Skip to content

A data steward works with carefully organised records

Security architecture

Built for the record to outlive the encryption.

A record designed to last across decades needs named controls, visible boundaries and a migration path that begins before today's cryptography expires.

Security architecture

Six controls, stated plainly.

Security is enforced in the service, data and audit layers, with test coverage checked on every change.

Assurance

168 production services

5,447 automated tests at 100 percent coverage, enforced on every change.

Continuous verification
Encryption

AES-256-GCM

Envelope encryption at rest, scoped per owner.

Implemented
Access

Six-role capability model

A capability matrix enforced on every service that touches patient data, at the data layer rather than the interface.

Implemented
Audit

Append-only and independently verifiable

SHA-256 hash-chained audit records anchored to a write-once series.

Implemented
Cohorts

De-identification at the query layer

k-anonymity suppression at a minimum cohort of five distinct people. Secure aggregation reconstructs only the aggregate.

Implemented
Post-quantum

Hybrid ML-KEM and ML-DSA

Migration is underway ahead of the 2030 NIST deprecation of RSA-2048 and ECC P-256.

Migration underway

Assurance with a status

Architecture here. Standards in the Trust Center.

Shiora is built to HIPAA technical safeguards and SOC 2 criteria. ISO 27001 certification and ADHICS assessment are underway.

The Trust Center keeps each standard, its scope and its current status together.

Open the Trust Center

Institutional review

Review the architecture in your deployment context.

Talk to us