Skip to content

Security & Trust

Enterprise-grade healthcare data protection with GDPR-aligned controls

Security at a Glance

Encryption at Rest
AES-256
Industry standard
Encryption in Transit
TLS 1.2+
Pen-test validated
Authentication
Mandatory MFA (TOTP)
All users
Data Residency
Australia and Ireland
Region-locked
Backups
Daily automated, region-locked
Point-in-time recovery
Penetration Testing
CREST-certified, annual
Zero critical findings
Infrastructure
AWS serverless (Multi-AZ)
Enterprise cloud

How We Protect Your Data

Medical Data Encryption

All patient data is encrypted using AES-256 at rest and TLS 1.2+ in transit. Sensitive health identifiers receive additional field-level encryption via AWS KMS for defence in depth.

Strong Access Controls

Multi-factor authentication is mandatory for all users. Role-based access control ensures staff only access what they need for their role.

Enterprise Infrastructure

Fully serverless architecture on AWS with multi-availability zone redundancy. Private subnet architecture and encrypted databases protect your data at the infrastructure level.

Activity Logging

Key actions within the platform are logged. This includes authentication events, data access, and administrative changes to support accountability.

Independent Validation

Our security controls are verified by independent third parties, not just self-assessed.

  • CREST-Certified Penetration Testing

    Annual penetration testing by a CREST-accredited provider. Our most recent test found zero critical vulnerabilities and independently confirmed multi-tenant data isolation.

  • Certification Roadmap

    Actively pursuing Cyber Essentials Plus (2026) and ISO 27001:2022 certification to complement our existing technical controls and ISMS framework.

  • AWS Infrastructure Certifications

    Built on AWS infrastructure that holds SOC 2, ISO 27001, and HIPAA certifications at the platform level, providing a certified foundation for our application security.

Regulatory Alignment and GDPR Compliance

ScreenIT is designed to meet the requirements of healthcare data protection regulations in our target markets.

  • GDPR Compliance (EU/UK)

    Designed to comply with the General Data Protection Regulation. ScreenIT acts as a Data Processor; your organisation remains the Data Controller. We offer data residency in Australia for Australian organisations and in Ireland for UK and EU organisations and Data Processing Agreements (DPAs) are available upon request.

  • Australian Privacy Act

    Designed to comply with the Australian Privacy Principles (APPs). Patient data can be stored exclusively in Australian data centres.

  • Data Minimisation

    We collect only information necessary for clinical purposes. We are committed to responsible data practices and transparent communication about how data is used.

Your Data, Your Control

We believe healthcare providers should have full control over their patient information. Patient data protection is central to everything we do. Here is our commitment to you:

  • Data Portability

    We can provide exports of your data upon request. Contact our support team to arrange data exports in standard formats.

  • Right to Deletion

    You can request deletion of patient records. We will process deletion requests in accordance with applicable regulations and confirm completion.

  • Transparent Data Practices

    We will always be clear about how patient data is used. Any future changes to data practices will be communicated in advance with your consent.

Questions About Your Data?

If you have questions about data handling, exports, or deletion, our team is here to help. We are committed to working with you to meet your data management needs.

Review our legal documentation:

Privacy PolicyClinician TermsSub-processorsEmail Support

Built for Reliability

Clinical workflows need dependable systems. Our infrastructure is designed with redundancy and recovery in mind.

Multi-AZ

Redundancy

Multiple availability zones for resilience

Daily

Backups

Automated with point-in-time recovery

Encrypted

Storage

All data encrypted at rest and in transit

Your Role in Security

Security is a shared responsibility. While we protect the platform, here is how you can help protect your patients.

  • Use Strong, Unique Passwords

    Choose passwords at least 12 characters long, combining letters, numbers, and symbols. Never reuse passwords across different services.

  • Secure Your Devices

    Keep operating systems and browsers updated. Use device encryption and automatic screen locks. Avoid accessing patient data on public Wi-Fi.

  • Watch for Phishing

    Be cautious of unexpected emails requesting login credentials. ScreenIT will never ask for your password via email. When in doubt, contact us directly.

  • Manage Team Access

    Review who has access to your organisation's account periodically. Remove users who no longer need access when they leave your organisation.

  • Report Concerns

    If you notice unusual activity or suspect a security issue, contact support@yourbrainhealth.io. Early reporting helps protect everyone.

Frequently Asked Questions

Is ScreenIT GDPR compliant?

ScreenIT is designed to comply with GDPR requirements. We implement appropriate technical and organisational measures including encryption, access controls, and data minimisation. We offer data residency in Australia for Australian organisations and in Ireland for UK and EU organisations, and Data Processing Agreements (DPAs) are available upon request. Contact support@yourbrainhealth.io to discuss your compliance requirements.

Where is my data stored?

ScreenIT offers regional data residency. Data for Australian organisations is stored in Australia; data for UK and EU organisations is stored in Ireland. You select your region at signup and your live data remains in that location. Backup copies are held in a second location, which is set out in our Data Processing Agreement.

Can I get a copy of my data?

Yes. We can provide exports of your data upon request. Contact support@yourbrainhealth.io and our team will work with you to provide your data in a suitable format. Please allow reasonable time for processing data export requests.

What happens if there's a data breach?

In the unlikely event of a data breach affecting your data, we will notify you within 72 hours as required by GDPR. We will provide information about what occurred, what data was affected, and what steps we are taking. We take our notification obligations seriously.

How do you handle account access when staff leave?

Administrators can remove user access through the ScreenIT dashboard. We recommend reviewing access permissions regularly and removing users promptly when they leave your organisation.

What authentication methods does ScreenIT support?

All ScreenIT accounts require multi-factor authentication (MFA) using time-based one-time passwords (TOTP). This works with authenticator apps like Google Authenticator, Microsoft Authenticator, or Authy. SSO/SAML integration is on our roadmap. Contact us to discuss your requirements.

Do you conduct penetration testing?

Yes. We engage a CREST-accredited provider for annual penetration testing covering application security, API security, infrastructure configuration, and multi-tenant isolation. Our most recent test found zero critical vulnerabilities. Executive summaries are available to customers under NDA upon request.

How often do you back up data?

Data is backed up daily with point-in-time recovery capability. Backups are encrypted and stored securely. In the event of data loss, we can restore your data from these backups.

Can I request deletion of patient data?

Yes. You can request deletion of patient records at any time. We will process your request in accordance with applicable data protection regulations and confirm when deletion is complete. Contact support@yourbrainhealth.io for deletion requests.

Who do I contact about security questions?

For all technical queries including security questions, data requests, or to report a concern, contact support@yourbrainhealth.io. We aim to respond to all enquiries promptly.

Questions About Security?

Our team is happy to discuss our security practices and answer your questions.

Email Us

Trusted by Healthcare Professionals

99242

+

Screenings completed

1132

+

Clinicians registered

4782

+

Patient records secured

Built on Enterprise Infrastructure

AWS Cloud

Enterprise infrastructure with multi-AZ redundancy

AES-256

Industry-standard encryption at rest and in transit

MFA Required

Mandatory multi-factor authentication for all accounts

AU | EU

Regional data residency with region-locked storage

Learn more about AWS Security