Security and compliance built into every layer

Security

Patient data demands
more than a checkbox.

We operate inside one of the most regulated industries in the UK. Security is not a feature we ship. It is the condition under which everything else works.

UK data residency
UK GDPR compliant
GPhC and CQC support
MHRA aligned
Scroll

Infrastructure

Built in the UK.
Stays in the UK.

UK-only data residency

All patient and clinical data is stored and processed on Hetzner infrastructure located within the United Kingdom. Nothing leaves UK borders.

Encrypted in transit and at rest

TLS 1.2 or higher on all connections. Data at rest is encrypted using AES-256. This applies to all environments, including backups.

Isolated environments

Production, staging, and development environments are fully separated. No shared credentials. No cross-environment data access.

Containerised and version-controlled

All services run in Docker containers. Infrastructure changes go through version control, and rollbacks take minutes.

Data privacy

UK GDPR is not
a bolt-on.

UK GDPR compliant by design

Data minimisation, purpose limitation, and retention policies are built into the platform architecture—not applied as an afterthought.

Access controls and session management

Role-based access controls limit what each user can see and do. Sessions are time-limited, authenticated, and logged. Privileged access requires additional verification.

Data processing agreements

We operate as a data processor under UK GDPR. Data processing agreements are available for all clients and reviewed by our legal team.

Right to erasure

Patient data deletion requests are handled within statutory timeframes. Audit trails of deletions are maintained as required.

Clinical compliance

Regulated end
to end.

GPhC and CQC support

Our platform and dispensing workflows are built to support and inspection requirements. Documentation, audit trails, and SOPs are accessible and inspection-ready.

MHRA-aligned prescribing workflows

Online prescribing flows built on the platform follow guidance for remote prescribing and clinical decision support.

Clinical audit trails

Every prescribing and dispensing event is logged with timestamp, practitioner identity, and patient record reference. Logs are immutable and exportable.

Multi-tenancy and data isolation

Each client’s data is logically isolated within the platform. No client can access another’s patient records, configuration, or operational data. Isolation is enforced at both application and database layers.

Clinical safety

DCB0129 registered.

DataForge meets the NHS England Clinical Risk Management standard for health IT manufacturers. Our clinical safety documentation is maintained, reviewed and approved by a GMC-registered Clinical Safety Officer.

StandardDCB0129Amd 24/2018

Questions

Something not covered here?
Ask us directly.

Procurement teams, IT leads and clinical governance officers are welcome to contact us with specific questions. We reply within one working day.