Bespoke software, and AI you can trust with your own data.
The biggest reason teams hold their data back from AI is that they can’t be sure where it goes. MedRep is built the other way round: secure, commercial-grade AI grounded in your own business that never leaks and never trains public models — on a foundation where isolation, least-privilege access and accountability are properties of the platform, not promises in a policy document.
The intelligence is yours. So is the data behind it.
MedRep gives you commercial-grade AI trained on your catalogue, your documents and your processes — and grounded in them every time it answers. It draws from your own material and cites the source, so the answers are trustworthy rather than invented. Your data never leaves your control to train shared or public models, and it is never pooled with anyone else’s.
- Answers grounded in your own documents — cited, never invented
- Your content never trains shared or public models
- Nothing is pooled with other customers’ data
- Runs on your isolated environment, in your chosen region
“What does our latest IFU say about device compatibility?”
Answered directly from your own document library — with the exact source cited, and nothing sent off to train a public model.
Source · device-ifu.pdf · p.4
Security that’s engineered in, not bolted on.
Each control below is part of how the platform is built — from how your AI handles your data to how every service authenticates. They reinforce one another, so no single mistake exposes your data or anyone else’s.
AI grounded in your own data
Your AI is trained on your catalogue, documents and processes — and nothing else. It answers from your own material with the source cited, so you get instant answers you can trust rather than confident guesses.
Your data never trains public models
The content you put to work in MedRep is never used to train shared or public models, and it never leaves your environment to do so. Your knowledge stays your advantage — it is not pooled, mined or resold.
Strict isolation between customers
Every customer-scoped table enforces row-level security in the database itself. Queries are filtered by customer at the engine, not just in application code, so an ordinary query cannot reach another customer’s data.
Managed-identity service auth
Services authenticate to each other and to platform resources using managed identities. There are no service credentials in source code, environment files or pipelines to leak, rotate by hand, or lose.
Secrets in a managed key vault
Connection strings, API keys and signing material live in a managed key vault with access policies and audit logging — pulled at runtime by identity, never baked into builds or container images.
Encryption in transit and at rest
Traffic is encrypted in transit with modern TLS, and data is encrypted at rest across databases, storage and backups using platform-managed keys. Encryption is on by default, everywhere.
Enterprise identity
Your staff sign in through your enterprise identity provider with workforce SSO, while your end users authenticate through a separate external identity directory — keeping internal and external populations cleanly apart.
Full audit trail
Sensitive actions — privileged access, data exports, permission changes and configuration edits — are recorded to a tamper-evident audit trail with actor, timestamp and context, ready for review and export.
Regional data residency
Workloads run in the cloud region you choose, with backups to a paired region in the same geography. Your data stays where your compliance team expects it to stay.
Layers, not a single line of defence.
If one control fails, the next still holds. Each layer is independent, and a boundary between customers has to be crossed at every level before any data is exposed — which, by design, it never is.
- 1Edge & WAF
A global edge with a web application firewall fronts every request before it reaches an origin.
- 2Identity
Enterprise SSO for staff and a separate external directory for end users gate who gets in at all.
- 3Session-bound context
The active customer is fixed from the verified session and cannot be overridden by request input.
- 4Managed-identity service auth
Internal calls authenticate by identity, with no shared secrets to intercept or replay.
- 5Row-level security
The database itself filters every customer-scoped table — the final, non-negotiable boundary.
- 6Audit & monitoring
Sensitive actions are logged and observable, so anomalies surface and access stays accountable.
A boundary you don’t have to trust us to remember.
The strongest isolation is the kind a developer can’t accidentally switch off. That’s why ours lives in the database and is set from the session on every connection — not in a code path that has to be remembered on each query. Privileged access exists, but it is rare, scoped and always written to the audit log.
- Isolation enforced by the database engine, not application convention
- No service secrets in code — managed identity throughout
- Encryption in transit and at rest, by default, everywhere
- Cross-customer access limited to administrators and fully audited
Your data, in your region, on terms your compliance team will recognise.
MedRep is built on enterprise-grade cloud infrastructure, so residency, resilience and governance come from a foundation your auditors already understand.
Regional residency
Deployed to the cloud region you choose, with backups to a paired region in the same geography. Data stays where you need it to live.
GDPR-ready handling
Lawful-basis-aware data handling with support for data-subject access requests and deletion, so you can meet your obligations to your own users.
Resilient by design
Paired-region backups and platform-managed redundancy underpin recovery objectives, with restores you can verify rather than assume.
Certifications and assurance, stated honestly.
We run GDPR-ready data handling and ISO-aligned operational practices, and we’re glad to share SOC 2 readiness details, data-processing terms and a completed security questionnaire on request. We won’t claim a certificate we don’t hold — ask us, and we’ll tell you exactly where we stand.
Security questions we hear most.
No. The documents and data you put to work in MedRep are used only to answer your own questions, grounded in your own material. They are never used to train shared or public models, and they are not pooled with other customers. Your knowledge stays your advantage.
Answers are retrieval-grounded: the assistant draws from your own document library and cites the source it used, rather than inventing a response. If the answer isn’t in your material, it tells you — it doesn’t guess.
Isolation is enforced in the database with row-level security on every customer-scoped table, and the active customer is set from the authenticated session on each connection. Even a buggy query cannot return another customer’s data, because the filter is applied by the database engine rather than trusted to application code.
From the authenticated session only. It is never taken from a request body, query parameter or path segment, so there is no input a caller can manipulate to cross a customer boundary.
Through managed identities issued by the platform. There are no shared secrets or service passwords in code or configuration to be exposed, and access can be revoked centrally.
In transit with modern TLS and at rest across databases, storage and backups using platform-managed keys. Application secrets are held in a managed key vault and fetched at runtime by identity.
We follow GDPR-ready data handling — including data-subject access requests and deletion — and ISO-aligned operational practices. We are happy to walk through SOC 2 readiness, data-processing terms and a security questionnaire on request.
Yes. Workloads are deployed to the cloud region you select, with backups to a paired region in the same geography for residency and disaster recovery.
Put our security posture in front of your reviewers
Book a working session with our team. We’ll walk your security and compliance reviewers through the architecture, the AI data controls and the evidence — on your real requirements.
