Powering the UK's most efficient NHS Right To Choose providers

Trust & compliance

Built for trust,
Secured for healthcare

Cerebric is a registered UKCA Class I medical device, architected from the ground up to meet and exceed the highest UK standards for data security, clinical safety, and privacy.

Certified & assured

Cyber Essentials Plus logo
NHS Data Security & Protection Toolkit (DSPT) logo
NHS DTAC logo
NHS DCB 0129 logo
GDPR Compliant logo
ICO Registered logo
Medical Device (UKCA Class I) logo
Penetration Tested logo

The standards we're certified against

Clinical safety & device regulation

Cerebric is regulated as a medical device and governed by NHS clinical safety standards.

UKCA Class I medical deviceRegistered
Registered under UK medical device regulations, with an Intended Purpose Statement and Basic UDI-DI in place.
NHS DCB 0129Compliant
A mandatory human-in-the-loop review for every report, backed by a maintained hazard log. Clinical content remains the responsibility of the qualified clinician.
NHS DTACPassed
Assessed against the Digital Technology Assessment Criteria: clinical safety, data protection, technical security and interoperability.

Data protection & privacy

Patient data handled beyond the NHS baseline, under UK law, with a registered Data Protection Officer.

NHS DSPTStandards Exceeded
Our latest annual assessment exceeded the baseline NHS England sets for handling patient data.
UK GDPR & DPA 2018Compliant
All data processed under a robust Data Processing Agreement, encrypted in transit and at rest, and fully GDPR compliant.
ICO registrationActive
Cerebric Ltd is formally registered with the ICO as a Data Processor.

Security assurance

Independent, externally audited evidence that our controls actually work.

Cyber Essentials PlusCertified
Independently audited technical controls: access control, secure configuration, malware protection and patch management.
Penetration testingAnnual
An annual, independent test of our application code by a CREST-approved provider.

GDPR-compliant hosting, 99.99% availability

Data protection

GDPR

Patient data is hosted in the UK and EU under GDPR.

In transitTLS 1.2+
At restAES-256

Availability

99.99%

Uptime target on a high-availability architecture, with a near-zero recovery time objective so clinics are never left waiting.

90 days agoToday

For procurement teams

Everything your information governance and clinical safety reviews ask for, self-serve through our live Trust Centre and always current.

  • Compliance certificates (Cyber Essentials, DSPT, DTAC, GDPR, UKCA Class I registration)
  • DCB0129 clinical safety documentation and hazard log
  • Data Processing Agreement (DPA)
  • Subprocessor DPAs and privacy documentation
trust.cerebric.io/public
Trust Centre
Cerebric Ltd · live compliance status
All controls active
Certifications
NHS DSPTStandards Exceeded
Cyber Essentials PlusValid
NHS DTACPassed
UKCA Class IRegistered
ICO RegistrationActive
Documents
Compliance certificatesPDF · 8 filesDownload
DCB0129 clinical safety & hazard logPDFDownload
Data Processing Agreement (DPA)PDFDownload
Subprocessor DPAs & privacy docsPDFDownload
Penetration test summary (CREST)PDFDownload

Security, compliance & procurement FAQs

Where is our patient data hosted?

All data is hosted in the UK and EU under GDPR, encrypted in transit (TLS 1.2+) and at rest (AES-256).

Is Cerebric a medical device?

Yes. Cerebric is a registered UKCA Class I medical device, with an Intended Purpose Statement and Basic UDI-DI in place confirming its role as an administrative efficiency tool with a clinician always in control.

What compliance evidence can you provide for procurement?

Our live Trust Centre provides certificates, the DCB0129 hazard log, our DPA and subprocessor documentation on request. We hold NHS DSPT (Standards Exceeded), DTAC, Cyber Essentials Plus, ICO registration and annual CREST-accredited penetration testing.

How does Cerebric's pricing work?

Cerebric is quote-based; there are no public price lists. Pricing scales with your assessment volume and the parts of the pathway you deploy, from the reporting module alone through to the full platform. Book a consultation and we'll scope pricing to your service.

What are the contract terms?

Contract terms (commitment, notice and support) are agreed as part of scoping your deployment. Speak with our team and we'll set them out for your service before you commit.

Can we get our data out if we leave?

Yes. Cerebric exports activity data as CSV (the format used for NHS submissions such as MHSDS and CSDS), and data handling is configurable. All data is held in the UK under a Data Processing Agreement, and patient data is never used to train models for other clients.

How much effort is onboarding?

Typical deployment is around four weeks. Staff onboarding is supported by a built-in Training Centre with completion certificates, and report templates are tailored to your existing structure and language as part of set-up.

Join leading practices already using Cerebric