security & data sovereignty
The safest cloud is the one that answers to you.
Run RadForms inside your own network, or have Trucell host a dedicated instance for you in our private cloud. Either way the discipline is the same: encrypted transport, strong identity, complete audit trails and signed, tamper-evident records.
Deployment · single stack, your host
- edgeNginx reverse proxy · TLS termination · rate limiting
- webNext.js app · HTTPS · CSP-friendly static assets
- apiFastAPI · JWT auth · Pydantic validation · audit middleware
- dataPostgreSQL 15 · SSL connections · nightly backups
- dicomMWL C-FIND & C-STORE on your LAN · configurable AE titles
your infrastructure or trucell's private cloud · docker compose
the controls
Built for healthcare operations, reviewed like software.
Everything below ships in the product — not on a roadmap slide.
sovereignty
Your infrastructure — or ours, dedicated to you
Self-host RadForms in Docker behind your own firewall, or have Trucell run it as a managed service in our private cloud. Either way it's a dedicated instance: patients, forms, signatures and audit logs live in their own PostgreSQL database, with no shared multi-tenant storage and no third-party data processing.
transport
Encrypted in transit, end to end
HTTPS/TLS on every service — web, API, and even the internal database connection. Certificates are generated at install and replaceable with your CA-signed certificates for production.
identity
Enterprise identity, healthcare defaults
JWT-based sessions with bcrypt-hashed credentials, enforced password complexity, rate-limited logins, TOTP multi-factor authentication for administrative access, and LDAP / Active Directory integration for single sign-on — with ClaveÚnica national-ID sign-in available for Chilean deployments.
access
Role-based access control
Admins, staff and clinicians see what their role allows. User licensing is pooled and auditable, and kiosk devices authenticate with their own scoped tokens — never a shared staff login.
audit
Every PHI access, on the record
Form completions, PDF downloads, PACS routing, logins and configuration changes are written to an audit log with user, action, timestamp and IP — structured JSON, ready for your SIEM.
integrity
Tamper-evident signed forms
Completed forms — including Medicare AoB agreements — are sealed with an Ed25519 digital signature over a canonical serialisation of the data. Any alteration voids the signature, and every record can be re-verified on demand. Keys rotate without invalidating history.
devices
Locked-down at the bedside
Kiosk mode confines shared tablets to the form in front of the patient, with pairing codes, inactivity timeouts and staff PIN confirmation. Per-site Android builds slot into your MDM, including remote wipe.
resilience
Backups you can actually restore
Scheduled database and document backups to local disk, NAS, S3 or Azure Blob with retention policies — plus documented disaster recovery: 2–4 hour RTO, 24-hour RPO or better, and a pre-update backup before every release is applied.
Deploying RadForms on your own infrastructure means it inherits — and is designed to support — the privacy and security obligations your organisation already operates under, whether that's the Australian Privacy Principles, the NZ Privacy Act or Chile's data-protection law. Instances hosted by Trucell are operated under the certified management system described below. Ask us for the deployment security guide and disaster-recovery runbook during your evaluation.
compliance & certifications
Certified quality. Audited security.
RadForms is built and supported by Trucell Pty Ltd, which runs a single integrated management system across sixteen frameworks — from ISO 9001 quality management to the Australian Government ISM.


ISO 9001:2015
Quality management
Quality management system across service delivery, document control, corrective action and management review.
ISO/IEC 27001:2022
Information security
Information security management system — risk methodology, Statement of Applicability, access control and incident response.
ISO/IEC 27701
Privacy management
Privacy information management covering PII mapping, data-subject rights and breach response.
ISO 22301:2019
Business continuity
Continuity plans, business impact analysis and an exercise programme — the discipline behind RadForms' documented RTO/RPO targets.
ISO/IEC 27017 + 27018
Cloud security & PII
Cloud security controls and protection of personal information in public clouds.
SOC 2 Type II
Trust services criteria
Controls and evidence programme across security, availability, confidentiality and privacy.
IRAP · Australian ISM
OFFICIAL: Sensitive
System security plan and ISM controls matrix for Australian-government-aligned environments.
PCI DSS v4.0
Payment security
Payment-card data security under an annual self-assessment regime.
Ask for the current compliance pack, certificates and audit evidence during your evaluation.
Bring your IT team to the demo.
We'll walk the architecture, the audit log and the recovery drill — the questions security reviews actually ask.