Security built into every layer
Cybersecurity
& Data Protection
As a certified medical AI device manufacturer, Avicenna.AI upholds the highest standards of data privacy and cybersecurity, protecting patients and healthcare institutions worldwide.
Security Framework
Three pillars of our cybersecurity commitment
ISO/IEC 27001
Our information security management system is independently certified to ISO/IEC 27001 by SGS. Controls are audited annually for continued conformance.
Data Privacy
We embed privacy by design and by default across our product life cycle. A dedicated Data Protection Officer leads our compliance programme.
Cloud Security
Patient Data is anonymized and encrypted in transit. Strict logical isolation between customer environments is enforced through our multi-tenant architecture.
In practice
Security measures
across our entire stack
Our security posture is a continuously maintained programme, not a one-time certification. It spans infrastructure, processes, and people.
End-to-end TLS 1.2+ encryption for all data in transit
Encryption at rest for all stored Patient Data
Role-based access control with least-privilege enforcement
Regular security awareness training for all staff
Regulatory landscape
Standards we comply with
ISO 81001-5-1
Security risk management runs through our entire software life cycle: design, development, deployment, and post-market monitoring. This ensures vulnerabilities are identified and addressed continuously, not just before release.
ISO/IEC 27001
Together with ISO 81001-5-1, our ISO 27001 certification extends security management from the organizational level into the product itself. Certification scope covers infrastructure, software development, and third-party integrations.
Europe
We maintain individual Data Processing Agreements with every customer and jurisdiction, and our dedicated DPO ensures data subjects can exercise their rights to access, rectify, or erase their information at any time.
United States of America
For US healthcare customers, Avicenna.AI operates as a Business Associate and executes Business Associate Agreements to ensure full HIPAA compliance. All Patient Data are anonymized before reaching our systems.
Your point of contact
Data Protection Officer
For GDPR or HIPAA enquiries, data subject access requests, or regulatory due diligence, our DPO is your dedicated contact.
We respond within 72 hours.

Stéphane Berger