Trust and security
Built for healthcare from the first line.
Where your data goes, how every agent is kept safe, and the standards we work to. If you need something for your own assurance process that is not here, ask us.
At a glance
Standards and certifications.
What is in place today, and what is under way. We update this page as things change.
Not a medical device. Ostify is not a medical device, and it is not designed for building medical devices. Agents built on Ostify share information from content you have approved. Their guardrails stop them from diagnosing, advising on individual treatment or making clinical decisions.
- In placeDCB0129 clinical safety case
Our own clinical safety case is published, for you to reference in yours.
- In placeDSPT and DTAC alignment
Agents built on Ostify are aligned with the Data Security and Protection Toolkit and the Digital Technology Assessment Criteria. We are finalising completion of both, pending penetration testing and Cyber Essentials.
- In placeICO registered
Registered with the Information Commissioner’s Office, number ZC243397. Check the register.
- In placeEncryption and access control
Data is encrypted in transit, and access is limited to the people who need it. How the platform is protected.
- In progressCyber Essentials
Certification is under way.
- In progressIndependent penetration testing
An external test of the platform is under way.
Your data
Where data goes, and where it does not.
Patient conversations stay in the UK and are never stored.
- Patient conversations
- Processed in the UK, never storedEach question is answered and the conversation is not kept.
- Evaluation and assurance
- Processed within EuropeTest runs, scores and drafted assurance documents.
- AI models
- Hosted in our secure health cloudFoundational models run in Ostify’s own secure environment. See where the models run.
- Your build
- Private until you submit itWe cannot see your build or your evaluations until you submit them for review. Everything you build remains your intellectual property.
- This website
- Hosted on Microsoft Azure in the UKIncluding our contact form and analytics. See our privacy policy.
Clinical safety
Safety is built into every agent.
You own the agent and your clinical safety officer signs it off. These are the protections underneath.
- Answers only from approved content
An agent can only use the passages you have approved. If your content does not cover a question, it says so rather than guessing.
- Six guardrails on every question
Emergency words, urgency detection, no clinical decisions, harmful content, relevance, and your own rules. See the guardrails.
- Evaluation you can evidence
Test against a fixed question set, including emergencies and attempts to trick the agent, and review every answer with another clinician.
- Reviewed by us before it goes live
No agent reaches a patient until it has passed an individual Ostify review. Changing content or key settings sends it back for review.
Documents
For your assurance process.
Most teams need some of these for a DPIA, a DTAC submission or a clinical safety case.