Security & privacy
Security and privacy as a foundation.
Triagen processes sensitive health data. Below you can read how we handle certifications, data storage, GDPR, and medical confidentiality.
Certification
Certification & Standards.
ISO 27001
Certified since August 2026. ISO 27001 is the international standard for an information security management system: risks mapped, controls documented and audited externally every year.
NEN 7510
Certified since August 2026. NEN 7510 is ISO 27001 applied to healthcare information, the standard you should expect from anyone handling medical data.
Both certificates cover the Triagen platform. To us a certificate is the baseline, not the proof: an audit tests the management system on a sample basis. So do ask further.
Trust Center
Our Trust Center holds our current security controls, certifications, subprocessors and documentation. Publicly accessible and always up to date.
Open Trust CenterData & privacy
Data Sovereignty & GDPR.
Data Location
All health data is stored encrypted (AES-256) and transmitted (TLS 1.3) within the Netherlands and the EU. We do not use sub-processors outside the EEA.
Privacy by Design
Data is processed exclusively through secure API connections. Model training on customer data is disabled β your health data is never used to improve AI models.
Processing Agreement
A standard GDPR-compliant data processing agreement is available for all organizations working with Triagen.
Medical confidentiality
Medical Confidentiality & WGBO.
Access to patient data is strictly regulated through Role-Based Access Control (RBAC). Only authorized professionals have access.
Role-Based Access Control (RBAC)
Only authorized professionals
All access is logged in accordance with ISO 27001 and NEN 7510
Full audit trail at API and database level
Explicit employee consent prior to AI interaction
What the AI does and does not do, and who decides, is set out in How we use AI.
Contact
Questions about our security architecture?
Our team is happy to answer your questions about security, compliance, and data protection.
