Security & Trust

Built for organisations that answer to regulators.

You hold clinical records, safeguarding concerns and workforce data. AmbuNet is designed so that access is isolated, justified, logged and consented โ€” not just permitted.

๐Ÿ—„๏ธ

Your own workspace. Strictly isolated.

Every customer runs in their own workspace on their own subdomain, provisioned automatically at signup. Organisation data and file storage are strictly segregated, and every request is authenticated and scoped to your organisation on the server โ€” one customer's clinical and HR data is never visible to another's.

๐Ÿ”

MFA โ€” with step-up for patient data

Multi-factor authentication (TOTP) protects sign-in, and reaching patient-identifiable data โ€” PTS patient lookup, governance record review, patient identifiers on medicine administrations โ€” requires a fresh MFA challenge. Even Site Admins cannot bypass it.

๐Ÿงฑ

Permissions enforced on the server

Every access rule is checked server-side on every request โ€” not just hidden in the interface. Layered controls: site admin, functional teams, module tiers (CAD Viewer / Dispatcher / Commander; PTS Crew / Co-Ordinator; hospital portal Ward / Site / Admin) and base-location scoping. A searchable permissions matrix in the documentation shows exactly who can do what.

๐Ÿ“œ

Audit everywhere

A dedicated audit trail records creates, updates, deletes, views, exports and approvals with actor, reason and timestamp. Opening a patient record requires a stated reason. Every share-code access attempt โ€” successful or not โ€” is logged with name, organisation and IP. Control rooms write system logs for every operational change automatically.

๐Ÿ“

Consent-first location tracking

Crew location is only ever shared after an explicit approval on the crew member's own phone โ€” time-boxed to the shift, stopped at clock-out, with every request and response logged. Patient tracking links are deliberately minimal: a plain-language status and ETA that expires after six hours, with no map and no other patients' data.

๐Ÿ›ก๏ธ

Hardened by default

Session authentication with rolling refresh, bcrypt password hashing, Helmet security headers, strict CORS, reCAPTCHA on all public forms, and versioned terms and privacy acceptance tracking for every user.

๐ŸŒ

UK & Ireland data residency

Separate regional estates for the UK and the Republic of Ireland โ€” customer data stays in its region, with regional VAT and currency handled natively.

โš•๏ธ

Clinical safety governance of the product itself

AmbuNet maintains a DCB0129-style clinical risk hazard log across all modules โ€” the same discipline we ask of our customers, applied to the software they run on.

Designed-in, not bolted-on

Privacy decisions you can defend to the ICO, CQC and your patients.

โ“

Reason-for-access

Governance staff searching patient records must record why โ€” and the reason travels with the audit entry.

โฑ๏ธ

Time-limited sharing

ePCR share codes for receiving hospitals expire and are revocable, behind patient-detail matching and reCAPTCHA on a no-login page.

๐Ÿ™ˆ

Protected incident subjects

Incident reports support "hidden from" protection, so the subject of a concern can't see the investigation about them.

๐Ÿงพ

Impersonation with a paper trail

Support access to a tenant records the reason and device fingerprint โ€” no silent logins.

โœ…

Safeguarding by design

Every full clinical record must answer the safeguarding question before submission โ€” review is MFA-gated and tracked as a KPI.

๐Ÿ”

Offline data stays encrypted

Draft clinical records held on crew phones while offline are encrypted on-device and sync in the background when coverage returns.

Questions about security or data protection?

Start a trial and see the audit trail, permissions matrix and MFA step-up behaviour first-hand โ€” or dig deeper in the in-app documentation.