Trust Centre
Compliance built into
how we handle your evidence.
MediiC is a trade name of Tritone Health Ltd. Here's the formal picture: how your certificates, policies and audits are hosted and protected, and where we stand against the frameworks that matter for UK health and social care technology.
Cyber Essentials
CertifiedCyber Essentials is the UK government-backed scheme verifying the baseline technical controls an organisation handling sensitive data should have in place. MediiC is certified against it.
What this covers
- Boundary firewalls and internet gateways on every environment
- Secure configuration of all devices and software
- User access control, least-privilege by default
- Malware protection across every device
- Security patches applied promptly
Request documentation
Documents are provided by email, typically acknowledged within one business day.
Cyber Essentials certificate
Current certification, renewed annually against NCSC-backed IASME criteria.
Request →UK GDPR & Data Protection Act 2018
Data protection by designMediiC processes certificates, policies, audits and care-related evidence on behalf of regulated providers, hosted on Microsoft Azure. Every workspace is access-controlled and every change to a record is logged, so it's always clear who saw or changed what, and when.
What this covers
- UK GDPR & Data Protection Act 2018
- Workspace-scoped access: staff only see the services and records they're assigned to
- Every record change written to an append-only audit trail
- Data encrypted in transit and at rest
- Data Processing Agreement available on request
Request documentation
Documents are provided by email, typically acknowledged within one business day.
Data Processing Agreement
Standard DPA covering MediiC's processing of provider and staff data.
Request →Data Protection Impact Assessment
Architecture-level DPIA covering evidence upload, storage and AI review.
Request →EU AI Act
Human review, alwaysMediiC's AI reads and structures evidence; it does not make the final call on whether a service is compliant. Every answer is graded by strength, proven, inferred, or claimed, and traces back to the actual document behind it, so a person always reviews before anything is treated as settled.
What this covers
- No prohibited AI practices under Article 5
- AI-derived answers clearly distinguished from human-verified evidence
- Every AI output traces back to a specific source document
- A person reviews and approves before a requirement counts as met
Request documentation
Documents are provided by email, typically acknowledged within one business day.
AI transparency overview
How MediiC's AI review process meets the Act's transparency and human-oversight principles.
Request →NHS Data Security and Protection Toolkit
Standards metThe DSPT is the annual self-assessment NHS and social care organisations use against the National Data Guardian's data security standards. MediiC keeps its own submission current, and is built so the providers using it can evidence their own DSPT requirements more easily.
What this covers
- Annual DSPT submission, standards met
- Aligned to the National Data Guardian's 10 data security standards
- Staff training and access controls matched to NHS requirements
- Incident reporting process in place
Request documentation
Documents are provided by email, typically acknowledged within one business day.
Digital Technology Assessment Criteria (DTAC)
Meets DTAC criteriaDTAC is the baseline standard NHS and social care organisations use to assess digital health technology before adoption, covering clinical safety, data protection, technical security, interoperability, and usability and accessibility.
What this covers
- Clinical safety considerations documented
- Data protection aligned to UK GDPR
- Technical security: Cyber Essentials certified, encrypted storage
- Interoperability with existing care and practice systems
- Usability and accessibility reviewed
Request documentation
Documents are provided by email, typically acknowledged within one business day.
Frequently asked questions
Where is our data hosted?
MediiC is hosted on Microsoft Azure. Uploaded evidence, certificates, policies and audits are stored encrypted, and every workspace's data is scoped so only the staff assigned to that service can see it.
Who can see our evidence?
Access is scoped per workspace and per role. A staff member only sees the services and record types they've been assigned to, not the whole organisation by default.
Does MediiC's AI make compliance decisions on its own?
No. The AI reads and structures your evidence and grades how strong it is, but every requirement is reviewed the way an experienced compliance officer would before it counts as met, and every answer traces back to the actual document behind it.
Does MediiC replace our existing care records or HR systems?
No. MediiC sits alongside what you already use. You bring your existing folders and files; it reads and organises them rather than asking you to re-enter anything.
Can our organisation use MediiC with confidence?
Yes. MediiC is Cyber Essentials certified, meets NHS DSPT and DTAC criteria, and is built around UK GDPR and EU AI Act requirements. Each framework has its own tab above with a summary and the documents you can request.