Security and compliance
How Radly protects clinician and patient data
Radly supports radiologists with an assistant workflow. This page summarises the controls we use to safeguard data, honour deletion requests, and support compliance reviews.
Core safeguards
Encryption
Data in transit is encrypted with TLS 1.2+ and data at rest is encrypted using AES-256 aligned with cloud-provider best practice.
Access controls
Role-based access limits internal data access. Administrative actions require SSO and are audited.
Retention
Async job results expire after six hours while usage and audit logs stay available for 90 days before automatic cleanup.
Audit and monitoring
- Access logs are retained for 90 days and can be shared with partner security teams on request.
- Administrative actions (template updates, user changes) require multi-factor authentication and are reviewed weekly.
- Third-party vendors undergo regular security reviews aligned with their risk profile.
Data subject requests
Email [email protected] to request deletion, export, or to review subprocessors. We respond within two business days.
Radly assists clinicians. Radiologists review and finalise every report.
Ready to evaluate with your security team?
Download the compliance pack or contact us for a tailored review. Five complimentary reports are included for trials.