Security starts with the architecture.
And extends into day-to-day operations.
Avelios protects sensitive patient data through encryption, context-based access controls, and complete traceability. Built for the security requirements of modern hospitals.
Certified to rigorous standards.
Designed for healthcare.
Updates that keep you compliant with the latest requirements are included as part of the platform, at no additional cost.
ISO 27001. Certified information security management for systematic security processes.
ISO 9001. Certified quality management for reliable business processes.
ISO 13485. Certified quality management for structured development processes.
BSI C5 Type 2. Independently audited cloud security based on the gold standard for information security.
Encrypted and securely separated.
Across the entire data flow.
Tenants are strictly isolated. Data from different tenants is separated at the database level and stored in separate PostgreSQL databases or using discriminator columns.
Encrypted end to end. Patient data is protected with modern TLS encryption during transmission and encrypted at rest. For particularly sensitive data, customers can use their own managed encryption keys.
Built to meet the GDPR in practice. The platform supports data access and rectification rights, pseudonymization, as well as the implementation of retention and deletion periods.
Secure access.
Fully traceable.
Sign in as usual. Single sign-on and multi-factor authentication integrate seamlessly into existing identity systems.
Context-based permissions. Access to patient data is based on the user’s role and involvement in the patient’s treatment.
Every access is logged. Access to and changes made to patient data are recorded in a traceable, audit-proof audit trail.
Multi-layered protection.
Continuously validated.
Security across multiple layers. Firewalls, intrusion detection and prevention, and a zero-trust architecture protect the platform across multiple layers.
Protection that is regularly tested. Penetration tests and independent security audits assess the effectiveness of our security measures.
AI in a controlled environment. Patient data does not leave its controlled environment for model training. AI-generated outputs remain auditable and traceable.


