Security built for medical records

UK GDPR and DPA 2018 compliant medical record review with UK data residency, AES-256 encryption and zero AI training on client records.

UK GDPR & DPA 2018

Special category health data processed under a documented lawful basis with a data processing agreement for every firm.

UK data residency

Bundles, OCR text and chronologies are stored in UK/EU regions.

AES-256 encryption

Encrypted at rest and TLS 1.2+ in transit.

No model training

Your client records are never used to train AI models.

Role-based access

Firm admin, fee earner, medical expert and read-only viewer roles. Users only see their own case conversations.

Fail-closed ingestion

Every upload is malware-scanned; anything suspicious is blocked before processing.