Built to be trusted.
Health information is sensitive — for people and animals alike. Qumira is built so privacy and control are the default, not a setting you have to go and find. This page describes what is true today of how the product works, in plain language. Where something depends on configuration we're still finalising, we mark it [to confirm] rather than overclaim.
Honesty note: we do not currently claim HIPAA, SOC 2, ISO 27001 or PCI certification, and we don't assert encryption-at-rest beyond what our managed host provides. Nor does using Qumira make your practice compliant with anything — it helps you keep the records your regulator expects; the responsibility stays yours. We'd rather under-promise here.
A few commitments the product is built around.
These aren't aspirations bolted on later — they're how Qumira is wired. The rest of this page is the detail behind them.
You approve everything
No plan, message or change reaches a patient or owner until you have reviewed it and signed it off. The AI drafts; you decide.
Isolated by practice
Every record is scoped to the practice that owns it. One practice can never read another's patients, plans or messages.
Encrypted in transit
Every connection — your desk, your team, the recipient's phone — is secured with HTTPS/TLS.
Nothing is quietly rewritten
Clinical notes are append-only. An edit keeps an attributed snapshot of the previous version and marks the note amended; a deletion leaves a tombstone, not a hole.
Least surprise
Recipients see only their own plan. Drafts and archived plans are never exposed. Clinical SOAP notes stay private to your team.
Sensitive actions are logged
Record exports and subject erasures are written to an append-only accountability trail — who did what, and when.
Where your data lives.
Qumira runs on managed cloud infrastructure. Here's what that means for your records, in concrete terms.
Managed Postgres in the EU/UK
Your data is stored in a managed PostgreSQL database (Neon) hosted in the EU/UK region [confirm region]. It isn't shipped to a region you didn't expect.
Encrypted in transit (HTTPS/TLS)
All traffic to and from Qumira travels over HTTPS/TLS. We do not assert encryption-at-rest beyond the protections our managed host provides [host-level at-rest].
Strict tenant separation
Every read and write is scoped to the owning practice. Tenancy is enforced in the data layer, not left to the user interface — a practice's records are unreachable from another practice's session.
Versioned, restorable edits
Every plan edit is saved as a revision. You can see what changed over time and roll back to an earlier draft — nothing is silently lost or overwritten.
Who can get in, and how.
The biggest risk to recipient data is a stray credential. Qumira's answer is to give recipients no password at all.
Practitioner sign-in
Practitioner accounts sign in with a password that is salted and hashed with scrypt — we never store passwords in plain text, and we can't read them.
No passwords for recipients
Patients and owners never set a password. They open their plan through a single-use magic link sent to their email — so there's no recipient password to guess, reuse or leak.
Links expire and are single-use
Each magic link is valid once and for a short window, then it's spent. Issuing links is rate-limited per email, so they can't be brute-forced.
Holding a link isn't enough
Access is checked on the verified email every time, against that specific plan — possessing a link never grants access on its own, and only active plans are reachable.
Role-based team access
Team members have roles (e.g. admin vs practitioner). You can also invite a referring vet, specialist or trainer onto a single case with their own role-appropriate view.
Private clinical notes
Subjective / Objective / Assessment / Plan notes are your clinical record and stay inside your team — they're never part of what a recipient sees.
A record you can stand behind.
A clinical record is only worth anything if it can't be quietly rewritten. Qumira's notes are built to be added to, never painted over — so what you wrote, when you wrote it, and what changed after are all still there.
Clinical notes are append-only
Editing a SOAP note doesn't overwrite it. The previous version is snapshotted first, attributed to the person who changed it and stamped with the time — and the note itself is marked as amended. An amendment is a supplement to the record, not a replacement of it.
Deletion leaves a tombstone
"Removing" a clinical note takes it out of your working view and records who removed it and when. The note is retained — nothing disappears from the record silently.
How the consultation happened
Each note records its modality — seen in person, or consulted remotely — so the record says how you formed your view, not just what you concluded.
Plans keep their versions too
Every care-plan edit is saved as a revision you can read back and restore. What the recipient was told last month is still there next month.
An accountability log
Record exports and subject erasures are written to an append-only audit trail: who did it, to what, and when. It holds accounting metadata — never clinical content — and it survives the erasure it describes, so you can still answer for the action.
The complete record, on demand
Produce one printable document containing the subject's identifiers, referrals, SOAP notes (amendments marked), outcome measurements and care plans — to hand to a client, an insurer, or another clinician.
Built for work done under veterinary direction.
Animal rehabilitation, hydrotherapy and physiotherapy are carried out under the direction of a veterinary surgeon, and the professional bodies expect the referral and the vet's diagnosis to be in the record. Qumira gives that a home, next to the notes and the plan.
The referring vet, on the record
Record who referred the animal, their RCVS or SAVC registration number and practice, the date they examined the animal, their diagnosis, the treatment they authorised, any contraindications they flagged, and the date the referral should be reviewed.
Whether the signed form is held
A referral record notes whether your practice actually holds a signed referral or consent-to-treat form — so "we have it somewhere" becomes a field you can answer, or can't.
Remedial and maintenance, kept apart
Treating a diagnosed condition and doing fitness or maintenance work on a healthy animal are different things, and Qumira records them as different things.
A nudge when a referral is missing
Start a remedial plan for an animal with no active referral on file and Qumira says so. It's a warning, not a wall — it won't block you, and it won't decide for you.
Qumira does not make your practice compliant, and we won't pretend otherwise. Software can't hold a qualification or answer to a regulator. What Qumira does is help you keep the records your regulator and professional body expect — legibly, in one place, and honestly. Which rules apply to you, whether a referral is needed, and what goes in the record remain your professional judgement and your responsibility.
The AI drafts. You approve. Always.
Qumira uses AI to turn a quick note into a clean first draft — never to act on its own. Approval is structural: a plan stays a private draft until you publish it, and the recipient view can't see drafts at all.
Nothing is sent or saved as live without your confirmation. The draft is yours to change or discard until you say it's ready.
Your data is not used to train AI models. Your notes draft your plans and nothing more. The model provider is Anthropic (Claude); whether prompts are retained for abuse monitoring is governed by their terms [provider data terms]. When no AI key is configured, Qumira falls back to an offline draft and your text never leaves the system.
- 1
You write or dictate a note. Qumira drafts a structured plan from it.
- 2
The draft sits with you — nothing is sent or saved as live until you confirm.
- 3
You edit, tweak the wording, and approve. Then, and only then, it's shared.
- 4
Assistant actions (a booking, message or measurement) are proposed, re-validated, and saved only on your approval.
GDPR isn't an afterthought.
Data-subject rights are built into the product, so you can act on a request the day it arrives — and show, afterwards, that you did.
One-click export
Export a patient's full record from Qumira whenever you need it — to hand to the person, move it elsewhere, or keep your own copy. No support ticket required.
Right to erasure
Honour a GDPR erasure request with a permanent, scoped hard-delete of a patient and their associated records. It's a real deletion, not a hidden flag.
Scoped to your practice
Export and erasure act only within your own practice's data — they can't reach across tenants, by design.
And both are recorded
Every export and every erasure appends a line to your accountability log — the actor, the subject, the action, the time. The log holds no clinical content, and it outlives the record it describes, so you can still show what was done.
Where we are — honestly.
We're building Qumira toward alignment with HIPAA, SOC 2 and UK/EU GDPR — the frameworks that matter for health data about people and animals. That work is genuinely underway, and it isn't finished. So rather than a badge we haven't earned, here is the plain state of play: what is true of the product today, and what we do not yet claim.
True today
- Every record is scoped to the owning practice in server-side code, so one practice can't reach another's data.
- Practitioner passwords are salted and hashed with scrypt; we never store or see them.
- Recipients use single-use, rate-limited, expiring magic links — no recipient password exists to leak.
- Clinical notes are append-only with attributed revisions and tombstones; plans are versioned.
- Record exports and subject erasures are written to an append-only accountability log.
- One-click GDPR subject-access export and a real, scoped hard-delete for erasure.
- All traffic is encrypted in transit over HTTPS/TLS.
What we don't (yet) claim
- We are NOT certified against HIPAA, SOC 2, ISO 27001 or PCI DSS.
- We do NOT assert encryption-at-rest beyond what our managed hosts provide by default.
- We have NOT yet signed formal data-processing agreements (or HIPAA BAAs) with our sub-processors.
- Database-level row-level security is written but not yet the enforcing layer; tenant isolation is enforced in application code today.
- Multi-factor authentication for practitioners is not yet available.
- Using Qumira does not, by itself, make your practice compliant with anything.
Certification is a journey we're on, not a claim we're making. As BAAs, data-processing agreements and formal assessments are completed, we'll say so here — dated and specific. Until then, we'd rather under-promise. If a formal step matters to your decision, ask us where it stands and we'll tell you plainly.
The services we rely on.
Qumira uses a small number of trusted providers to run. This list is maintained here; entries are marked [to confirm] until the formal register and data-processing terms are finalised.
| Provider | Purpose |
|---|---|
| Vercel[confirm region] | Application hosting and compute (serves the app; terminates HTTPS/TLS) |
| Neon[confirm region] | Managed PostgreSQL database hosting — the primary store for patient, owner and clinical records |
| Cloudflare R2[confirm region] | Object storage for uploaded plan and patient media (images and video) |
| Resend[confirm] | Transactional email delivery (magic links, reminders, notifications) |
| Anthropic (Claude)[confirm] | AI drafting of plans and clinical-note structure — used only when an AI key is configured |
| Deepgram[if enabled] | Speech-to-text for dictation — used only when Deepgram is the configured transcription provider |
Hosting may run on additional underlying infrastructure providers via the services above [full chain].
Found something? Tell us.
If you believe you've found a security issue in Qumira, please email us. We'll acknowledge your report and work with you to resolve it. Please give us a reasonable window to fix things before any public disclosure.