Privacy & security

How we protect patient data.

How patient data is stored, accessed and protected in Rhazes.

Protection built around patient data.Encrypted data. Role-based access. Logged activity.

Data protection standards.

Privacy is built into Rhazes from the start. We follow the data-protection laws that apply, including GDPR, and HIPAA-aligned standards.

Data is encrypted when sent and stored. People only see what their role allows, and access is logged.

Read the product privacy policy
GDPRApplicable data-protection law
HIPAAAligned standards

Security controls.

Explore how access, testing and data separation work together.

Access checks and monitoring

Enterprise runs on secure cloud servers. Every request for access is checked (zero-trust), and activity is logged and monitored.

Regular security testing

We run penetration tests and security reviews to find and fix weak spots.

Protected encryption keys

Dedicated secure hardware protects your encryption keys and other secrets.

Separate data

Clinical data is kept apart from our system monitoring and analytics. Customer data is not used to train foundation models (large, general-purpose AI models).

Illustration of security controls

Customer data is not used to train foundation models.

Large, general-purpose AI models.

Hosting for your organisation.

With Enterprise, your data can stay in your region, on a dedicated setup or a shared one with your data kept separate.

Before you go live, agree with us where data is hosted, who can access it and where it goes.

Enterprise hosting
Your agreed region
Dedicated setupYour organisation
Shared setupYour data kept separate
Hosting options are agreed with your organisation before you go live.

Documents for your security review.

Enterprise and government teams can ask for our security documents, system diagrams and compliance questionnaires, under a non-disclosure agreement.

  • Security documents
  • System diagrams
  • Questionnaires