Verbal assignment of benefit ended 1 July 2026

security & data sovereignty

The safest cloud is the one that answers to you.

Run RadForms inside your own network, or have Trucell host a dedicated instance for you in our private cloud. Either way the discipline is the same: encrypted transport, strong identity, complete audit trails and signed, tamper-evident records.

Deployment · single stack, your host

  • edgeNginx reverse proxy · TLS termination · rate limiting
  • webNext.js app · HTTPS · CSP-friendly static assets
  • apiFastAPI · JWT auth · Pydantic validation · audit middleware
  • dataPostgreSQL 15 · SSL connections · nightly backups
  • dicomMWL C-FIND & C-STORE on your LAN · configurable AE titles

your infrastructure or trucell's private cloud · docker compose

the controls

Built for healthcare operations, reviewed like software.

Everything below ships in the product — not on a roadmap slide.

sovereignty

Your infrastructure — or ours, dedicated to you

Self-host RadForms in Docker behind your own firewall, or have Trucell run it as a managed service in our private cloud. Either way it's a dedicated instance: patients, forms, signatures and audit logs live in their own PostgreSQL database, with no shared multi-tenant storage and no third-party data processing.

transport

Encrypted in transit, end to end

HTTPS/TLS on every service — web, API, and even the internal database connection. Certificates are generated at install and replaceable with your CA-signed certificates for production.

identity

Enterprise identity, healthcare defaults

JWT-based sessions with bcrypt-hashed credentials, enforced password complexity, rate-limited logins, TOTP multi-factor authentication for administrative access, and LDAP / Active Directory integration for single sign-on — with ClaveÚnica national-ID sign-in available for Chilean deployments.

access

Role-based access control

Admins, staff and clinicians see what their role allows. User licensing is pooled and auditable, and kiosk devices authenticate with their own scoped tokens — never a shared staff login.

audit

Every PHI access, on the record

Form completions, PDF downloads, PACS routing, logins and configuration changes are written to an audit log with user, action, timestamp and IP — structured JSON, ready for your SIEM.

integrity

Tamper-evident signed forms

Completed forms — including Medicare AoB agreements — are sealed with an Ed25519 digital signature over a canonical serialisation of the data. Any alteration voids the signature, and every record can be re-verified on demand. Keys rotate without invalidating history.

devices

Locked-down at the bedside

Kiosk mode confines shared tablets to the form in front of the patient, with pairing codes, inactivity timeouts and staff PIN confirmation. Per-site Android builds slot into your MDM, including remote wipe.

resilience

Backups you can actually restore

Scheduled database and document backups to local disk, NAS, S3 or Azure Blob with retention policies — plus documented disaster recovery: 2–4 hour RTO, 24-hour RPO or better, and a pre-update backup before every release is applied.

Deploying RadForms on your own infrastructure means it inherits — and is designed to support — the privacy and security obligations your organisation already operates under, whether that's the Australian Privacy Principles, the NZ Privacy Act or Chile's data-protection law. Instances hosted by Trucell are operated under the certified management system described below. Ask us for the deployment security guide and disaster-recovery runbook during your evaluation.

compliance & certifications

Certified quality. Audited security.

RadForms is built and supported by Trucell Pty Ltd, which runs a single integrated management system across sixteen frameworks — from ISO 9001 quality management to the Australian Government ISM.

ISO 9001 quality management certification — Trucell
ISO/IEC 27001 information security certification — Trucell

ISO 9001:2015

Quality management

Quality management system across service delivery, document control, corrective action and management review.

ISO/IEC 27001:2022

Information security

Information security management system — risk methodology, Statement of Applicability, access control and incident response.

ISO/IEC 27701

Privacy management

Privacy information management covering PII mapping, data-subject rights and breach response.

ISO 22301:2019

Business continuity

Continuity plans, business impact analysis and an exercise programme — the discipline behind RadForms' documented RTO/RPO targets.

ISO/IEC 27017 + 27018

Cloud security & PII

Cloud security controls and protection of personal information in public clouds.

SOC 2 Type II

Trust services criteria

Controls and evidence programme across security, availability, confidentiality and privacy.

IRAP · Australian ISM

OFFICIAL: Sensitive

System security plan and ISM controls matrix for Australian-government-aligned environments.

PCI DSS v4.0

Payment security

Payment-card data security under an annual self-assessment regime.

Ask for the current compliance pack, certificates and audit evidence during your evaluation.

Bring your IT team to the demo.

We'll walk the architecture, the audit log and the recovery drill — the questions security reviews actually ask.