🔒 Security & Compliance

Carelyx is built for clinical environments where data accuracy, privacy, and auditability are critical.

🇪🇺 EU-region hosting 🔐 Encrypted in transit & at rest 📋 Full audit logs 👥 Role-based access

🛡 Data Protection

All data is encrypted in transit (HTTPS) and at rest. Infrastructure is hosted in EU-region servers (London).

We do not sell, rent, or share patient data with third parties.

👥 Access Control

Role-based access ensures users only see what they are authorized to access.

Doctors, nurses, admins, and patients have clearly defined permissions.

📋 Audit & Traceability

All key actions are logged and traceable — including patient updates, notes, and treatment changes.

This enables full audit trails for clinical workflows and compliance requirements.

🤖 AI Safety & Explainability

AI outputs in Carelyx are structured, explainable, and grounded in patient data.

The system does not generate uncontrolled or black-box decisions — all outputs are designed to support, not replace, clinical judgment.

📑 Compliance

Carelyx is designed with GDPR principles and healthcare compliance standards in mind.

Formal certifications (HIPAA / GDPR readiness) are in progress (target: Q2 2026).

Business Associate Agreements (BAA) are available for applicable plans.

🧠 Our Approach

We design systems for high-risk environments — where data integrity, traceability, and reliability are essential.

Security is not an add-on — it is built into every layer of the system.

Security inquiries

Contact us at [email protected]