Security & compliance Back to the platform
Security & professional secrecy

Data security
at the core of the architecture.

Professional secrecy and data protection are built into the whole application — not bolted on afterwards. Here's exactly what's in place today, and what's still underway.

EU hosting · encrypted in transit and at rest · never used to train public models

ISO 27001
GDPR
EU AI Act
Why this matters

A veterinary dictation is a professional document. It deserves the same protection as a medical record.

Choosing a tool without a secure architecture isn't a neutral decision. With many scribe tools, professional data and client personal data pass through servers outside the EU — and if it isn't properly secured, it can be retained, analysed, or reused to train models.

Transfer outside the EU

Animal-health and client personal data hosted outside the European Union, under jurisdictions where it is less protected.

Reuse for AI training

Notes used to train public models — phrasing, protocols and client data, exploited without control.

Breach of professional secrecy

A leak or unauthorised access exposes professional secrecy and the trust between vet and owner.

Legal liability

In a GDPR breach, the practice is the data controller — not just the software vendor.

Whichever veterinary software you evaluate, ask where the data is hosted and which certifications the vendor holds. A specific answer is the only useful one.

Certifications & compliance

Independent audits for security and AI governance. GDPR by design.

ISO certification is a multi-month process, audited by an accredited third party — here's exactly where we stand.

Certification in progress
ISO 27001
Information security management

The international benchmark for protecting information: risk analysis, access controls, encryption, continuity.

For you: your records and your clients' are protected by a security system built for independent audit, not just internal promises.

Certification in progress
ISO 42001
AI management system

The standard for responsible AI: transparency, human oversight, model risk management.

For you: the AI that writes your notes is governed, traceable and supervised — not a black box.

Designed for compliance
GDPR
General Data Protection Regulation

GDPR is a legal framework, not a certification — there's no external body to audit it against. We're built for it today: data minimisation, consent, the right to erasure, a processing register, a signed DPA. Our ISO 27001 audit will let us demonstrate this formally, in a trust center, once it's complete.

For you: your clients keep control of their data, and your practice stays compliant.

Alignment in progress
EU AI Act
European Artificial Intelligence Act

The EU AI regulation, in force from August 2026: transparency, human oversight, risk management of AI systems.

For you: the platform is already working toward the framework that will apply to all medical AI.

Testing in progress
Pentest
Independent penetration testing

Independent security experts test the platform under real attack conditions, so issues are fixed before they become incidents.

For you: our security doesn't rest on internal review alone.

What's actually in place

Concrete facts, not slogans.

EU hosting

The application runs on Render, and files are stored on Amazon S3 — both in the EU. Your data stays under European law.

Encrypted in transit and at rest

Data is encrypted with TLS between your browser and our servers. Personal data is encrypted at the application level in our databases, backups included.

Backed up, encrypted

Database backups are encrypted and taken regularly, so an incident doesn't mean starting from zero.

Never trains public AI

Your data is never used to train public models — every AI provider we use is contractually committed, in its DPA, not to train on our traffic.

Controlled access

Role-based access scoped to each medical case, two-factor authentication, and a queryable log of every sign-in and account change.

DPA & data rights

A signed Data Processing Agreement, plus the GDPR rights you'd expect: access, correction, deletion and portability, on request.

How we secure AI
AI governance

Medical AI is entering a regulatory framework. Our controls go further than the law requires.

The EU AI Act, in force since 2024 and applying progressively, governs the use of AI — including in healthcare and clinical decision support. It requires transparency, human oversight, risk management and traceability of AI systems.

Beyond regulatory alignment, the platform is built with technical guardrails: each AI call is scoped to the case being processed, agents can't browse the open web or call arbitrary URLs, and every provider we use is contractually barred from training on your data.

Transparency: you know what the AI does, and what it doesn't.

Human oversight: the vet validates and remains responsible for the act.

Scoped by design: each AI call sees only the medical case being processed — no cross-case or cross-tenant data leakage, no browsing the open web.

Controlled providers: every AI provider's contract bars training on our traffic, and organisations can restrict processing to EU-only providers.

Free VoiceIt

Free does not mean less secure.

The free site voiceit.vet benefits from all the platform's security work and is just as secure: same EU-hosted infrastructure, same encryption, same commitment to ISO 27001, ISO 42001, GDPR and the EU AI Act. Being free is no reason for your data — and your clients' data — to be any less protected.

The same security, the same standards, the same guarantee. All of it, free.

Discover voiceit.vet →
Your advantages

What you concretely gain.

Your clients' trust

Announcing a compliant, EU-hosted platform reassures owners about how their data is handled.

Your legal peace of mind

You remain the data controller: choosing a compliant provider directly reduces your exposure.

Professional secrecy upheld

The confidentiality of the clinical exchange is protected by architecture, not goodwill.

A head start

While the AI framework tightens, you already work with a tool built for these requirements.

Straight answers

The questions worth asking before you sign up.

What happens to our data if we leave the platform?
You can export or delete your records at any time. Beyond that, we only retain data as long as necessary — see our Privacy Policy for exact retention periods.
Do you use our data to train AI models?
No. Every AI provider we work with is contractually committed, in its DPA, not to train on our traffic. We log which provider and model handled each request — never the content or the response.
Where exactly is our data processed?
Application hosting and file storage are both in the EU — Render and AWS S3, Germany. Organisations that need every AI call to stay in the EU too can restrict processing to our EU-only providers: Mistral for AI, Gladia for transcription, both based in France.
What happens if there's a security incident?
We investigate and contain it immediately, notify affected users as required by law, run a root-cause analysis, and review afterwards to prevent a repeat.
How do we report a vulnerability?
Email team@digitalclinic.vet with a description, reproduction steps and the impact. We acknowledge every report promptly, and ask only that you give us time to fix it before disclosing it publicly.
Let's talk

Compliance shouldn't be a gamble.

Ask our security team anything — hosting, GDPR, AI Act, professional secrecy.

Or email hannes@digitalclinic.vet

The platform is founder-run — meet the founders