Security & Compliance – RadAssist AI

RadAssist AI is committed to maintaining the highest standards of security and compliance for healthcare technology. This page outlines our comprehensive security measures, compliance frameworks, and data protection practices.

Platform & Hosting

Microsoft Azure UK Regions:

All infrastructure hosted exclusively in Microsoft Azure UK regions to ensure data sovereignty and compliance with UK data protection requirements.

Transport Layer Security:

TLS 1.2+ encryption for all data in transit, ensuring secure communication between all system components.

Encryption at Rest:

All stored data encrypted using industry-standard AES-256 encryption with Azure-managed keys.

Identity & Access Management

Microsoft Entra ID Integration:

Single Sign-On (SSO) with Multi-Factor Authentication (MFA) for all user access.

Conditional Access Policies:

Risk-based access controls and device compliance requirements for enhanced security.

Least-Privilege Access:

Role-based access control (RBAC) ensuring users have only the minimum permissions required for their role.

Privileged Identity Management:

Just-In-Time (JIT) access for administrative functions with approval workflows and time-limited access.

Monitoring & Protection

Microsoft Defender Integration:

Advanced threat protection and real-time security monitoring across all cloud resources.

Centralized Logging:

Comprehensive audit trails and security event logging with automated alerting for suspicious activities.

Web Application Firewall:

Azure WAF protection against common web vulnerabilities and application-layer attacks.

Security Hardening:

Implementation of CIS benchmarks and security baselines across all infrastructure components.

Change Control

Tracked Changes:

All system changes are version-controlled and tracked through our development lifecycle management system.

Review & Approval Process:

Multi-stage review process with security and compliance validation before any production deployment.

Rollback Capabilities:

Automated rollback procedures to quickly revert changes if issues are detected post-deployment.

Backups & Disaster Recovery

Azure Backup Services:

Automated daily backups with geo-redundant storage across multiple Azure UK regions.

Periodic Restore Testing:

Regular testing of backup integrity and restore procedures to ensure business continuity capabilities.

Data Residency

UK by Default:

All data processing and storage occurs within UK borders by default, ensuring compliance with UK data sovereignty requirements.

International Transfer Safeguards:

No data transfers outside the UK without explicit contractual agreements and appropriate safeguards in place.

Governance & Compliance

Identifiers:

Company No: 16769710 • ICO: ZC024151 • ODS: G3A4H.

For assurance documents (DSPT statement, policies), email privacy@radassistai.com.

Registration:

Registered in England & Wales — view our Companies House listing (Company No: 16769710).

DSPT Assessment:

Data Security and Protection Toolkit assessment in progress for 2025–26 compliance period.

DTAC & DCB Standards:

Digital Technology Assessment Criteria (DTAC) and DCB 0129/0160 compliance planned and will be completed before any live patient data processing.

Key Roles & Responsibilities

Data Protection Officer (DPO):

DPO contact details and responsibilities will be published on this page prior to any live patient data processing.

Caldicott Guardian:

Caldicott Guardian information and governance framework will be published here before live deployment.

Vulnerability Disclosure

Reporting Security Issues:

Please report security vulnerabilities to security@radassistai.com

Include in Your Report:

Detailed steps to reproduce the issue, potential impact assessment, and any supporting evidence or proof-of-concept.

Important Notice:

Do not test security vulnerabilities against live NHS systems. Use only designated testing environments or contact us for coordinated disclosure.

Last updated: 14 November 2025

We use cookies to run our site and improve your experience. See our Cookies Policy.

Talk with Us