
Security, privacy and standards
Trust Center
Shiora holds the most sensitive category of personal data there is. This is how it is protected, which standards it is built to and where each certification stands.
Standards and certifications
A clear status for every standard.
Implementation, architecture alignment, certification and migration are distinct states. This table keeps the distinction visible.
| Standard | Scope | Status |
|---|---|---|
| AES-256-GCM encryption at rest | All patient data | Implemented |
| GDPR Articles 15, 17, 20 | Access, erasure, portability | Implemented |
| HL7 FHIR R4 | Import and export | Implemented |
| HIPAA technical safeguards | Access control, audit, integrity, transmission security | Built to |
| SOC 2 Trust Services Criteria | Security, availability, confidentiality | Built to |
| ISO 27001 | Information security management | Certification underway |
| ADHICS | UAE healthcare information security | Assessment underway |
| NIST FIPS 203 / 204 | Post-quantum cryptography | Migration underway |
Inspect the detail
Four views of the same responsibility.
Each page moves from plain-language assurance to the technical detail an individual, clinical partner or procurement team needs.
Institutional review


