Genassis Logo

Trust & Security

Secure AI built for healthcare

We take security seriously. Your data is encrypted, securely stored, and protected by the controls below — built on certified cloud infrastructure, with a transparent path to independent certification.

Security Features

Certified Cloud Infrastructure

The platform runs on Google Cloud, whose infrastructure holds ISO 27001, ISO 27017, ISO 27018, and SOC 2 Type II certifications — with redundant networking, physical security, and 24/7 monitoring inherited from that foundation.

Data Encryption

All data is encrypted at rest using AES-256 and in transit with TLS 1.2+, with encryption keys managed through Google-managed key infrastructure.

Access Control

Access to production systems is restricted to named personnel on a least-privilege basis, with multi-factor authentication enforced across cloud, source control, and business systems. No shared credentials; access is reviewed on any role change.

Audit Logging

Administrative activity across the cloud environment is logged and retained via Cloud Audit Logs, so actions in the environment are attributable and reviewable.

Secure Development

Every code change is version-controlled and reviewed before merge, with automated continuous-integration gates — type checks, linting, and compile checks — on every change. Secrets live in a managed secret store, never in code.

Dependency & Vulnerability Management

Third-party dependencies are automatically monitored against the published vulnerability database, with security alerting and automated remediation pull requests applied through the same reviewed, gated release process as any other change.

Data Governance & Privacy

Personal data is handled under UK GDPR, with recognised safeguards (IDTA / Standard Contractual Clauses) for any cross-border transfer. The platform's evidence base is built from published, publicly accessible sources — not patient records.

Responsible AI

Every output traces back to a specific, cited source — the platform is designed not to generate unsourced claims, and to show an honest gap where the evidence does not support a conclusion. Client data is never used to train or fine-tune models.

Certification Roadmap

We are candid about where we are: UK Cyber Essentials certification is underway, with Cyber Essentials Plus to follow and ISO 27001 as the longer-term goal. Until then, our security posture rests on the certified infrastructure and the controls above.