Skip to content

Security & Trust Centre

Clinics trust Marlmed with sensitive stock, patient, and controlled-drug records. This page sets out, in plain terms, how we protect that data - so your due-diligence questions are answered in one place.

Last updated: July 2026

Where your data is hosted

Your data stays in the UK. Marlmed runs on DigitalOcean's London (lon1) region - the production database, application servers, and backups are all held in the United Kingdom. Data is not moved outside the UK or EEA except for specific sub-processors (such as email and payments), each under UK GDPR-compliant safeguards. See our sub-processors list.

Encryption

  • In transit: TLS 1.2 or higher on every public endpoint, with automatically renewed certificates.
  • At rest: the storage volume holding the production database is encrypted with full-volume (LUKS) encryption, and every database backup is independently encrypted with AES-256 before it is stored.

Backups and recovery

Database backups run automatically every night, each encrypted with AES-256 and integrity-checked immediately after it is written. We keep a rolling 14-day history on UK infrastructure, used only for disaster recovery, with extended retention available on request. Our targets are a recovery point of under 24 hours and a recovery time of under 4 hours; these are internal targets rather than a guaranteed service level.

Access control and authentication

  • Role-based access control with fine-grained, per-product permissions - for example, co-signing a controlled-drug movement requires a specific sign-off permission.
  • Passwords are hashed with Argon2id and a per-instance pepper; they are never stored in plain text.
  • Sessions use versioned tokens, so every session for an account can be revoked instantly if it is ever compromised.
  • Multi-factor authentication (TOTP) is available on every account, with enforced MFA being rolled out for privileged administrator roles.
  • Authentication endpoints are rate-limited with account lockout, and access to production systems is restricted, key-based, and logged.

Tenant isolation and a tamper-evident audit trail

Marlmed is multi-tenant by design. Every organisation's data is isolated by a scope identifier enforced at the data-access layer, so the platform is built so that one clinic cannot access another's records. Every significant action is written to an audit log secured with a SHA-256 hash chain, scoped per organisation and product. Any later attempt to alter, insert, or delete an audit entry is detectable, and you can request a chain-integrity check at any time.

Your data, your control

You own your data. You can export your full data set - stock, contacts, audit log, and configuration - in CSV or JSON at any time during your subscription and for 30 days after it ends. Your organisation's data is retained for 90 days after termination in total before it is securely and permanently deleted. We support data-subject erasure requests, with one exception: entries the law requires us to keep (such as controlled-drug movements under the Misuse of Drugs Regulations) are pseudonymised in place rather than deleted, so the regulatory record stays intact.

Payments

All card payments are handled directly by Stripe, a PCI DSS Level 1 provider. Marlmed never sees or stores full card numbers, security codes, or expiry dates.

Sub-processors

We use a small, vetted set of sub-processors to run the service (hosting, transactional email, and payments). The full list - what each one does and where it processes data - is on our sub-processors page, and we give notice before adding a new one.

Breach response

If a personal-data breach affects your data, we notify you without undue delay and, in any event, within 24 hours of becoming aware - with the information you need to meet your own regulatory obligations as the data controller.

Data Processing Agreement

We publish our UK GDPR Data Processing Agreement (DPA), which covers how we process personal data on your behalf. Read it in full at marlmed.com/dpa, or request a countersigned copy for your organisation at [email protected].

This page describes our current security practices and is reviewed regularly. It is provided for transparency and does not by itself form part of your contract; our Terms of Service and the Data Processing Agreement govern our legal commitments. Security or due-diligence questions are welcome at [email protected].