Updated on October 2, 2025
Updated on October 2, 2025
Compliance
Our clinical platforms are designed to support customers in meeting their obligations under GDPR and other applicable privacy and security regulations when processing personal data in healthcare and research settings. We emphasize privacy by design, robust technical and organizational security controls, and clear governance so that controllers and processors can use our services with confidence.
All infrastructure providers and subprocessors are vetted by QTIS AI before integration and must successfully pass our vendor risk assessment, including verification of relevant certifications and attestations. We maintain and regularly update a global register of these subprocessors and their certifications to ensure ongoing compliance and transparency for our customers.
Our clinical platforms are designed to support customers in meeting their obligations under GDPR and other applicable privacy and security regulations when processing personal data in healthcare and research settings. We emphasize privacy by design, robust technical and organizational security controls, and clear governance so that controllers and processors can use our services with confidence.
All infrastructure providers and subprocessors are vetted by QTIS AI before integration and must successfully pass our vendor risk assessment, including verification of relevant certifications and attestations. We maintain and regularly update a global register of these subprocessors and their certifications to ensure ongoing compliance and transparency for our customers.
ISO 27001
Our information security management system is aligned with ISO 27001 and extends to all subprocessors that handle customer data. We only engage subprocessors that maintain ISO 27001 certification or equivalent security controls, and we bind them by contract to strict confidentiality, security, and incident notification obligations. We keep an up-to-date list of subprocessors, perform regular security and compliance reviews, and continuously monitor their performance to ensure they meet our standards for protecting your data.
https://cloud.google.com/security/compliance/iso-27001
Our information security management system is aligned with ISO 27001 and extends to all subprocessors that handle customer data. We only engage subprocessors that maintain ISO 27001 certification or equivalent security controls, and we bind them by contract to strict confidentiality, security, and incident notification obligations. We keep an up-to-date list of subprocessors, perform regular security and compliance reviews, and continuously monitor their performance to ensure they meet our standards for protecting your data.
https://cloud.google.com/security/compliance/iso-27001
ISO 27701
Our privacy information management system is aligned with ISO 27701 and applies to all subprocessors that process personal data on our behalf. We only use subprocessors that maintain ISO 27701 certification or comparable privacy controls and bind them by contract to strict obligations on data protection, purpose limitation, data subject rights support, and incident notification. We keep an up-to-date list of these subprocessors, review their privacy practices regularly, and monitor them to ensure ongoing compliance with our privacy and regulatory commitments.
https://cloud.google.com/blog/products/identity-security/google-cloud-certified-as-a-data-processor
Our privacy information management system is aligned with ISO 27701 and applies to all subprocessors that process personal data on our behalf. We only use subprocessors that maintain ISO 27701 certification or comparable privacy controls and bind them by contract to strict obligations on data protection, purpose limitation, data subject rights support, and incident notification. We keep an up-to-date list of these subprocessors, review their privacy practices regularly, and monitor them to ensure ongoing compliance with our privacy and regulatory commitments.
https://cloud.google.com/blog/products/identity-security/google-cloud-certified-as-a-data-processor
Azure Certifications
We host and process customer data on Microsoft Azure, which maintains one of the largest portfolios of independently audited compliance certifications in the industry, including ISO 27001, ISO 27018, ISO 27701, SOC 1, SOC 2, SOC 3, PCI DSS, FedRAMP, HITRUST, and multiple regional and sector-specific standards.
Azure’s compliance posture is verified through regular third-party audits, and detailed certification reports and shared responsibility documentation are available via the Microsoft Service Trust Portal for our customers upon request.
https://learn.microsoft.com/en-us/azure/compliance/
We host and process customer data on Microsoft Azure, which maintains one of the largest portfolios of independently audited compliance certifications in the industry, including ISO 27001, ISO 27018, ISO 27701, SOC 1, SOC 2, SOC 3, PCI DSS, FedRAMP, HITRUST, and multiple regional and sector-specific standards.
Azure’s compliance posture is verified through regular third-party audits, and detailed certification reports and shared responsibility documentation are available via the Microsoft Service Trust Portal for our customers upon request.
https://learn.microsoft.com/en-us/azure/compliance/
We host and process customer data on Microsoft Azure, which maintains one of the largest portfolios of independently audited compliance certifications in the industry, including ISO 27001, ISO 27018, ISO 27701, SOC 1, SOC 2, SOC 3, PCI DSS, FedRAMP, HITRUST, and multiple regional and sector-specific standards.
Azure’s compliance posture is verified through regular third-party audits, and detailed certification reports and shared responsibility documentation are available via the Microsoft Service Trust Portal for our customers upon request.
https://learn.microsoft.com/en-us/azure/compliance/
Authentication
We design our clinical platforms around principles of data minimisation and purpose limitation. Customers can restrict data fields, separate identity data from operational data, and configure which information is mandatory for each workflow.
We support technical requirements for FAPI, a set of advanced security profiles specified by the OpenID Foundation. FAPI introduces stricter security standards for industries and scenarios that require more security on top of normal OAuth 2.0 and OpenID Connect (OIDC) implementations. Our Auth providers are certified FAPI OpenID Provider for the following two profiles:
FAPI 1 Advanced OP with mTLS, PAR
FAPI 1 Advanced OP with Private Key JWT, PAR
They also undergo ISO 27001/27017/27018 audit by an independent auditor annually. We can also share our Statement of Applicability (SOA) upon request with a non-disclosure agreement (NDA) signed by a corporate officer authorized to represent the company. To request the SOA, please contact your account team.
We design our clinical platforms around principles of data minimisation and purpose limitation. Customers can restrict data fields, separate identity data from operational data, and configure which information is mandatory for each workflow.
We support technical requirements for FAPI, a set of advanced security profiles specified by the OpenID Foundation. FAPI introduces stricter security standards for industries and scenarios that require more security on top of normal OAuth 2.0 and OpenID Connect (OIDC) implementations. Our Auth providers are certified FAPI OpenID Provider for the following two profiles:
FAPI 1 Advanced OP with mTLS, PAR
FAPI 1 Advanced OP with Private Key JWT, PAR
They also undergo ISO 27001/27017/27018 audit by an independent auditor annually. We can also share our Statement of Applicability (SOA) upon request with a non-disclosure agreement (NDA) signed by a corporate officer authorized to represent the company. To request the SOA, please contact your account team.
Changes to this page
We may update this policy to reflect changes in our services or the law. We will notify you of significant changes.
We may update this policy to reflect changes in our services or the law. We will notify you of significant changes.
Contact us
If you have questions or concerns, please email us at compliance@qtis.ai
If you have questions or concerns, please email us at support@q