Native nLPD
Native audit log of accesses and modifications, built for Swiss law from the first line of code. Not a recycled GDPR patch.
Compliance
Native nLPD, KVG/LAMal, exclusive Swiss hosting, immutable audit log. Compliance isn't a layer we added — it's built into the platform from line one.
Native audit log of accesses and modifications, built for Swiss law from the first line of code. Not a recycled GDPR patch.
Infrastructure hosted at Infomaniak (Geneva). Patient data does not leave Swiss territory — no exception, no hidden clause.
Modern TLS in transit on a Swiss server, encryption of sensitive fields (PHI), HMAC-signed visit reports.
Immutable trace of every access and modification, exportable for your internal audits and cantonal authorities. Granular RBAC and multi-institution.
Regulatory framework
CareBond was built for specific Swiss requirements, not adapted from a European product. Here are the main frameworks we address.
Federal Act on Data Protection. Native audit log, rights of access and rectification, complaint route to the FDPIC documented in our privacy policy.
Cryptographically signed visit reports (HMAC), traceability as a basis for justification to the health insurer (Spitex).
The few transfers outside Switzerland (contact form via Resend, hosting via Vercel fra1 Frankfurt) are governed by Standard Contractual Clauses and documented.
Certifications
Beyond the nLPD requirements and data sovereignty already covered by our architecture, CareBond aims to obtain the international certifications expected by hospital procurement teams.
Information security management system. Certification set as a medium-term target.
French reference for health data hosting, considered as a comparative target. Our main argument is hosting in Switzerland.
Technical documentation
We keep complete technical documentation available: architecture, data flows, audit log, retention policies, processor contract templates. On request, with no form to fill out.