Ship a compliant product without building a vault.
Embed MediVault as your storage and compliance layer via FHIR R4, SDKs and webhooks. You keep the product; we carry the residency and audit burden.
- To first integration
- Days
- Median FHIR read (p50)
- 38 ms
- Route to Swiss providers
- Co-sell
- Plan
- Partner programme

Built for what
you are actually dealing with.
Your product needs to hold patient data in Switzerland, and building compliant storage yourself costs a year you do not have.
- Days
- To first integration
- 38 ms
- Median FHIR read (p50)
- Co-sell
- Route to Swiss providers
What we usually
find on arrival.
Your product needs to hold patient data in Switzerland, and building compliant storage yourself costs a year you do not have.
ISVs building on clinical data
Embed MediVault as your storage and compliance layer via FHIR R4, SDKs and webhooks. You keep the product; we carry the residency and audit burden.
How this
actually runs.
A real timeline with named gates, not a marketing promise. Every stage has a written acceptance point before the next one starts.
Sandbox tenant
Self-serve, synthetic patient data, full API surface. Most teams have an authorised read working within an afternoon.
Conformance review
We review your integration against the FHIR conformance statement and purpose-of-use requirements, and return a written gap list.
Joint security review
Credential handling, retention and audit propagation reviewed together. This is where most integrations get materially safer.
Certified and listed
Public listing, advance notice of API changes, a named engineering contact and access to co-sell routes into Swiss providers.
The things you are
actually worried about.
- Who is the data controller?
- The healthcare provider remains controller. You and MediVault are both processors, with responsibilities defined in a three-party agreement rather than left ambiguous.
- Commercial model
- Usage-based partner pricing, billed to you or passed through to the provider. Both models are supported; most partners start with pass-through.
- Do you compete with us?
- We build infrastructure, not clinical applications. The Intelligence layer stops at administrative and operational scope, and we will put that in writing.
- API stability
- Date-based versions with a minimum 12-month deprecation window and written notice to every affected partner. Breaking changes never ship silently.
Not quite
your situation?
Scope it against
your real numbers.
Send us your site count, record volume, existing systems and governance requirements. We come back with a written scope, a timeline and a price — or an honest reason why we are not the right fit.
Partner programme — usage based