Skip to content
Trust & assurance

Security you can verify, not just believe.

Every vendor claims strong security. The useful question is what they publish before you ask, what an independent party has tested, and what they commit to contractually. This page is our answer to all three.

Breaches since 2019
0
Independent audits / yr
6
Standing data access
None
Disclosure triage
< 24 h
A steel padlock closing a heavy chain across a gate.
Trust & assurance

Anyone can hang
a padlock. Prove it holds.

A lock closing a chain proves nothing until someone independent has actually tried to defeat it. Six audits a year test ours that way, and the summary goes out whether it flatters us or not.

0
Breaches since 2019
6
Independent audits / year
None
Standing staff data access
< 24 h
Disclosure triage
Compliance centre

The primitives,
named and versioned.

'Military-grade encryption' means nothing. Here are the actual algorithms, parameters and rotation schedules, so your security team can evaluate them rather than trust an adjective.

Symmetric encryption
AES-256-GCM for all record and document content, with per-record data encryption keys.
Key wrapping
AES-256-KW under a per-tenant master key, itself held in a FIPS 140-2 Level 3 HSM. Master keys never exist in plaintext outside the HSM boundary.
Asymmetric operations
ECDSA P-384 for audit-event signing; X25519 for key agreement in client-side flows.
Hashing
SHA-512 for shard integrity and audit chaining. Argon2id for password derivation, with parameters reviewed annually.
Transport
TLS 1.3 only. TLS 1.2 and below are refused. HSTS preloaded, certificate transparency monitored, CAA records enforced.
Key rotation
Tenant master keys rotate every 90 days or on demand. Rotation re-wraps data keys without re-encrypting record content, so it completes in minutes rather than days.
Randomness
All key material derives from hardware entropy sources inside the HSM. No userspace PRNG participates in key generation.
Post-quantum posture
Hybrid X25519 + ML-KEM key agreement is in testing for the client-side path. We will publish a migration timeline rather than a marketing claim.

The biggest risk
to your data is us.

A vendor's own staff are the most privileged threat in any hosted system. These are the controls that constrain our engineers — and they are the ones we would want to see if we were buying.

No standing access

No MediVault employee holds standing access to customer data. Every access requires a ticketed, time-boxed, customer-visible grant.

Four-eyes approval

Production access requires approval from a second engineer outside the requester's reporting line. Self-approval is not possible.

Session recording

Every production support session is recorded in full and retained. Recordings are available to the affected customer on request.

Hardware-key MFA

FIDO2 hardware keys are mandatory for all staff. Phishable second factors — SMS, email codes, push approval — are not permitted anywhere.

Managed endpoints

Engineering happens on fully managed, encrypted, EDR-monitored devices. Personal devices cannot reach production or source control.

Segregated environments

Production, staging and development are separate accounts with separate credentials. Production data never flows downstream.

Signed builds

Every artefact is reproducibly built, signed and verified at deploy time. Unsigned code cannot reach a production node.

Dependency scanning

Continuous SCA and SBOM generation on every build, with a 72-hour remediation SLA for critical advisories.

Personnel vetting

Swiss criminal record check, reference verification and signed confidentiality undertakings before any production access is granted.

Six independent audits
every year.

Annual penetration test
Full-scope test by an independent Swiss security firm, rotated every three years to avoid familiarity bias. Summary published; full report under NDA.
Enterprise dedicated tests
Enterprise customers receive a dedicated annual test of their own instance, scoped with them, with the unredacted report delivered to their security team.
Continuous scanning
Automated DAST against staging on every release and weekly against production, plus continuous SAST in the build pipeline.
Red team exercise
An annual objective-based red team engagement including social engineering against our own staff, with findings fed into the security roadmap.
Restore testing
Quarterly full restore from encrypted backup into an isolated environment, timed and verified. Results are published to customers.
Chaos and failover drills
Scheduled failover between Zürich sites and an annual full DR exercise to Genève, both executed during business hours with customers notified.

What happens
on the worst day.

We have not had a breach since founding in 2019. That is not a reason to lack a plan — it is the reason we rehearse one quarterly.

Detect

24/7 monitoring against behavioural baselines, integrity alerts and SIEM correlation, with a Swiss-based on-call rotation.

Triage

Severity assigned within 15 minutes of detection. P1 activates the incident commander role and opens a customer communication channel.

Contain

Isolate affected components, revoke credentials, and preserve forensic evidence before remediation begins — never after.

Notify

Affected customers notified within 24 hours of confirmation. EDÖB notification within 72 hours where the FADP threshold is met.

Remediate

Fix, verify, and confirm with the customer's own security team before the incident is closed on our side.

Publish

A written post-incident review to affected customers within 10 working days, including timeline, root cause and corrective actions.

Found something?
Tell us properly.

We operate a coordinated disclosure programme. Researchers acting in good faith under this policy will not face legal action from us.

Email
security@medivaultzurich.site
Phone
+41 44 512 88 77
PGP fingerprint
9F14 C0A3 7B2E 44D1 8A05 6C93 E77B 2E5F 0A18 C4D6
Triage SLA
Triaged within 24 hours
Availability
24 / 7 on-call rotation
  • Acknowledge your report within 24 hours
  • Provide a triage decision within 5 working days
  • Keep you updated at least every 10 working days
  • Credit you publicly, if you want the credit
  • Never pursue legal action for good-faith research
  • Publish a summary once the issue is remediated

Out of scope: denial of service, social engineering of our staff or customers, physical attacks, and anything involving real patient data. If your test would touch production patient records, stop and contact us first.

Security review

Send us the
questionnaire.

We complete security questionnaires in full, in writing, with evidence references — before any commercial conversation. Most come back within five working days.

SOC 2 Type II report and penetration test summaries available under NDA