Security & compliance
The most secure imaging data
is the data we never keep.
Dicomly's security model starts with a simple idea: the safest place for patient data is your backend, not ours. We move the bytes and keep nothing — so there is no archive of imaging data on our side to leak, subpoena, or mismanage.
Trust surfaces & legal directory
Nothing is stored — no PHI at rest
DICOM bytes stream from the sender straight through to your HTTPS endpoint and are gone. Nothing is written to disk, a queue, or a cache — not even transiently. The only thing Dicomly keeps is routing metadata and usage counters (byte counts, instance counts, timestamps). No DICOM tags, no patient identifiers.
Per-device authentication with mTLS
Every DICOM source authenticates with its own client certificate over mutual TLS (read why mTLS is essential for DICOM). No shared secrets, no API keys handed to a PACS or modality. Revoke a single device without touching the others.
EU data residency
Infrastructure runs in the European Union — AWS eu-central-1 (Frankfurt, Germany). Traffic stays within EU-based facilities.
A conduit, not a custodian
Because nothing is persisted, Dicomly acts as a HIPAA conduit and a GDPR processor — not a data custodian. Your backend is where the data lives; Dicomly is just the pipe between the hospital and your app.
BAA / DPA available to everyone
A Data Processing Agreement (BAA-equivalent) is available to every customer — free, with no plan requirement. Read the full agreement at our DPA page, email info@dicomly.io for a signable copy, and receive a countersigned version within 1 business day — before you provision your first endpoint.
No buffering, predictable failure
If your app is down, Dicomly returns an error to the sender, which retries on its own schedule — exactly as the DICOM standard expects. No data is queued or held on our side, so there is no hidden store to breach.
Stripe processes card payments only
Stripe, Inc. processes card payments. Stripe receives billing data only — it never receives or stores DICOM data. Card numbers, CVC, and expiry are entered directly into Stripe and never touch our systems; we only see the card brand and last four digits.
Cryptographic Baselines
- Mutual TLS (mTLS) for every sender
- SHA-256 integrity baseline
- ECDSA certificate keys
- Encrypted in transit, end to end
Certification status
Where Dicomly runs is certified. All infrastructure is hosted in AWS Frankfurt (eu-central-1), operating under ISO 27001, SOC 1/2/3, and PCI DSS Level 1 certified physical, perimeter, and operational controls. Those are the hosting provider's certifications, and we name them as such.
Dicomly does not hold an ISO 27001 or SOC 2 certification of its own. The compensating controls we put in front of your assessment are architectural, and they remove most of what those audits exist to govern:
- Zero PHI at rest: no imaging data is ever written to disk, storage, queue, or cache, so the scope of a data breach is bounded by architecture rather than by policy. There is no imaging archive on our side to leak, subpoena, or mismanage.
- Per-device mTLS: every sender authenticates with its own client certificate. Access is cryptographic, individually revocable, and verifiable from your side of the connection.
- EU-only residency: processing, configuration data, and backups stay inside the European Union, under a GDPR Art. 28 agreement you can sign before sending a single study.
- Encrypted off-site backups: configuration backups are encrypted before they leave our systems; the storage provider holds ciphertext and no keys.
Every one of those controls is stated as a contractual measure in Annex II of the DPA— not as marketing copy.
Technical & Organisational Measures (TOMs) summary
Our security controls are designed to protect customer configurations, account credentials, and in-transit network communications under strict outcome-based controls:
1. Encryption & Transport Security
All DICOM associations require mutual TLS with modern ciphers. All egress STOW-RS webhooks use TLS 1.3/1.2. Public web and API endpoints enforce HTTPS with strict HSTS.
2. Access Control & Least Privilege
Administrative access to production infrastructure is restricted to named operators, authenticated by SSH key. There are no shared administrative accounts and no password-based administrative login.
3. Data Minimization & Zero Retention
Streaming memory buffers are bounded to the single active DICOM instance and discarded immediately upon webhook delivery. No DICOM tags or patient identifiers are ever logged.
4. Backup & Disaster Recovery
System configuration backups are automated daily, encrypted with customer-independent keys prior to upload, and stored off-site in the EU with a 4-hour recovery objective.
Sub-processors
Dicomly runs on infrastructure operated by Amazon Web Services in theeu-central-1 region (Frankfurt, Germany), within the European Union. Because no imaging data is stored, sub-processors never hold PHI at rest.
Cloudflare provides DNS, protection against attack and abuse, and website hosting; it sees connection metadata only, and the DICOM path bypasses it entirely, so imaging traffic never reaches Cloudflare.
Backblaze stores off-site system backups in the EU, encrypted with our keys before upload — it holds ciphertext only and never receives DICOM data. For full legal entities, transfer safeguards, and change notification terms, see our authoritative Sub-processor Directory, and our privacy policy.
Stripe, Inc. processes card payments only — it never receives or stores DICOM data. Card details (number, CVC, expiry) are entered directly into Stripe and never pass through or get stored on Dicomly's systems; we only ever see the card brand and the last four digits.
What procurement usually asks
Can our legal team get a signed DPA / BAA before integrating?
Yes. Review our complete agreement at /dpa. You can sign and email a copy to info@dicomly.io; we return countersigned agreements within 1 business day, well before you route any production traffic.
How do we validate your security posture during a vendor assessment?
Three routes, all of which exist today. One: send us your own security questionnaire — we answer it in writing within 5 business days, no template deflection. Two: book a technical review call under mutual NDA, where we walk your security team through the controls above and answer follow-ups on the record. Three: verify the architecture yourself — mTLS is enforced at connection time, so a sender without a valid certificate cannot connect, and because no imaging data is stored there is no archive for us to grant or deny access to. Start at security@dicomly.io.
How does Dicomly handle vulnerability disclosures?
We welcome responsible disclosures from researchers and customers. Vulnerabilities should be reported directly to security@dicomly.io (PGP encryption available upon request). We acknowledge receipt within 24 hours and provide remediation updates until the issue is closed.
Can Dicomly be deployed on-premises or in a dedicated single-tenant cloud?
Dicomly is a managed cloud service hosted in Frankfurt, Germany, and that is deliberate: managed certificate provisioning and protocol conversion are what remove the on-premise VPN appliance from your integration in the first place. On-premise hardware deployments are out of scope. If your procurement process requires dedicated isolation, talk to us at info@dicomly.io and we will tell you precisely what we can commit to in writing.
Does Dicomly personnel have access to our patients' medical images?
No. Dicomly does not store, cache, or index imaging payloads. Transmission occurs via streaming protocol conversion directly from sender to customer webhook in real-time memory. Our engineers cannot view or access patient images because no imaging data exists at rest on our systems.
Talk to us directly
Security question for a procurement review, or something you think we should know about? Email security@dicomly.io: questionnaires answered in writing within 5 business days, vulnerability reports acknowledged within 24 hours. A countersigned DPA / BAA is in your hands before you send a single real study.
Start receiving DICOM today.
EU-hosted. Nothing stored. DPA countersigned within 1 business day.