Our application services involve sensitive data subject to special data protection regulations, which we know exactly how to protect. For this reason, we operate data security and data protection at the highest level.
Physical security and backups
Our servers are located in ISO-certified Tier 4 high-security data centers in Switzerland. We are protected against physical failure with redundant RAID hard disks and duplex servers that mirror each other. Continuous backups of the data, including the data history between the backups, are not only stored on the mirrored servers themselves, but also at external, secure locations. This means that we can restore the system at any time in the event of a physical failure or data loss.
Data security
The adjumed.net data collection tool meets banking standards. With separate databases, SSL-encrypted transmission, IP blocking, cryptographically secured or department-specific encrypted master data and two-factor authentication, we can guarantee maximum access security. We have also implemented various other data security measures. For example, all movements in the system are traced, i.e. we can always tell who entered or queried what and when.
Data sovereignty and data protection
In principle, the data always belongs to the person collecting it or their patients. The collectors determine what happens to the data and when, and are in control at all times: everyone only has access to the data for which they are authorized. In the area of data protection, we work closely and openly with the official bodies (Federal Data Protection Commissioner and ethics committees) and our data protection officers. In Germany, we have been certified by the renowned ” TMF – Technologie- und Methodenplattform für die vernetzte medizinische Forschung e.V.” and included in the exclusive TMF toolpool. In addition, as part of the introduction of the Human Research Act, we had our entire documentation revised by David Rosenthal, a lawyer specializing in data protection. It is clear that our solution had to withstand all data protection reviews as part of the projects for highly specialized medicine.
Organizational and personnel security
In addition, our “AQC” system has been ISO-certified in accordance with the ISO 9001:2015 standard for quality management systems since September 2006 (SGS certificate CH06/0722). Our organizational processes are standardized and transparently documented. With around ten employees working solely on registry technology and its processing, we are also well staffed. We are prepared for critical incidents and the continuous improvement process has been implemented.
We know how important data security and data protection are for our customers and their patients. That’s why we spare no effort here and are constantly developing our system in this respect.
Regular security audits
We carry out emergency tests at regular intervals. We have all our systems extensively checked by external security experts. Our servers are secured against unauthorized access and malware using state-of-the-art technology. They are continuously tested for vulnerabilities (penetration test) and withstand attempted attacks. This has been confirmed by the security reports. The last security report was issued by Cyllective AG in October 2024. Any feedback from these audits is addressed and implemented swiftly. We also subject our programs to a continuous external code review to identify vulnerabilities.