Skip to content
Platform architecture

Six layers. Eight products. One platform.

MediVault replaces the stack a healthcare organisation would otherwise assemble from a storage vendor, an IAM vendor, a compliance tool, an integration engine and a hosting provider — with one platform, one audit trail and one accountable Swiss supplier.

Products
8
Platform layers
6
Deployment models
5
Swiss residency
100%
A wall of cooling fans and coolant pipework along a data centre plant room.
Behind the six layers

Software runs on
hardware that has to stay cold.

Every layer above depends on a plant room most tenants never see — banked cooling fans and coolant pipework holding the racks inside their thermal envelope, 24 hours a day, so a spike in read volume never turns into a spike in temperature.

6
Platform layers
N+1
Cooling redundancy
3
Swiss facilities
100%
Swiss residency
Deployment models

Every pillar is a product
you could buy alone.

We build them together because the seams between vendors are where compliance failures happen — an access decision one system makes and another never records.

What happens between
the click and the record.

A single read of one patient document passes through six independent controls. Any one of them refusing means no data is returned — and the refusal is itself recorded.

1

Swiss edge

TLS 1.3 termination, rate limiting, WAF

2

Identity

Token validation, MFA state, device posture

3

Policy engine

Role, attribute, relationship, consent

4

Audit ledger

Event written before data is released

5

Key service

HSM unwraps the record data key

6

Shard reader

Integrity-verified reconstruction

Median end-to-end latency: 38 ms (p50), 94 ms (p95) for an authorised FHIR read from the Swiss edge. Security controls are not a performance trade-off we ask clinicians to absorb.

The numbers your
security review will ask for.

Encryption at rest
AES-256-GCM envelope encryption. Each record is sealed with a unique data encryption key, itself wrapped by a tenant key rooted in a FIPS 140-2 Level 3 HSM.
Encryption in transit
TLS 1.3 only, with modern cipher suites and HSTS preloading. TLS 1.0–1.2 and all legacy suites are refused at the edge.
Key management
Three-tier hierarchy: HSM root → per-tenant master → per-record data key. Rotation on a 90-day schedule or on demand. BYOK and HYOK available on Enterprise.
Storage topology
Records are sharded across three independent storage domains with per-shard integrity hashes. A corrupted or tampered shard is detected on read and reconstructed.
Audit ledger
Append-only, hash-chained event log. Each entry commits to its predecessor, so removal or edit of any historic event invalidates every subsequent hash.
Authorisation
Policy decision point evaluates role, attributes, care relationship, purpose of use and consent per request, at field-level granularity.
Availability
Active-active across two Zürich Tier IV sites with synchronous replication, plus a Genève warm standby at a 15-minute RPO. 99.99% contractual SLA.
Data residency
100% of production patient data resides in Switzerland. No processing, backup, support access or telemetry leaves Swiss jurisdiction.

Swiss soil.
Swiss jurisdiction.

Data residency is a legal position, not a marketing claim. Every byte of production patient data lives in facilities we can name, in cantons we can point to, under Swiss law — with a documented deployment model for organisations that need it inside their own walls.

ZH-DC-01Tier IV

Rümlang, ZH

Primary production vault

Role
Active — read / write primary
Resilience
2N power · N+1 cooling
Latency
< 4 ms to Zürich metro
Attested
ISO 27001 · ISO 50001 · biometric multi-zone access
ZH-DC-02Tier IV

Glattbrugg, ZH

Synchronous replica

Role
Active — synchronous replication
Resilience
2N power · N+1 cooling
Latency
< 2 ms inter-site RTT
Attested
ISO 27001 · ISO 22301 business continuity
GE-DC-03Tier III+

Meyrin, GE

Disaster recovery vault

Role
Warm standby — 15 min RPO
Resilience
N+1 power and cooling
Latency
< 9 ms Zürich → Genève
Attested
ISO 27001 · Swiss data-residency attested

Swiss cloud

Multi-tenant, fully managed, hosted in our Zürich Tier IV facilities.

Best fit
Clinics and hospitals wanting zero infrastructure burden

Private cloud

Single-tenant instance with dedicated compute, storage and key hierarchy.

Best fit
Groups with isolation requirements from their CISO

On-premise

Deployed inside your own data centre, operated by your team or ours.

Best fit
Institutions with existing estate and sovereignty policy

Hybrid

Keys and sensitive shards on-premise, scale and DR in the Swiss cloud.

Best fit
Networks balancing control against operational cost

Air-gapped

No external network path. Updates delivered by signed, verified media.

Best fit
Classified, forensic and public-sector environments
127
Healthcare sites live
Clinics, hospitals and networks
38 ms
Median API response
FHIR R4 read, p50, Swiss edge
1.2 bn
Audit events written
Cryptographically signed, immutable
18
EHR systems connected
Certified production connectors
6
Independent audits / year
Pen-test, SOC 2, ISO surveillance
30 min
P1 incident response
24/7 Swiss-based on-call
Technical evaluation

Bring us your
hardest questions.

Our Zürich engineers run architecture deep-dives with CISOs, CIOs and clinical governance leads. Ninety minutes, no sales deck, and we answer your security questionnaire in writing.

Sandbox tenants provisioned in under 5 minutes · No credit card required