Consenta← Back to home
Security & Compliance

Built for GDPR, HIPAA & Cyber Essentials

Consenta keeps raw patient data inside the client boundary and publishes only anonymised, risk-assessed data with verifiable, tamper-evident proofs.

GDPR

EU / UK GDPR

  • Lawful basis: explicit, granular, revocable patient consent captured per cohort and purpose.
  • Data minimisation: only anonymised, risk-assessed data leaves the client boundary.
  • Right to erasure: consent withdrawal removes the subject from the lake and all future snapshots.
  • Records of processing, audit trails and Data Processing Agreement support.

HIPAA

US Health Data

  • Safe Harbor de-identification: 18 identifiers suppressed or generalised at the edge.
  • No PHI reaches the platform — raw data is processed only inside the client environment.
  • Access controls, audit controls, integrity and transmission security safeguards.
  • Business Associate Agreement (BAA) ready operating model.

Cyber Essentials

UK NCSC

  • Boundary firewalls and secure configuration by default.
  • Least-privilege access control with multi-factor authentication.
  • Patch and vulnerability management across the platform.
  • Malware protection and continuous monitoring of privileged access.

Core security controls

Data stays at the edge

The Edge Anonymisation Engine runs inside the client’s on-premises, private cloud or VPC. Only anonymised snapshots and non-identifying proofs are published outbound.

Encryption everywhere

Encryption in transit (TLS 1.2+) and at rest, with customer-managed keys available where required.

Zero-trust access

MFA, least-privilege roles, privileged-access approval and full session logging.

Immutable audit

Every consent, certificate and sale event is recorded with a tamper-evident SHA-256 proof — anchored on Polygon or stored securely off-chain.

Revocation by design

Withdrawing consent deactivates the subject’s data lake objects and excludes them from every future dataset and sale.

Tenant isolation

A separate tenant boundary and encryption context for every client organisation.

Information governance templates

Draft governance artefacts are available in the platform documentation library for signed-in administrators. They are provided as starting-point templates and must be reviewed by your DPO / legal counsel before use.

Detailed user guides are available inside each portal after you sign in — patients, organisations, buyers and administrators each have guidance tailored to their role.