Security & compliance

ISO 27001 certified. Clinical safety assured. Due diligence, ticked.

Ameryst runs on Microsoft Azure with a dedicated instance for every customer, held in the UK as standard, or in the region you need, and replicated in real time to a second data centre. ISO 27001 certified, assured to the NHS DCB 0129 clinical safety standard, and penetration-tested every year by an external firm. Everything your due diligence needs is set out here, ready to share.

Ameryst · Security postureDue diligence
ISO 27001Certified
Clinical safetyDCB 0129 assured
Data residencyUK, or your region
ReplicationReal time, second data centre
Your instanceDedicated to you
Two-factor loginStandard, every account
Penetration testAnnual, external firm

Independently certified and assured

ISO 27001:2022 certified by Citation ISO Certification, certificate number 371412021DCB 0129 clinical safety, assured by Safehand
Where the data lives

Care management software security, starting with where your data lives.

Three decisions that were made once, properly, and that you inherit on day one.

1One instance each

Your records live in an instance of their own.

Every customer gets their own.

2Held where you need it

On Microsoft Azure, in the UK as standard.

Or in the region your organisation needs.

3Copied as it is written

Replicated in full and in real time to a second data centre.

Your records are always held in two places.

Security that is in place from day one, with nothing for your team to set up.

Access control

Who can see what, down to the section.

Permissions as detailed as you need them to be, because real services have real exceptions.

  • Permissions go further than a job title. Every tab and every function is permission-controlled, down to individual sections of the patient record. Permission groups can be cloned and exported to CSV so an auditor can see them. And an individual member of staff can be blocked from one specific record, for when a colleague is related to somebody on your caseload.
  • The audit trail records reading, not just writing. Notes before and after every edit, care plan versions, bookings, allergies, preferences, and who printed what and when. The activity log shows which records were opened, which is the question an investigation actually asks.
What it protects

Why this matters beyond the questionnaire

Compliance & governance

Answers you can evidence

Every claim on this page can be checked: a certificate, a test report, UK data residency, a permission model you can export. That is exactly what an information governance review looks for, and it makes the review quicker for everyone involved.

Reputation

Only the right people see the record

Permissions down to a section, an audit log that shows who opened each record, and safeguarding flags set by a trained lead. Privacy is protected by how the system works, every day, for every member of staff.

Cost & financial control

Nothing to install or maintain

Ameryst runs entirely in the cloud. Servers, updates and patching are all taken care of, so there is no hardware to buy and no IT contractor to keep on retainer. For a small service, that is a strong business case on its own.

Patient safety

Care keeps running

Every record is copied to a second data centre as it is written, with disaster recovery and failover in place and a critical helpline around the clock. Your team keeps caring, whatever the day brings.

The questions that come up in due diligence

Where will our data be held?
In the UK as standard, on Microsoft Azure, with a full copy replicated in real time to a second data centre. Working outside the UK? We can host in the region where you are located, so your data stays in the right jurisdiction, in an instance dedicated to you.
Is the software assured for clinical safety?
Yes. Ameryst is assured against DCB 0129, the NHS clinical risk management standard for health software, by Safehand, a specialist clinical safety consultancy. It is alongside our ISO 27001 certification, and it gives your own clinical safety and governance leads the evidence they will ask for when you bring a new system into your service.
What happens if there is a problem during a shift?
Your data is copied in real time to a second data centre, with disaster recovery and failover in place and backups kept of care plans, notes and summaries. Our critical helpline is available 24 hours a day, seven days a week, so help is always a phone call away.
Can we stop one member of staff seeing one particular record?
Yes. An individual can be blocked from a specific patient record. The case people usually have in mind is a staff member who turns out to be related to somebody you care for. More broadly, every tab and function is permission-controlled down to individual sections of the record.
Does the audit trail show who looked at a record?
Yes. The activity log shows which records were opened, not only which were changed, so you can see who looked at a record and when. Edits keep their before-and-after values, care plans keep every version, and printing is logged too, which gives an investigation or a subject access request the full picture.
Can we use our own single sign-on?
Yes. Organisations on Microsoft 365 can use Azure single sign-on, so staff sign in with the account they already use every day. Families and external professionals sign in with two-factor authentication, which is standard on every account, so everyone who reaches the record is verified.
How does Ameryst help us with GDPR?
Subject access requests can be extracted with a dedicated tool, and data can be destroyed or obfuscated for a whole family, a patient only or a single family member, with a cooling-off period before it takes effect. Photographs flag themselves as out of date after a period you set, so records stay accurate.

Want to see Ameryst in action?