Verified security baseline

StrydeOS Data Handling and Security Policy

Effective date: March 2026 · Version 1.0 · Last reviewed: March 2026

Built for clinical precision with data protection as the baseline. This public policy summarises our operational controls for data residency, encryption, access, incident handling, and retention.

UK-hosted production infrastructure
Google Cloud eu-west2 (London)
Encrypted transport + storage
TLS in transit and AES-256 at rest
Role-based access controls
Access limited by account permissions
Event and access logging
Accountability and incident review trails

Data Residency

All production data is hosted in UK infrastructure. StrydeOS does not intentionally move patient-identifiable data outside approved UK hosting regions for routine operations.

Encryption & Access Control

Data in transit is encrypted using modern TLS standards. Data at rest is encrypted using managed cloud controls. Access follows role-based permissions with authentication and auditable events.

Audit Logging & Retention

Access and critical security events are logged for accountability. Retention and deletion are controlled through policy-based lifecycle controls and contractual obligations.

Incident Response

Security events are triaged through a documented response process. Where legally required, notifications are made to relevant supervisory authorities and affected parties within required timeframes.

Contact and requests

For security questions, data-subject requests, or to report a concern, contact hello@strydeos.com.