Skip to main content

Security questionnaire answers

Written to be answered from directly. Each links to the fuller treatment.

Data handling​

Where is patient data stored? On the clinician's device, in browser local storage and IndexedDB. It is not transmitted to or stored by the supplier. Data flows

Can the supplier access patient data? No. There is no server-side clinical store and no mechanism to retrieve one.

Is patient data encrypted at rest? On-device data is protected by the browser's origin isolation and the device's own encryption and lock policy — i.e. by the organisation's device management. The supplier holds no clinical data to encrypt.

Is data encrypted in transit? Yes. HTTPS only, TLS, HSTS with preload. Security model

Where is data processed geographically? Application hosting is UK-based. Google and Stripe may process outside the UK/EEA under their own commitments. Subprocessors

Is data shared with third parties? Only the subprocessors listed, each for a stated purpose. No data is sold, and no data is shared for advertising.

AI​

Is AI used, and on what data? Yes, optionally and user-initiated. A redacted summary of structured clinical findings is sent to Google Gemini when a clinician runs an AI feature. What gets sent

What de-identification is applied before data reaches the model? Automated redaction runs twice — in the browser before the request leaves the device, and again on the server before the prompt is assembled. It removes emails, UK phone numbers, NHS numbers, UK postcodes, numeric and written dates of birth, and reduces names introduced by a title or a relationship word to initials. The patient is referred to only as "Pt". How it works, rule by rule

Why redact on the server as well as the client? Because a server must not trust a client's assurance that it already did. The client pass is what keeps identifiable text off the network; the server pass is the control that survives a modified or replayed request.

How do you know the two passes behave the same? An automated test runs a shared corpus of realistic free text through both implementations and fails the build if their output differs at all. Further tests assert identifier removal, zero false positives on a standard set of vital signs, and linear-time behaviour on adversarial input.

Is redaction applied to specific fields, or to everything? To everything. The request object is walked recursively and every string in it is redacted. There is no maintained list of fields that can fall out of date, so a field added later is covered by default.

Is the model's output checked as well as its input? On the safeguarding route, yes — the response is redacted and the prompt forbids producing a full name. All routes cap input lengths, and category fields accept only values from a closed list.

Do you claim the data is anonymised? No, and we would not accept that claim from a supplier either. Redaction is pattern matching, not named-entity recognition; it is defence in depth over the primary control, which is that patient-identifiable information should not be entered into the app at all. The product tells clinicians so directly. Privacy and governance

Is our data used to train models? The AI features are used through Google's API rather than a consumer product. We do not provide data for model training.

Are prompts and responses retained? No. We log feature name, token counts and cost only — never content.

Is the output clinically validated? No, and it is not presented as such. Output is an explicitly labelled draft for a clinician to check; clinical responsibility remains with the clinician. AI overview

Can AI features be disabled? They are individually gateable and are never invoked without an explicit user action. For an organisation-wide requirement, talk to us.

Authentication and access​

What authentication is used? Google Firebase Authentication, email and password. No supplier-held passwords. Security model

Is MFA available? Not currently for standard accounts. Some risk-flagged registrations require mobile verification.

Is SSO available? Not currently. Raise it with us if it is a requirement.

How is authorisation enforced? Server-side on every privileged operation. Entitlement, role and organisation membership are derived server-side and never taken from the client.

Is administrative access logged? Yes — every administrative mutation appends to an immutable audit log, with sensitive values recorded as "changed" rather than copied.

Application security​

Are security headers deployed? Yes: HSTS (1 year, includeSubDomains, preload), nosniff, referrer policy, permissions policy, restricted frame-ancestors. A Content Security Policy is deployed report-only pending a clean observation window, then enforced. Security model

Is there a vulnerability disclosure route? Yes — hello@swyftscale.com.

Is penetration testing carried out? Contact us for the current position and to discuss evidence requirements for your review.

Is card data handled? Never by us. Stripe-hosted checkout and payment elements; we receive status by signed webhook.

Availability​

What is the availability commitment? Discussed as part of an organisation agreement. Note that MedJot's clinical workflow is offline-capable, so a supplier outage does not stop a clinician documenting a patient — an unusual resilience property worth recording. Working offline

How are updates delivered? As web assets. Users are prompted rather than interrupted; in-progress work is preserved. Updates and stored data

Is there a business continuity concern if the supplier ceases trading? Reports are on the device and exportable to PDF or clipboard at any time. There is no supplier-held clinical archive to recover.

Privacy and compliance​

Who is the data controller? Swyftscale, for clinician account data. For clinical data there is no supplier processing in the ordinary case. Privacy and governance

Is a DPIA supported? Yes. Privacy and governance is written for one, and we will complete your own templates.

Is a DPA available? Contact us.

How are DSARs handled? Through a form that works without a sign-in. Note a DSAR to us cannot return clinical records — we hold none.

Is automated decision-making used? Only fraud flagging, and no account is suspended by automated decision alone. Human review and an appeal route always apply.

What analytics are collected? Opt-in only, from a closed catalogue with no free-text field anywhere by construction, revalidated server-side, with no account identifier sent to Google.

Network and deployment​

What must be allow-listed? Network requirements

Does it require TLS inspection exemption? Yes, and this is the most important single item. TLS inspection

Is there an MDM package? No. It is a PWA — nothing to install. Deployment and devices

Are inbound connections required? No.

Does it integrate with clinical systems? No. Output is copied or exported by the clinician.

Anything not answered here​

hello@swyftscale.com. We would rather answer a specific question directly than have a review stall on an assumption.