Security & governance
Governance considered from the start
We keep a clear line between what is in place today and what is planned for the platform, which is still in development.
In place today
On this website
- Encrypted connections (HTTPS) across this website
- Cookie consent before any optional cookies
- A data rights request process with tracked references
- Enquiries stored with access limited to server-side systems
Planned
For the Clinvela platform
- Organisation-specific roles and controlled membership
- Governed configuration with reviewable activity
- Clinvela Ledger: histories designed to make unauthorised changes detectable
- Access that follows local policy — seniority alone does not grant access to every patient
- Visible service status and exception handling
Regulatory landscape
The frameworks we are designing against
These are frameworks we are designing against, subject to assessment. Clinvela does not currently hold any certification, approval or clearance under them, and each deploying organisation stays responsible for its own compliance.
EU & Ireland
- • EU GDPR and the Irish Data Protection Act 2018
- • EU AI Act
- • NIS2
- • European Health Data Space
- • EU MDR — to be assessed for relevant features
United Kingdom
- • UK GDPR and Data Protection Act 2018
- • NHS Data Security and Protection Toolkit
- • DTAC
- • DCB0129 / DCB0160 clinical safety standards
United States
- • HIPAA and HITECH, including Business Associate Agreements where relevant
Due diligence
A planned assessment process
Detailed assurance information is available to legitimate due diligence through a controlled process — for example, supporting data protection impact assessments and clinical safety reviews. Contact us to start that conversation.
Early access
Start a governance conversation
Clinvela is in development. Register your interest in a product walkthrough or design-partner discussion.
