Tiro.health logoTiro.health
Security and privacy

Patient data deserves boring, verifiable security.

Tiro.health is built for European outpatient care: EU hosting, encryption everywhere, strict access control and no model training on patient data.

EU data residency

All patient data is stored and processed inside the European Union, on infrastructure with documented sub-processors.

Encrypted end to end

TLS 1.2+ in transit and AES-256 at rest, with key management separated from application access.

Audited access

Role-based access per practice, least-privilege defaults and an immutable audit trail on every record view and change.

No training on your data

Patient content is never used to train foundation models. AI processing runs per request and is not retained for model improvement.

How we work

Security is a process, not a badge.

Platform

  • Isolated per-practice data boundaries
  • Automated backups with point-in-time recovery
  • Continuous dependency and vulnerability scanning
  • Infrastructure as code with reviewed changes

People

  • Least-privilege staff access, reviewed quarterly
  • Mandatory MFA on all internal systems
  • Confidentiality and data-handling training
  • Documented onboarding and offboarding

Response

  • Documented incident response procedure
  • Breach notification within regulatory deadlines
  • Security contact for responsible disclosure
  • Post-incident review shared with affected clinics
Compliance

Built against the rules that apply to clinics.

We work with practices and hospitals that carry their own regulatory obligations, so our documentation is designed to plug into theirs.

GDPR
Processing as a data processor on behalf of the practice, with a Data Processing Agreement, records of processing and documented sub-processors.
Medical device scope
Tiro.health is a clinical documentation system. Features that would fall under MDR are scoped, assessed and documented before release.
Interoperability
FHIR resources and SNOMED CT coding so data leaves the record in a standard shape, including for hospital integrations.
Availability
Monitored uptime with alerting, and a defined maintenance window communicated to clinics in advance.

Need our security documentation?

We share our DPA, sub-processor list and security overview with practices and hospital IT teams on request.