Where your data lives

Primary hosting is in AWS UK (London), encrypted at rest. Production data is backed up daily and held in AWS, with additional encrypted offsite copies. Where any processing or sub-processor sits outside the UK or EEA, it is covered by the safeguards set out in our GDPR compliance page.

Tenant isolation: one clinic, one schema

Every clinic on Velastria has its own isolated database schema. Your patient records are not rows in a shared table filtered by an ID, they are structurally separated from every other clinic's data at the database level. This is an architectural decision, not a policy.

Access and protection

Encryption at rest (AES-256) and in transit over HTTPS. Role-based access control with least privilege, so reception roles cannot open clinical notes. A strong password policy (minimum twelve characters) with a forced password change on first login. Automatic account lockout after repeated failed logins. Comprehensive audit logs of data access and changes.

Your data is yours, including on the way out

If you leave Velastria, you leave with everything: a complete export of your data in open formats. We believe a system should keep your business by being good, not by holding your data hostage.

Regulatory posture

  • UK GDPR and the Data Protection Act 2018. See our GDPR compliance page for the full statement, including controller and processor roles and the data-processing agreement every customer receives.
  • Breach notification: the ICO within 72 hours; affected customers without undue delay.

Who's behind it

Velastria is built and run by Taimur Shoaib: consultant plastic surgeon, Diploma in Medical Informatics, founder of a CQC-registered private hospital which he ran for five years before selling. The person who wrote the security architecture is the same person whose name is on the front door. Questions: t.shoaib@doctors.org.uk.