Patient data deserves boring, verifiable security.
Tiro.health is built for European outpatient care: EU hosting, encryption everywhere, strict access control and no model training on patient data.
EU data residency
All patient data is stored and processed inside the European Union, on infrastructure with documented sub-processors.
Encrypted end to end
TLS 1.2+ in transit and AES-256 at rest, with key management separated from application access.
Audited access
Role-based access per practice, least-privilege defaults and an immutable audit trail on every record view and change.
No training on your data
Patient content is never used to train foundation models. AI processing runs per request and is not retained for model improvement.
Security is a process, not a badge.
Platform
- Isolated per-practice data boundaries
- Automated backups with point-in-time recovery
- Continuous dependency and vulnerability scanning
- Infrastructure as code with reviewed changes
People
- Least-privilege staff access, reviewed quarterly
- Mandatory MFA on all internal systems
- Confidentiality and data-handling training
- Documented onboarding and offboarding
Response
- Documented incident response procedure
- Breach notification within regulatory deadlines
- Security contact for responsible disclosure
- Post-incident review shared with affected clinics
Built against the rules that apply to clinics.
We work with practices and hospitals that carry their own regulatory obligations, so our documentation is designed to plug into theirs.
- GDPR
- Processing as a data processor on behalf of the practice, with a Data Processing Agreement, records of processing and documented sub-processors.
- Medical device scope
- Tiro.health is a clinical documentation system. Features that would fall under MDR are scoped, assessed and documented before release.
- Interoperability
- FHIR resources and SNOMED CT coding so data leaves the record in a standard shape, including for hospital integrations.
- Availability
- Monitored uptime with alerting, and a defined maintenance window communicated to clinics in advance.
Need our security documentation?
We share our DPA, sub-processor list and security overview with practices and hospital IT teams on request.




