Where your data lives

Primary hosting is AWS in the London region, encrypted at rest and in transit. Amazon Web Services is engaged under a Business Associate Addendum, and the services carrying patient data are ones AWS supports under it.

Where any processing or sub-processor sits outside the UK or EEA, it is covered by the safeguards set out in our GDPR compliance page, which also lists the sub-processors themselves.

Backups: two systems that fail differently

There are two independent backup systems, deliberately, because one backup is not a backup.

  • Automated daily database snapshots held in AWS. Taken on a schedule, retained, and restorable to a point in time.
  • A second encrypted copy taken daily to storage outside AWS entirely, on a rolling retention, together with the stored documents and images.

The point of the second one is that it survives a category of failure the first cannot: a problem with the cloud account itself. A backup that lives in the same place as the thing it is backing up is a copy, not a contingency.

What the AI does with your patients' data

This is the question a governance lead should ask any vendor selling AI into a clinical record, and it deserves a direct answer rather than a paragraph about innovation.

  • Your data is never used to train models. Not ours, not a provider's. Clinical content passes through a model to produce a draft and is not retained by the provider for training.
  • Some processing never leaves our own hardware. A portion of the AI workload, including speech-to-text, runs on self-hosted machines in the UK rather than on any third-party API.
  • Cloud processing runs in the London region where it goes through AWS, under the same Business Associate Addendum as the rest of the platform.
  • Every AI output is a draft. Transcription, note drafting, coding suggestions and letters are all reviewed, edited and signed off by a clinician, and the sign-off is recorded with a name and a time. Nothing written by a model enters the record unsigned.
  • AI usage is itemised. You can see what was used and what it cost on your invoice rather than being told it is included and hoping.

Tenant isolation: one clinic, one schema

Every clinic on Velastria has its own isolated database schema. Your patient records are not rows in a shared table filtered by an ID, they are structurally separated from every other clinic's data at the database level. This is an architectural decision, not a policy.

Access and protection

Encryption at rest (AES-256) and in transit over HTTPS. Role-based access control with least privilege, so reception roles cannot open clinical notes. A strong password policy (minimum twelve characters) with a forced password change on first login. Automatic account lockout after repeated failed logins. Comprehensive audit logs of data access and changes.

Traffic reaches the application through a managed web application firewall with rate limiting on authentication endpoints, so a password-guessing attempt is throttled at the edge before it reaches a login form at all.

How a change reaches your clinic

Every change to Velastria runs the full automated test suite before it can ship, on every single commit, without anyone choosing to run it. That is thousands of tests covering the clinical, financial, compliance and communication paths, and a failure blocks the change rather than generating a note for somebody to read later.

That makes testing a release gate rather than an intention, which is the form a governance reviewer is looking for: a control that runs whether or not anyone remembers to run it.

Your data is yours, including on the way out

If you leave Velastria, you leave with everything: a complete export of your data in open formats. We believe a system should keep your business by being good, not by holding your data hostage.

Regulatory posture

  • UK GDPR and the Data Protection Act 2018. See our GDPR compliance page for the full statement, including controller and processor roles and the data-processing agreement every customer receives.
  • Breach notification: the ICO within 72 hours; affected customers without undue delay.
  • Regular security assessments and penetration testing, as set out in our terms of service.
  • A service availability target of 99.9%, excluding scheduled maintenance.

Every control described on this page is one you can ask us to evidence, and we would rather be specific about what we operate than general about what we believe in.

Due diligence, answered in writing

If you are placing a registered clinical service on this platform, you should be asking for written answers rather than a page on a website. Ask, and you will get them: data hosting and residency, sub-processors, backup and restore, business continuity, audit logging, data export and exit, security testing, incident response, AI processing and model training, uptime, support and escalation, and the data processing agreement itself.

You will get them in writing, from the founder, and you are welcome to put them straight in front of your board or your registered manager.

Who's behind it

Velastria is built and run by Taimur Shoaib: consultant plastic surgeon, Diploma in Medical Informatics, founder of an HIS-registered private hospital which he ran for five years before selling. The person who wrote the security architecture is the same person whose name is on the front door. Questions: t.shoaib@doctors.org.uk.