Security at Remy

Last updated: 14 July 2026

Remy handles sensitive healthcare information, so security and privacy are built into how we operate. This page summarises the measures we use to protect your practice's data. For how we process personal data, see our Privacy Policy and Data Processing Agreement.

Data hosting and residency

  • Core data (database, authentication, file storage) is hosted with Supabase in London, UK, keeping it within the UK.
  • Telephony is routed via an EU (Dublin) edge where available.
  • Where a sub-processor operates outside the UK/EEA, we use appropriate transfer safeguards (Standard Contractual Clauses and/or the EU-US Data Privacy Framework). See our Sub-processor list.

Encryption

  • In transit: all traffic is encrypted with TLS.
  • At rest: data stored in our database and file storage is encrypted.
  • Sensitive credentials (such as integration API keys and OAuth refresh tokens) are encrypted at the application layer before storage.

Access control and tenant isolation

  • Every practice is a separate tenant. Row-level security enforces that one organisation can never access another's data.
  • Role-based access control limits what each user can see and do.
  • Sign-in uses OAuth / single sign-on (Google and Microsoft) with support for your provider's security controls.
  • Internal access to production data is on a least-privilege, need-to-know basis by authorised personnel only.

Monitoring, logging and backups

  • Key actions and access are audit-logged.
  • Data is backed up on a regular schedule with restoration processes in place.
  • We monitor for errors and anomalies to keep the service available and secure.

Secure development

  • Changes go through code review and automated checks (type-safety, schema validation, tests) before release.
  • Environments are separated; secrets are managed securely and never committed to source control.

Incident response and breach notification

  • We maintain a documented incident-response process. If a personal data breach affects your data, we will notify you without undue delay in line with our DPA so you can meet your own obligations.

Sub-processors

We use a vetted set of service providers, each under a data processing agreement requiring appropriate security. The current list, purpose and location of each is published at /legal/subprocessors.

Certifications

We'll list any formal security certifications we hold here as they're awarded. If your organisation has a specific assurance requirement — for example Cyber Essentials, ISO 27001, or the NHS Data Security and Protection Toolkit — please contact security@remy.health and we'll tell you where we are.

Responsible disclosure

If you believe you've found a security issue, please email security@remy.health. We welcome responsible disclosure and will acknowledge your report promptly. Please give us reasonable time to investigate and remediate before any public disclosure, and do not access or modify data that isn't yours.