Security isn't a premium tier.
It's the baseline.

Patient data is sensitive medical data. Movari is built for it from the ground up, not as an add-on.

Where your data lives

🇬🇧UK data centres. Application functions run in London (Vercel lhr1); your database and your files run in London (Supabase eu-west-2); voicemail transcription and summarising run in the UK (Azure UK South). We pin these and keep it auditable. A few supporting services (email delivery, telephony carriage and the messaging channels themselves) operate outside the UK under UK transfer safeguards, and every one of them is named in our Privacy Notice.

How it's protected
  • Mandatory multi-factor authentication, with no opt-out.
  • Row-level isolation enforced at the database on every table.
  • Encrypted in transit and at rest.
How we stay accountable
  • Append-only audit log of clinically significant actions.
  • GDPR compliant; Data Processing Agreement published.
  • Controller / processor split clearly documented.
Your data is yours
  • Export your full record at any time.
  • Clear retention duty; on account closure your data is deleted after a 30-day hold.
What we don't do
  • We don't sell or share your data.
  • We don't use tracking cookies. Our analytics is cookieless.
  • We don't train AI on your patient data.

Legal

Full subprocessor list: see our Privacy Notice.

Report a vulnerability: security@movariapp.com

Built for the practitioner, not the organisation.

Request early access