Clinics trust us with patient data. Here is precisely how it's held, and how you get it back.
Primary hosting is in AWS UK (London), encrypted at rest. Production data is backed up daily and held in AWS, with additional encrypted offsite copies. Where any processing or sub-processor sits outside the UK or EEA, it is covered by the safeguards set out in our GDPR compliance page.
Every clinic on Velastria has its own isolated database schema. Your patient records are not rows in a shared table filtered by an ID, they are structurally separated from every other clinic's data at the database level. This is an architectural decision, not a policy.
Encryption at rest (AES-256) and in transit over HTTPS. Role-based access control with least privilege, so reception roles cannot open clinical notes. A strong password policy (minimum twelve characters) with a forced password change on first login. Automatic account lockout after repeated failed logins. Comprehensive audit logs of data access and changes.
If you leave Velastria, you leave with everything: a complete export of your data in open formats. We believe a system should keep your business by being good, not by holding your data hostage.
Velastria is built and run by Taimur Shoaib: consultant plastic surgeon, Diploma in Medical Informatics, founder of a CQC-registered private hospital which he ran for five years before selling. The person who wrote the security architecture is the same person whose name is on the front door. Questions: t.shoaib@doctors.org.uk.