Cyber Essentials Plus certified; CREST penetration test completed
ClinLexis was certified to Cyber Essentials Plus in July 2026. Plus is the tier at which an independent assessor tests the company’s systems hands-on rather than accepting a self-completed questionnaire; ClinLexis holds both tiers, renewed annually.
In the same month, a CREST-approved security company completed a penetration test of the platform to CREST and OWASP methodologies. The brief prioritised the property customers actually depend on: cross-tenant access to case data. The result: no unauthorised access to case data or records across roles, cases or tenants, and no findings of critical, high or medium severity.
ClinLexis’s remediation policy is to fix anything of medium severity or above; the low-severity observations from the test were remediated regardless. Certification and testing repeat annually.
