Six layers. Eight products. One platform.
MediVault replaces the stack a healthcare organisation would otherwise assemble from a storage vendor, an IAM vendor, a compliance tool, an integration engine and a hosting provider — with one platform, one audit trail and one accountable Swiss supplier.
- Products
- 8
- Platform layers
- 6
- Deployment models
- 5
- Swiss residency
- 100%

Software runs on
hardware that has to stay cold.
Every layer above depends on a plant room most tenants never see — banked cooling fans and coolant pipework holding the racks inside their thermal envelope, 24 hours a day, so a spike in read volume never turns into a spike in temperature.
- 6
- Platform layers
- N+1
- Cooling redundancy
- 3
- Swiss facilities
- 100%
- Swiss residency
From encrypted bytes
to operational insight.
Each layer depends on the one beneath it. You can adopt them in order — most organisations start with storage and access, then add audit, integration and intelligence as their programme matures.
Every pillar is a product
you could buy alone.
We build them together because the seams between vendors are where compliance failures happen — an access decision one system makes and another never records.
What happens between
the click and the record.
A single read of one patient document passes through six independent controls. Any one of them refusing means no data is returned — and the refusal is itself recorded.
Swiss edge
TLS 1.3 termination, rate limiting, WAF
Identity
Token validation, MFA state, device posture
Policy engine
Role, attribute, relationship, consent
Audit ledger
Event written before data is released
Key service
HSM unwraps the record data key
Shard reader
Integrity-verified reconstruction
Median end-to-end latency: 38 ms (p50), 94 ms (p95) for an authorised FHIR read from the Swiss edge. Security controls are not a performance trade-off we ask clinicians to absorb.
The numbers your
security review will ask for.
- Encryption at rest
- AES-256-GCM envelope encryption. Each record is sealed with a unique data encryption key, itself wrapped by a tenant key rooted in a FIPS 140-2 Level 3 HSM.
- Encryption in transit
- TLS 1.3 only, with modern cipher suites and HSTS preloading. TLS 1.0–1.2 and all legacy suites are refused at the edge.
- Key management
- Three-tier hierarchy: HSM root → per-tenant master → per-record data key. Rotation on a 90-day schedule or on demand. BYOK and HYOK available on Enterprise.
- Storage topology
- Records are sharded across three independent storage domains with per-shard integrity hashes. A corrupted or tampered shard is detected on read and reconstructed.
- Audit ledger
- Append-only, hash-chained event log. Each entry commits to its predecessor, so removal or edit of any historic event invalidates every subsequent hash.
- Authorisation
- Policy decision point evaluates role, attributes, care relationship, purpose of use and consent per request, at field-level granularity.
- Availability
- Active-active across two Zürich Tier IV sites with synchronous replication, plus a Genève warm standby at a 15-minute RPO. 99.99% contractual SLA.
- Data residency
- 100% of production patient data resides in Switzerland. No processing, backup, support access or telemetry leaves Swiss jurisdiction.
Swiss soil.
Swiss jurisdiction.
Data residency is a legal position, not a marketing claim. Every byte of production patient data lives in facilities we can name, in cantons we can point to, under Swiss law — with a documented deployment model for organisations that need it inside their own walls.
Rümlang, ZH
Primary production vault
- Role
- Active — read / write primary
- Resilience
- 2N power · N+1 cooling
- Latency
- < 4 ms to Zürich metro
- Attested
- ISO 27001 · ISO 50001 · biometric multi-zone access
Glattbrugg, ZH
Synchronous replica
- Role
- Active — synchronous replication
- Resilience
- 2N power · N+1 cooling
- Latency
- < 2 ms inter-site RTT
- Attested
- ISO 27001 · ISO 22301 business continuity
Meyrin, GE
Disaster recovery vault
- Role
- Warm standby — 15 min RPO
- Resilience
- N+1 power and cooling
- Latency
- < 9 ms Zürich → Genève
- Attested
- ISO 27001 · Swiss data-residency attested
Swiss cloud
Multi-tenant, fully managed, hosted in our Zürich Tier IV facilities.
Private cloud
Single-tenant instance with dedicated compute, storage and key hierarchy.
On-premise
Deployed inside your own data centre, operated by your team or ours.
Hybrid
Keys and sensitive shards on-premise, scale and DR in the Swiss cloud.
Air-gapped
No external network path. Updates delivered by signed, verified media.
Bring us your
hardest questions.
Our Zürich engineers run architecture deep-dives with CISOs, CIOs and clinical governance leads. Ninety minutes, no sales deck, and we answer your security questionnaire in writing.
Sandbox tenants provisioned in under 5 minutes · No credit card required