Security & Trust
Enterprise-grade healthcare data protection with GDPR-aligned controls
Security at a Glance
How We Protect Your Data
Medical Data Encryption
All patient data is encrypted using AES-256 at rest and TLS 1.2+ in transit. Sensitive health identifiers receive additional field-level encryption via AWS KMS for defence in depth.
Strong Access Controls
Multi-factor authentication is mandatory for all users. Role-based access control ensures staff only access what they need for their role.
Enterprise Infrastructure
Fully serverless architecture on AWS with multi-availability zone redundancy. Private subnet architecture and encrypted databases protect your data at the infrastructure level.
Activity Logging
Key actions within the platform are logged. This includes authentication events, data access, and administrative changes to support accountability.
Independent Validation
Our security controls are verified by independent third parties, not just self-assessed.
CREST-Certified Penetration Testing
Annual penetration testing by a CREST-accredited provider. Our most recent test found zero critical vulnerabilities and independently confirmed multi-tenant data isolation.
Certification Roadmap
Actively pursuing Cyber Essentials Plus (2026) and ISO 27001:2022 certification to complement our existing technical controls and ISMS framework.
AWS Infrastructure Certifications
Built on AWS infrastructure that holds SOC 2, ISO 27001, and HIPAA certifications at the platform level, providing a certified foundation for our application security.
Regulatory Alignment and GDPR Compliance
ScreenIT is designed to meet the requirements of healthcare data protection regulations in our target markets.
GDPR Compliance (EU/UK)
Designed to comply with the General Data Protection Regulation. ScreenIT acts as a Data Processor; your organisation remains the Data Controller. We offer data residency in Australia for Australian organisations and in Ireland for UK and EU organisations and Data Processing Agreements (DPAs) are available upon request.
Australian Privacy Act
Designed to comply with the Australian Privacy Principles (APPs). Patient data can be stored exclusively in Australian data centres.
Data Minimisation
We collect only information necessary for clinical purposes. We are committed to responsible data practices and transparent communication about how data is used.
Your Data, Your Control
We believe healthcare providers should have full control over their patient information. Patient data protection is central to everything we do. Here is our commitment to you:
Data Portability
We can provide exports of your data upon request. Contact our support team to arrange data exports in standard formats.
Right to Deletion
You can request deletion of patient records. We will process deletion requests in accordance with applicable regulations and confirm completion.
Transparent Data Practices
We will always be clear about how patient data is used. Any future changes to data practices will be communicated in advance with your consent.
Questions About Your Data?
If you have questions about data handling, exports, or deletion, our team is here to help. We are committed to working with you to meet your data management needs.
Review our legal documentation:
Privacy PolicyClinician TermsSub-processorsEmail SupportBuilt for Reliability
Clinical workflows need dependable systems. Our infrastructure is designed with redundancy and recovery in mind.
Multi-AZ
Redundancy
Multiple availability zones for resilience
Daily
Backups
Automated with point-in-time recovery
Encrypted
Storage
All data encrypted at rest and in transit
Your Role in Security
Security is a shared responsibility. While we protect the platform, here is how you can help protect your patients.
Use Strong, Unique Passwords
Choose passwords at least 12 characters long, combining letters, numbers, and symbols. Never reuse passwords across different services.
Secure Your Devices
Keep operating systems and browsers updated. Use device encryption and automatic screen locks. Avoid accessing patient data on public Wi-Fi.
Watch for Phishing
Be cautious of unexpected emails requesting login credentials. ScreenIT will never ask for your password via email. When in doubt, contact us directly.
Manage Team Access
Review who has access to your organisation's account periodically. Remove users who no longer need access when they leave your organisation.
Report Concerns
If you notice unusual activity or suspect a security issue, contact support@yourbrainhealth.io. Early reporting helps protect everyone.
Frequently Asked Questions
Is ScreenIT GDPR compliant?
ScreenIT is designed to comply with GDPR requirements. We implement appropriate technical and organisational measures including encryption, access controls, and data minimisation. We offer data residency in Australia for Australian organisations and in Ireland for UK and EU organisations, and Data Processing Agreements (DPAs) are available upon request. Contact support@yourbrainhealth.io to discuss your compliance requirements.
Where is my data stored?
ScreenIT offers regional data residency. Data for Australian organisations is stored in Australia; data for UK and EU organisations is stored in Ireland. You select your region at signup and your live data remains in that location. Backup copies are held in a second location, which is set out in our Data Processing Agreement.
Can I get a copy of my data?
Yes. We can provide exports of your data upon request. Contact support@yourbrainhealth.io and our team will work with you to provide your data in a suitable format. Please allow reasonable time for processing data export requests.
What happens if there's a data breach?
In the unlikely event of a data breach affecting your data, we will notify you within 72 hours as required by GDPR. We will provide information about what occurred, what data was affected, and what steps we are taking. We take our notification obligations seriously.
How do you handle account access when staff leave?
Administrators can remove user access through the ScreenIT dashboard. We recommend reviewing access permissions regularly and removing users promptly when they leave your organisation.
What authentication methods does ScreenIT support?
All ScreenIT accounts require multi-factor authentication (MFA) using time-based one-time passwords (TOTP). This works with authenticator apps like Google Authenticator, Microsoft Authenticator, or Authy. SSO/SAML integration is on our roadmap. Contact us to discuss your requirements.
Do you conduct penetration testing?
Yes. We engage a CREST-accredited provider for annual penetration testing covering application security, API security, infrastructure configuration, and multi-tenant isolation. Our most recent test found zero critical vulnerabilities. Executive summaries are available to customers under NDA upon request.
How often do you back up data?
Data is backed up daily with point-in-time recovery capability. Backups are encrypted and stored securely. In the event of data loss, we can restore your data from these backups.
Can I request deletion of patient data?
Yes. You can request deletion of patient records at any time. We will process your request in accordance with applicable data protection regulations and confirm when deletion is complete. Contact support@yourbrainhealth.io for deletion requests.
Who do I contact about security questions?
For all technical queries including security questions, data requests, or to report a concern, contact support@yourbrainhealth.io. We aim to respond to all enquiries promptly.
Questions About Security?
Our team is happy to discuss our security practices and answer your questions.
Email UsTrusted by Healthcare Professionals
99242
Screenings completed
1132
Clinicians registered
4782
Patient records secured
Built on Enterprise Infrastructure
AWS Cloud
Enterprise infrastructure with multi-AZ redundancy
AES-256
Industry-standard encryption at rest and in transit
MFA Required
Mandatory multi-factor authentication for all accounts
AU | EU
Regional data residency with region-locked storage
Learn more about AWS Security