Security at ClinLexis

ClinLexis handles medical records for litigation. This page sets out where the data lives, how it is protected, and who has tested that in practice.

Cyber Essentials Plus
CREST Penetration Tested
NHS DSPT
DCB0129 Clinical Safety
UK Data Residency
ICO Registered

Independent audit

Cyber Essentials Plus, certified July 2026

The higher tier of the UK government-backed security certification. Rather than accepting a self-completed questionnaire, an independent assessor tests the company’s systems hands-on: secure configuration, patching, malware protection, access control and boundary protections, verified in practice. ClinLexis also holds the baseline Cyber Essentials certification; both renew annually.

Independent test

CREST penetration test, July 2026

Carried out by a CREST-approved security company to CREST and OWASP methodologies. A central objective was to leak case data out of an account: across roles, cases and tenants, no unauthorised access to case data or records was achieved. The test found nothing of critical, high or medium severity; ClinLexis remediates all findings at medium and above as policy, and the low-severity observations were fixed regardless.

Read how we hardened ClinLexis

Data handling

  • All customer data is stored in the United Kingdom
  • Data is encrypted in transit and at rest
  • Every upload is scanned for malware before it enters a case
  • Model inputs and outputs are not retained by any AI provider and are never used to train models

Access control

  • Multi-factor authentication is enforced for every account
  • Access is scoped per case: an invited expert sees the cases they are instructed on and nothing else
  • Every action is recorded in a complete audit trail

Clinical safety

  • A clinical safety case is maintained under DCB0129, the NHS clinical risk management standard
  • The appointed Clinical Safety Officer is a consultant neurologist in current NHS practice
  • AI outputs are presented as drafts for professional review, anchored to citations; the platform does not offer clinical or legal opinion

Certified & audited

  • Cyber Essentials Plus and Cyber Essentials, certified July 2026, renewed annually
  • NHS Data Security and Protection Toolkit: Standards Met
  • Registered with the Information Commissioner’s Office
  • Standard Data Processing Agreement with 72-hour breach notification; Data Protection Impact Assessment reviewed annually

The full picture, on request

Enterprise customers and their advisers can request the ClinLexis security and compliance pack: audits, agreements, infrastructure, data flows and sub-processors in one document, shared under our Data Processing Agreement. If you believe you have found a security issue, contact us and it will reach the right person the same day.