Skip to main content
CareBond

Compliance

Compliance by architecture, not by addendum.

Native nLPD, KVG/LAMal, exclusive Swiss hosting, immutable audit log. Compliance isn't a layer we added — it's built into the platform from line one.

Native nLPD

Native audit log of accesses and modifications, built for Swiss law from the first line of code. Not a recycled GDPR patch.

Swiss hosting

Infrastructure hosted at Infomaniak (Geneva). Patient data does not leave Swiss territory — no exception, no hidden clause.

Modern encryption

Modern TLS in transit on a Swiss server, encryption of sensitive fields (PHI), HMAC-signed visit reports.

Immutable audit log

Immutable trace of every access and modification, exportable for your internal audits and cantonal authorities. Granular RBAC and multi-institution.

Regulatory framework

Built for Swiss law.

CareBond was built for specific Swiss requirements, not adapted from a European product. Here are the main frameworks we address.

  • nLPD (Federal Act)

    Federal Act on Data Protection. Native audit log, rights of access and rectification, complaint route to the FDPIC documented in our privacy policy.

  • KVG / LAMal

    Cryptographically signed visit reports (HMAC), traceability as a basis for justification to the health insurer (Spitex).

  • International transfers

    The few transfers outside Switzerland (contact form via Resend, hosting via Vercel fra1 Frankfurt) are governed by Standard Contractual Clauses and documented.

Certifications

Targeted certifications

Beyond the nLPD requirements and data sovereignty already covered by our architecture, CareBond aims to obtain the international certifications expected by hospital procurement teams.

  • Medium-term target

    ISO/IEC 27001

    Information security management system. Certification set as a medium-term target.

  • Target (reference)

    HDS — French Health Data Host

    French reference for health data hosting, considered as a comparative target. Our main argument is hosting in Switzerland.

Technical documentation

Your legal and IT teams want the details?

We keep complete technical documentation available: architecture, data flows, audit log, retention policies, processor contract templates. On request, with no form to fill out.