Security overview
Last updated 18 Jul 2026 · version 0.2 (draft)
Draft — pending legal review. This wording is a working placeholder and must be approved by counsel for each corridor before launch.
1. Encryption
All data is encrypted with AES-256 at rest and TLS 1.3 in transit — no exceptions, including internal service-to-service traffic. Documents are stored as PDF/A where applicable; imaging transfers are chunked and resumable so nothing travels unencrypted or incomplete.
2. Hosting and residency
Case data is pinned to the region its corridor requires, set automatically at intake. French health data is hosted on HDS-certified infrastructure in the EEA; other corridors use UK or EEA regions. The residency region is shown on every case and confirmed on the governance dashboard.
3. Access control
Five roles on a least-privilege basis, mandatory multi-factor authentication, session timeout on inactivity, user-visible session and device revocation, and time-limited receiving access that expires after 90 days of case inactivity. Referrals route to a named specialist — never a shared inbox.
4. Audit
Every view, download, export, consent event, and status change is written to an append-only, tamper-evident audit log. A regulator can reconstruct any case from the audit trail alone — that is a design requirement, not an aspiration.
5. Responsible disclosure
Found a vulnerability? Report it via the contact page marked “security”. We acknowledge within two working days, won’t pursue good-faith research conducted without accessing real patient data, and credit fixes where wanted. Formal certifications (Cyber Essentials Plus, ISO 27001) are on the published roadmap.
Questions about this document? Contact LibaMed Ltd, Cardiff, Wales — we aim to respond within two working days.