isolated inside clustered environments, so one facility cannot reach another's records.
Where data lives
Health data sovereignty is a procurement requirement before it is a technical one.
National data residency
National programmes run inside the country's own infrastructure. Patient data does not leave the jurisdiction unless the contracting ministry explicitly directs otherwise.
Deployment model is yours to choose
On-premise, private cloud or hybrid, delivered as Docker containers. We do not require that data be hosted on infrastructure we control.
Defined data ownership
The contracting authority owns the data. Our access is limited to what support and maintenance require, and is logged like any other access.
Operational security
Controls matter less than what happens on the day something goes wrong.
Incident response
Defined severity levels, response times and escalation paths, including notification obligations to the contracting authority and, where applicable, data protection regulators.
Vulnerability management
Dependencies and platform components are monitored for known vulnerabilities, with patching prioritised by severity and deployed through controlled release management.
Business continuity
Backup, restore and failover procedures tested against recovery objectives agreed per programme, because national systems have no acceptable maintenance window.
Change control
Versioned releases with documented approval and rollback, so a security fix can be deployed without becoming an availability incident.
Our information security management system is certified to ISO 27001. Certification documents and audit summaries are available for tender submissions on the quality and certification page.
Reporting a vulnerability
If you believe you have found a security issue in one of our systems, we want to hear about it directly and we will not pursue researchers who report in good faith.
Need our security documentation?
We can provide security architecture documentation, certification evidence and completed security questionnaires for procurement.