ClinLexis handles medical records for litigation. This page sets out where the data lives, how it is protected, and who has tested that in practice.
Independent audit
The higher tier of the UK government-backed security certification. Rather than accepting a self-completed questionnaire, an independent assessor tests the company’s systems hands-on: secure configuration, patching, malware protection, access control and boundary protections, verified in practice. ClinLexis also holds the baseline Cyber Essentials certification; both renew annually.
Independent test
Carried out by a CREST-approved security company to CREST and OWASP methodologies. A central objective was to leak case data out of an account: across roles, cases and tenants, no unauthorised access to case data or records was achieved. The test found nothing of critical, high or medium severity; ClinLexis remediates all findings at medium and above as policy, and the low-severity observations were fixed regardless.
Read how we hardened ClinLexisEnterprise customers and their advisers can request the ClinLexis security and compliance pack: audits, agreements, infrastructure, data flows and sub-processors in one document, shared under our Data Processing Agreement. If you believe you have found a security issue, contact us and it will reach the right person the same day.