Privacy & security

# How we protect patient data.

How patient data is stored, accessed and protected in Rhazes.

[Explore the safeguards](/compliance/#architecture) · [Read the privacy policy](https://clinician.rhazes.ai/privacy)

## Data protection standards.

Privacy is built into Rhazes from the start. We follow the data-protection laws that apply, including GDPR, and HIPAA-aligned standards.

Data is encrypted when sent and stored. People only see what their role allows, and access is logged.

[Read the product privacy policy](https://clinician.rhazes.ai/privacy)

GDPR: applicable data-protection law. HIPAA: aligned standards.

## Security controls.

Explore how access, testing and data separation work together.

### Access checks and monitoring

Enterprise runs on secure cloud servers. Every request for access is checked (zero-trust), and activity is logged and monitored.

### Regular security testing

We run penetration tests and security reviews to find and fix weak spots.

### Protected encryption keys

Dedicated secure hardware protects your encryption keys and other secrets.

### Separate data

Clinical data is kept apart from our system monitoring and analytics. Customer data is not used to train foundation models (large, general-purpose AI models).

## Hosting for your organisation.

With Enterprise, your data can stay in your region, on a dedicated setup or a shared one with your data kept separate.

Before you go live, agree with us where data is hosted, who can access it and where it goes.

Hosting options: a dedicated setup for your organisation, or a shared setup with your data kept separate.

[Discuss your hosting needs](mailto:contact@rhazes.ai?subject=Rhazes%20Enterprise%20hosting)

## Documents for your security review.

Enterprise and government teams can ask for our security documents, system diagrams and compliance questionnaires, under a non-disclosure agreement.

[Request security documents](mailto:contact@rhazes.ai?subject=Rhazes%20security%20documentation)
