Skip to main content

Security questionnaire answers

Written to be answered from directly. Each links to the fuller treatment.

Data handling

Where is patient data stored? On the clinician's device, in browser local storage and IndexedDB. It is not transmitted to or stored by the supplier. Data flows

Can the supplier access patient data? No. There is no server-side clinical store and no mechanism to retrieve one.

Is patient data encrypted at rest? On-device data is protected by the browser's origin isolation and the device's own encryption and lock policy — i.e. by the organisation's device management. The supplier holds no clinical data to encrypt.

Is data encrypted in transit? Yes. HTTPS only, TLS, HSTS with preload. Security model

Where is data processed geographically? Application hosting is UK-based. Google and Stripe may process outside the UK/EEA under their own commitments. Subprocessors

Is data shared with third parties? Only the subprocessors listed, each for a stated purpose. No data is sold, and no data is shared for advertising.

AI

Is AI used, and on what data? Yes, optionally and user-initiated. A redacted summary of structured clinical findings is sent to Google Gemini when a clinician runs an AI feature. What gets sent

Is our data used to train models? The AI features are used through Google's API rather than a consumer product. We do not provide data for model training.

Are prompts and responses retained? No. We log feature name, token counts and cost only — never content.

Is the output clinically validated? No, and it is not presented as such. Output is an explicitly labelled draft for a clinician to check; clinical responsibility remains with the clinician. AI overview

Can AI features be disabled? They are individually gateable and are never invoked without an explicit user action. For an organisation-wide requirement, talk to us.

Authentication and access

What authentication is used? Google Firebase Authentication, email and password. No supplier-held passwords. Security model

Is MFA available? Not currently for standard accounts. Some risk-flagged registrations require mobile verification.

Is SSO available? Not currently. Raise it with us if it is a requirement.

How is authorisation enforced? Server-side on every privileged operation. Entitlement, role and organisation membership are derived server-side and never taken from the client.

Is administrative access logged? Yes — every administrative mutation appends to an immutable audit log, with sensitive values recorded as "changed" rather than copied.

Application security

Are security headers deployed? Yes: HSTS (1 year, includeSubDomains, preload), nosniff, referrer policy, permissions policy, restricted frame-ancestors. A Content Security Policy is deployed report-only pending a clean observation window, then enforced. Security model

Is there a vulnerability disclosure route? Yes — hello@swyftscale.com.

Is penetration testing carried out? Contact us for the current position and to discuss evidence requirements for your review.

Is card data handled? Never by us. Stripe-hosted checkout and payment elements; we receive status by signed webhook.

Availability

What is the availability commitment? Discussed as part of an organisation agreement. Note that MedJot's clinical workflow is offline-capable, so a supplier outage does not stop a clinician documenting a patient — an unusual resilience property worth recording. Working offline

How are updates delivered? As web assets. Users are prompted rather than interrupted; in-progress work is preserved. Updates and stored data

Is there a business continuity concern if the supplier ceases trading? Reports are on the device and exportable to PDF or clipboard at any time. There is no supplier-held clinical archive to recover.

Privacy and compliance

Who is the data controller? Swyftscale, for clinician account data. For clinical data there is no supplier processing in the ordinary case. Privacy and governance

Is a DPIA supported? Yes. Privacy and governance is written for one, and we will complete your own templates.

Is a DPA available? Contact us.

How are DSARs handled? Through a form that works without a sign-in. Note a DSAR to us cannot return clinical records — we hold none.

Is automated decision-making used? Only fraud flagging, and no account is suspended by automated decision alone. Human review and an appeal route always apply.

What analytics are collected? Opt-in only, from a closed catalogue with no free-text field anywhere by construction, revalidated server-side, with no account identifier sent to Google.

Network and deployment

What must be allow-listed? Network requirements

Does it require TLS inspection exemption? Yes, and this is the most important single item. TLS inspection

Is there an MDM package? No. It is a PWA — nothing to install. Deployment and devices

Are inbound connections required? No.

Does it integrate with clinical systems? No. Output is copied or exported by the clinician.

Anything not answered here

hello@swyftscale.com. We would rather answer a specific question directly than have a review stall on an assumption.