Built to protect
your data
Security and privacy are not features we added later — they are the foundation Consenta is built on. Here is how we keep health data safe and put people in control.

How we keep data safe
A privacy-first, federated architecture means value can be created from health data without compromising the people it belongs to.
Data never leaves
Anonymisation runs on-premises inside each organisation using our federated edge nodes. Raw patient records are never transferred to Consenta or to buyers.
Encrypted end to end
All data is encrypted in transit (TLS) and at rest. Cryptographic integrity records protect every dataset snapshot from tampering.
Dynamic, granular consent
Patients see exactly who wants their data and for what purpose, and can grant, adjust or withdraw consent per purpose at any time.
Anonymised at source
Datasets are de-identified using k-anonymity and related techniques before they can ever be licensed, minimising re-identification risk.
Strong access controls
Role-based access, mandatory two-factor authentication on every account, and least-privilege permissions across the platform.
Immutable audit trail
Every consent decision and data transaction is logged on a tamper-evident audit trail, with optional low-cost blockchain anchoring.
A federated approach
Rather than centralising sensitive records, Consenta pushes processing to the edge. Each organisation keeps its own data behind its own firewall; only anonymised, consented, aggregate datasets are ever made available. This dramatically reduces the attack surface and means a breach of one node cannot expose the raw data of another.
Your privacy rights
Consenta is designed around UK GDPR and international best practice. You remain in control of your personal data at all times.
Right to be informed
Clear, plain-English explanations of how your data may be used — before you decide.
Right to consent & withdraw
Grant or revoke consent at any time. Withdrawal stops future use of your data immediately.
Right of access
See the record of what you have consented to and the history of how your data has been used.
Right to erasure
Request deletion of your personal data in line with UK GDPR, subject to legal retention requirements.