Verified security baseline
StrydeOS Data Handling and Security Policy
Effective date: March 2026 · Version 1.0 · Last reviewed: March 2026
Built for clinical precision with data protection as the baseline. This public policy summarises our operational controls for data residency, encryption, access, incident handling, and retention.
UK-hosted production infrastructure
Google Cloud eu-west2 (London)
Encrypted transport + storage
TLS in transit and AES-256 at rest
Role-based access controls
Access limited by account permissions
Event and access logging
Accountability and incident review trails
Data Residency
All production data is hosted in UK infrastructure. StrydeOS does not intentionally move patient-identifiable data outside approved UK hosting regions for routine operations.
Encryption & Access Control
Data in transit is encrypted using modern TLS standards. Data at rest is encrypted using managed cloud controls. Access follows role-based permissions with authentication and auditable events.
Audit Logging & Retention
Access and critical security events are logged for accountability. Retention and deletion are controlled through policy-based lifecycle controls and contractual obligations.
Incident Response
Security events are triaged through a documented response process. Where legally required, notifications are made to relevant supervisory authorities and affected parties within required timeframes.
Contact and requests
For security questions, data-subject requests, or to report a concern, contact hello@strydeos.com.