Clinics trust us with patient data. Here is precisely how it's held, and how you get it back.
Primary hosting is AWS in the London region, encrypted at rest and in transit. Amazon Web Services is engaged under a Business Associate Addendum, and the services carrying patient data are ones AWS supports under it.
Where any processing or sub-processor sits outside the UK or EEA, it is covered by the safeguards set out in our GDPR compliance page, which also lists the sub-processors themselves.
There are two independent backup systems, deliberately, because one backup is not a backup.
The point of the second one is that it survives a category of failure the first cannot: a problem with the cloud account itself. A backup that lives in the same place as the thing it is backing up is a copy, not a contingency.
This is the question a governance lead should ask any vendor selling AI into a clinical record, and it deserves a direct answer rather than a paragraph about innovation.
Every clinic on Velastria has its own isolated database schema. Your patient records are not rows in a shared table filtered by an ID, they are structurally separated from every other clinic's data at the database level. This is an architectural decision, not a policy.
Encryption at rest (AES-256) and in transit over HTTPS. Role-based access control with least privilege, so reception roles cannot open clinical notes. A strong password policy (minimum twelve characters) with a forced password change on first login. Automatic account lockout after repeated failed logins. Comprehensive audit logs of data access and changes.
Traffic reaches the application through a managed web application firewall with rate limiting on authentication endpoints, so a password-guessing attempt is throttled at the edge before it reaches a login form at all.
Every change to Velastria runs the full automated test suite before it can ship, on every single commit, without anyone choosing to run it. That is thousands of tests covering the clinical, financial, compliance and communication paths, and a failure blocks the change rather than generating a note for somebody to read later.
That makes testing a release gate rather than an intention, which is the form a governance reviewer is looking for: a control that runs whether or not anyone remembers to run it.
If you leave Velastria, you leave with everything: a complete export of your data in open formats. We believe a system should keep your business by being good, not by holding your data hostage.
Every control described on this page is one you can ask us to evidence, and we would rather be specific about what we operate than general about what we believe in.
If you are placing a registered clinical service on this platform, you should be asking for written answers rather than a page on a website. Ask, and you will get them: data hosting and residency, sub-processors, backup and restore, business continuity, audit logging, data export and exit, security testing, incident response, AI processing and model training, uptime, support and escalation, and the data processing agreement itself.
You will get them in writing, from the founder, and you are welcome to put them straight in front of your board or your registered manager.
Velastria is built and run by Taimur Shoaib: consultant plastic surgeon, Diploma in Medical Informatics, founder of an HIS-registered private hospital which he ran for five years before selling. The person who wrote the security architecture is the same person whose name is on the front door. Questions: t.shoaib@doctors.org.uk.