Privacy & security
How we protect patient data.
How patient data is stored, accessed and protected in Rhazes.
Data protection standards.
Privacy is built into Rhazes from the start. We follow the data-protection laws that apply, including GDPR, and HIPAA-aligned standards.
Data is encrypted when sent and stored. People only see what their role allows, and access is logged.
Read the product privacy policySecurity controls.
Explore how access, testing and data separation work together.
Access checks and monitoring
Enterprise runs on secure cloud servers. Every request for access is checked (zero-trust), and activity is logged and monitored.
Regular security testing
We run penetration tests and security reviews to find and fix weak spots.
Protected encryption keys
Dedicated secure hardware protects your encryption keys and other secrets.
Separate data
Clinical data is kept apart from our system monitoring and analytics. Customer data is not used to train foundation models (large, general-purpose AI models).
Customer data is not used to train foundation models.
Large, general-purpose AI models.Hosting for your organisation.
With Enterprise, your data can stay in your region, on a dedicated setup or a shared one with your data kept separate.
Before you go live, agree with us where data is hosted, who can access it and where it goes.
Documents for your security review.
Enterprise and government teams can ask for our security documents, system diagrams and compliance questionnaires, under a non-disclosure agreement.
- Security documents
- System diagrams
- Questionnaires
