Security & Privacy
Cortex holds some of the most sensitive information in healthcare. Keeping it protected, private, and available is a core requirement of any clinical system, and we design for it at every layer of the platform.
Your data stays yours
Clinical data created in Cortex belongs to your organisation. Sense Medical acts as its custodian. We store it, protect it, make it available to your own systems, and give you a clear path to take it with you.
You own it
Your organisation owns all clinical data generated on the platform, backed by contractual terms that say so, and you can export it in standard formats whenever you need it.
Data residency you control
Your data is hosted in the region your organisation requires and stays within the jurisdiction you agree to.
Your analytics, fed in real time
Structured clinical data streams to your organisation's own decision support and reporting infrastructure, ready for your teams to use.
How we handle health information
Health information carries obligations that go beyond ordinary data. We treat it that way, and we work inside the rules your organisation already operates under.
Handled lawfully
Sense Medical operates under the privacy laws of the jurisdictions where we work, including the specific protections that apply to health information.
Within your governance
We work inside your clinical information governance and information security frameworks, and we support the review and assurance processes your teams run.
Used only to run your service
We process clinical data to deliver Cortex to your organisation. We do not sell it, and we do not use it to train external AI models.
How the platform is protected
Cloud-native on AWS
Cortex runs as a containerised, cloud-native application on Amazon Web Services, inheriting the infrastructure and physical security of one of the world's most heavily audited cloud platforms.
Encrypted in transit and at rest
Traffic between devices, the Cortex platform, and your clinical systems is encrypted in transit, with system integrations secured over mutually authenticated TLS. All data is encrypted at rest.
Enterprise identity and access
Single sign-on through your organisation's identity provider (Microsoft Entra ID, OpenID Connect), with role-based access aligned to clinical roles. Your existing joiners and leavers process stays in control of who has access.
A complete audit trail
Every document, task, and message in Cortex is timestamped and attributed to an identified clinician, giving you an auditable record of who did what, and when.
Tenant isolation
A multi-tenant architecture keeps each organisation's data logically separated, supporting deployment across separate health systems and regions.
Independently reviewed and tested
The platform is subject to regular independent security review and testing, and operates within the security assurance frameworks of the organisations we serve.
Built to stay available when clinicians need it
A clinical system has to work in the moments that matter most. Cortex is built to keep running through network problems and to recover quickly from disruption, so patient care is never waiting on technology.
Offline-first
Clinicians keep working through network interruptions, and the platform synchronises intelligently when connectivity returns.
Backup and recovery
Clinical data is continuously backed up, with recovery processes designed to restore service quickly after disruption.
Proven in production
Cortex runs in continuous hospital production, supporting clinical teams day in and day out.
A clear response if something goes wrong
Sense Medical maintains a defined incident response process. If a security incident occurs, we act quickly to contain and investigate it, keep you informed throughout, and notify affected customers in line with our contractual and legal obligations. Our team works directly with your security and governance contacts before, during, and after any incident.
Questions from your security team?
We work through security, privacy, and information governance requirements directly with your assurance and governance teams.