You hold clinical records, safeguarding concerns and workforce data. AmbuNet is designed so that access is isolated, justified, logged and consented โ not just permitted.
Every customer runs in their own workspace on their own subdomain, provisioned automatically at signup. Organisation data and file storage are strictly segregated, and every request is authenticated and scoped to your organisation on the server โ one customer's clinical and HR data is never visible to another's.
Multi-factor authentication (TOTP) protects sign-in, and reaching patient-identifiable data โ PTS patient lookup, governance record review, patient identifiers on medicine administrations โ requires a fresh MFA challenge. Even Site Admins cannot bypass it.
Every access rule is checked server-side on every request โ not just hidden in the interface. Layered controls: site admin, functional teams, module tiers (CAD Viewer / Dispatcher / Commander; PTS Crew / Co-Ordinator; hospital portal Ward / Site / Admin) and base-location scoping. A searchable permissions matrix in the documentation shows exactly who can do what.
A dedicated audit trail records creates, updates, deletes, views, exports and approvals with actor, reason and timestamp. Opening a patient record requires a stated reason. Every share-code access attempt โ successful or not โ is logged with name, organisation and IP. Control rooms write system logs for every operational change automatically.
Crew location is only ever shared after an explicit approval on the crew member's own phone โ time-boxed to the shift, stopped at clock-out, with every request and response logged. Patient tracking links are deliberately minimal: a plain-language status and ETA that expires after six hours, with no map and no other patients' data.
Session authentication with rolling refresh, bcrypt password hashing, Helmet security headers, strict CORS, reCAPTCHA on all public forms, and versioned terms and privacy acceptance tracking for every user.
Separate regional estates for the UK and the Republic of Ireland โ customer data stays in its region, with regional VAT and currency handled natively.
AmbuNet maintains a DCB0129-style clinical risk hazard log across all modules โ the same discipline we ask of our customers, applied to the software they run on.
Designed-in, not bolted-on
Governance staff searching patient records must record why โ and the reason travels with the audit entry.
ePCR share codes for receiving hospitals expire and are revocable, behind patient-detail matching and reCAPTCHA on a no-login page.
Incident reports support "hidden from" protection, so the subject of a concern can't see the investigation about them.
Support access to a tenant records the reason and device fingerprint โ no silent logins.
Every full clinical record must answer the safeguarding question before submission โ review is MFA-gated and tracked as a KPI.
Draft clinical records held on crew phones while offline are encrypted on-device and sync in the background when coverage returns.
Start a trial and see the audit trail, permissions matrix and MFA step-up behaviour first-hand โ or dig deeper in the in-app documentation.