Security and data

Your patient data stays where you put it.

Verityn is built for a hospital information governance and data protection officer audience. Identifiable imaging data can stay entirely within your environment. Where cloud processing is used, data is encrypted in transit and at rest, residency is configurable, and an audit trail records every action.

TLS 1.3 in transit

All data in motion is encrypted over TLS 1.3 as a minimum.

AES-256 at rest

Stored imaging data and derived outputs are encrypted at rest.

On-premise available

Identifiable data need not leave your environment.

Full audit trail

Every study, flag, and clinical decision is logged.

Encryption

Encrypted in transit and at rest, without exception.

Every byte of imaging data and derived output is protected whether it is moving or sitting still. There are no unencrypted paths in the Verityn processing chain.

Transport layer security

All connections between clients, PACS connectors, and Verityn services use TLS 1.3 as a minimum. Certificate pinning is configurable for institutional deployments. Older protocol versions are not accepted.

Encryption at rest

Stored imaging studies, derived outputs, flag data, and audit records are encrypted at rest using AES-256. Encryption keys are managed separately from the data they protect. Key rotation is supported.

Key management

In cloud deployments, encryption keys are held in a dedicated key management service with hardware-backed key storage. In on-premise deployments, key management remains entirely within your infrastructure.

Where your data lives

On-premise, private cloud, or region-pinned cloud. Your choice.

For hospitals and networks where identifiable imaging data must not leave the institutional environment, Verityn supports fully on-premise deployment. The model runs on your hardware; no study or patient identifier is transmitted to Verityn Ltd or any third-party cloud.

Recommended for NHS

On-premise

The Verityn inference engine runs on hardware you control, inside your network perimeter. Imaging data flows from PACS to the inference node and back. Nothing leaves your environment. Suitable for sites with strict data governance requirements or where identifiable data must remain on-premise.

Private cloud

Private cloud

A dedicated, single-tenant environment hosted in a cloud region of your choosing. Compute and storage are not shared with any other customer. Network access is restricted to your institution's IP ranges. A data processing agreement covers the relationship in full.

Cloud with residency

Hosted cloud

A multi-tenant cloud deployment with data residency pinned to your chosen region (UK or EU available). Suitable where on-premise is not feasible and data residency controls are sufficient for your governance framework.

De-identification

Where imaging data is transmitted to any Verityn infrastructure for processing, a de-identification step removes DICOM header fields containing patient-identifiable information before the study reaches the inference layer. Pixel-level scrubbing is applied where identifiable information is embedded in image data. De-identified studies are processed and the results are re-linked to the original study reference within your environment.

Access control

Role-based access, SSO, and a complete audit trail.

Access to Verityn is controlled at the role level. Every action on the platform, from study review to flag dismissal to administrative change, is written to an immutable audit log.

Role-based access control

Roles are defined per institution and assigned per user: reader, supervisor, administrator, and integration service account. Permissions are additive and follow the principle of least privilege.

SSO and directory integration

SAML 2.0 and OIDC single sign-on is supported for integration with existing identity providers, including Microsoft Entra ID and Okta. Local account creation can be disabled for sites that require directory-managed access.

Multi-factor authentication

MFA is required for administrative accounts and can be enforced for all users. TOTP and WebAuthn (hardware key) methods are supported.

Audit trail

Every study, flag, and decision is logged.

The audit trail captures the full lifecycle of every study: when it arrived, which model version processed it, what flags were generated with which confidence values, which user reviewed it, what decision they recorded, and when. Records are written to an append-only log and are not modifiable after creation.

  • Study arrival timestamp and source identifier
  • Model version and inference timestamp
  • Each flag: location, confidence, reason text
  • Clinician review action and outcome
  • Any administrative action by user and role
  • Structured export in JSON and CSV

Post-market surveillance

Audit trail data is also the primary input for Verityn's post-market surveillance system. Aggregate, de-identified statistics on flag agreement and dismissal rates are reviewed on a quarterly basis to monitor for any drift in model performance in real-world deployment.

Data residency and sub-processors

Where data is processed, and who processes it.

Verityn Ltd acts as a data processor where it handles patient data on behalf of a healthcare institution. The institution remains the data controller. Sub-processors are limited and documented.

GB

United Kingdom

Data processed and stored within UK data centres, aligned with UK GDPR and NHS data security requirements. Suitable for NHS and independent sector deployments.

EU

European Union

Data processed and stored within the EEA, with no transfer to third countries without an appropriate mechanism (adequacy decision, SCCs, or equivalent). Aligned with GDPR under MDR 2017/745 context.

Custom

Custom region

On-premise deployment means data stays on your own infrastructure, in your own data centre, in whatever jurisdiction you operate. No Verityn cloud infrastructure is involved.

Sub-processors

A full sub-processor list is maintained and provided to data controllers on request. Sub-processors are limited to cloud infrastructure providers in the contracted region and to security monitoring services. Sub-processors do not have access to unencrypted patient data. The sub-processor list is reviewed on a rolling basis; data controllers receive advance notice of any material change.

Data processing agreement

A data processing agreement (DPA) is executed with every healthcare institution before any patient data is processed. The DPA covers purpose limitation, data subject rights, breach notification obligations, and sub-processor controls. Standard contractual clauses are included for any cross-border transfer where required.

Security operations

Penetration testing, incident response, and retention.

Annual penetration testing

Independent penetration tests of the Verityn platform are conducted annually by a qualified third party. Findings are risk-rated and remediated against a defined schedule. Test scope covers the API layer, web console, DICOM integration, and authentication surfaces.

Vulnerability management

Continuous automated scanning of dependencies, container images, and infrastructure configurations is in place. Critical vulnerabilities trigger an expedited review. A coordinated vulnerability disclosure programme is open to external researchers.

Incident response

A documented incident response plan covers detection, containment, eradication, and recovery. In the event of a personal data breach, affected data controllers are notified within 72 hours in line with UK GDPR and GDPR Article 33 obligations.

Retention and deletion

Data retention periods are configurable to match the institution's records management policy and applicable legal retention requirements. Verityn does not retain imaging data beyond the agreed retention window. Secure deletion, with verification, is available on request and is performed as standard at the end of any contract. Individual data subject deletion requests (right to erasure) are processed in line with UK GDPR and GDPR timelines.

DPIA support

Processing special category health data using AI decision-support tools is likely to require a Data Protection Impact Assessment (DPIA) under UK GDPR Article 35. Verityn provides a completed DPIA template and a data flow diagram to support the institution's own DPIA process. Our clinical governance and privacy team is available to work through questions with the institution's Data Protection Officer.

Responsible disclosure

If you believe you have found a security vulnerability in Verityn, please report it to security@verityn.ai. We ask that you give us a reasonable window to investigate and address the issue before any public disclosure. We will acknowledge all reports within two working days and keep you informed of progress.

Further reading for governance teams

Our regulatory posture explains deployment context by region. The data page covers our legal basis for processing.

Talk to our information governance team.

Our clinical governance and privacy team can support your DPO, provide the DPA, walk through the DPIA template, and answer questions about on-premise deployment.