Certified to every
standard that matters.
MediVault maintains active certifications across HIPAA, Swiss FADP, ISO 27001, and SOC 2 Type II. Our compliance posture is independently audited and continuously monitored — not just a checkbox exercise.
All ePHI is encrypted using AES-256-GCM both at rest and in transit using TLS 1.3.
Cryptographically signed, immutable audit logs for every record access event.
HMAC-SHA512 integrity verification on every data object. Any modification is detected immediately.
TLS 1.3 enforced for all API communications. HSTS with 2-year max-age.
Technical and organisational measures proportionate to the risk. MediVault implements a full ISO 27001-aligned security framework.
Data minimisation and purpose limitation are enforced at the schema level. Consent gates are embedded in the data model.
Automated breach detection with <72h notification SLA to the FDPIC and affected data subjects.
Standard AVV (data processing agreement) available for all customers. No sub-processors outside Switzerland.
Defined cryptographic policy covering key lengths, algorithms, and key lifecycle management.
Centralised, append-only log infrastructure with automated alerting on anomalous access patterns.
Continuous vulnerability scanning, monthly penetration tests, and a responsible disclosure programme.
All cloud services audited against ISO 27017 and 27018. Swiss-only data centre footprint.
MFA enforced for all administrative access. Principle of least privilege applied at every level.
24/7 SIEM with automated alerting. Mean time to detect (MTTD) < 4 minutes.
Annual third-party risk assessment. Vendor due diligence programme for all sub-processors.
99.99% SLA guaranteed contractually. RPO < 1 hour, RTO < 4 hours.
Audit documentation
We publish redacted versions of our audit reports annually. Full reports are available to enterprise customers under NDA.