Security

Responsibility
that stays visible.

calliora processes sensitive health data. Security is therefore at the core of the operational responsibility we take on for every case.

Request a demo
Case 3141Logtoday
00:00calliora
Secondary diagnosis preparedN17.93, evidence: lab report, page 2
00:00calliora
Case reviewedDKR and MD patterns, documentation complete
00:00Specialist
Approval grantedDecision logged
00:00calliora
Case moved onnext step: billing
Every step documented, every approval made by a person.

Why this matters

Acting on a case
means taking responsibility for it.

calliora processes some of the most sensitive data there is: patient and case data, health information, financial detail. That demands a matching security commitment: every step calliora takes stays traceable and under control. People remain in control. Where professional judgment is required, the decision remains with a human.

Proof

Audited.
Certified. Transparent.

Independent standards make security verifiable. The evidence is available for review in the Trust Center.

Go to Trust Center
27001CertifiedISO/IEC 27001:2022Information security management system certified to international standard
C5AttestedBSI C5Audited under the Cloud Computing Compliance Criteria Catalogue, with ongoing audits
GDPRData protectionData processing in GermanyData processed exclusively in certified German data centers, no third-country transfers
InEKCertifiedInEK GrouperOfficially certified aG-DRG grouper

How we protect data

Security at every level.

Encryption
AES-256 at rest
TLS 1.2+ in transit

How we govern access

Clear roles.
Shared context.

Every case involves many people, and each of them carries a different responsibility. calliora reflects that with a comprehensive role and permission concept: everyone sees what their role requires, and every decision stays with the person accountable for it.

Roles and permissions

Granular permissions, defined per hospital, department and function.

Individual views

Coding specialists, medical controlling, physicians and management each work in a view tailored to their role.

Communication on the case

Queries, notes and approvals happen directly on the case, between the people responsible.

How we verify it

Trust is not a state.
It is an ongoing process.

Regular external penetration tests, documented incident response processes, mandatory security training for all employees, secure development practices with code reviews, and automated SAST/DAST scans.

  1. Regular external penetration tests
  2. Documented incident response processes
  3. Mandatory security training for all employees
  4. Secure development practices with code reviews
  5. Automated SAST/DAST scans

Trust Center

All the evidence
in one place.

All evidence, certificates, and reports are available for review in the Trust Center. Questions go directly to our security team.

Case closed.

Request a demo