Security
Why iCura is safe for regulated care.
Ten layers of control protect every organisation on iCura — from how a user authenticates to how an AI action is approved. Nothing here is optional or configurable away.
Ten layers of control
Security that assumes it will be tested.
Role-Based Access Control
Every user sees only the data and actions their role permits.
Multi-Factor Authentication
Identity is verified beyond a password before access is granted.
Tenant Isolation
Each organisation's data is logically and securely separated.
Encryption In Transit and At Rest
Data is encrypted end-to-end, on the wire and in storage.
Immutable Audit Trails
Every action is recorded and cannot be altered after the fact.
Policy Enforcement Checkpoints
Governance rules are enforced at the point of action, not after.
Human Approval Workflows
High-risk AI and operational actions require a human decision.
GDPR-Ready Operating Model
Data handling is designed around UK and EU data protection law.
AI Governance Controls
Every AI output is explainable, scoped and auditable.
Azure Security Baseline
Built on Microsoft Azure's enterprise security foundation.
Ask your questions before you commit.
Our team will walk your IT and information governance leads through the full security model.