Trust

Looking after your patients’ information

Choosing a practice system means trusting someone with your patients’ records. Here is how we look after them, in plain language.

Yours

Never sold, shared, or used to train AI. Export everything, whenever you want.

Secure

Encrypted while it is stored, and while it moves.

Reliable

Automatic backups on established, enterprise-grade infrastructure.

The questions we get asked

Straight answers, no jargon

All of this describes how the system works today, not how we intend it to work.

Can I get my data out?

Yes - all of it, whenever you want.

Patients, appointments, clinical records, documents and invoices. If you ever decide to leave, you leave with your data, and we do not delete it because a subscription lapsed.

Who on my team can see what?

Exactly what you decide.

A receptionist managing the diary does not need clinical notes, and a practitioner at one site does not need files from another. You set that up once and it applies everywhere.

Can I find out who opened a file?

Yes, every time.

Each time a patient record is viewed or changed it is written down. If you ever have to answer who looked at a file and when, the answer is there.

Could someone read it on the way?

No - it is encrypted end to end.

Information is scrambled while it travels between your browser and us, and again while it sits in storage. Documents you email to a patient can be password-protected too.

What if a password gets stolen?

A password on its own is not enough.

Accounts can require a code from your phone as well as a password. We set that up with you today, and switching it on yourself in the app is coming shortly.

Where is it actually kept?

On managed servers in Europe.

Backed up automatically, so a stolen laptop or a failed office computer does not put your records at risk. Nothing important lives on a machine in your practice.

What is it built on?

Established, enterprise-grade infrastructure.

Hosting, storage and message delivery run on specialist providers rather than anything we built ourselves. They are contractually bound to protect your data and we review them regularly. If your group needs the specifics for a security review, we will share them with you directly.

Do you sell it, or train AI on it?

No, and no.

We do not sell your practice's information or your patients' details, and we never hand them to advertisers. Patient records are not used to train AI models - the intelligence in OmniCore-AI works for your practice, not off it.

Does your team read my patients' records?

Only if you ask us to.

We do not browse patient records. If you ask us to look into something, we ask first and look only at what is needed to sort it out.

POPIACompliant

POPIA compliant

OmniCore-AI complies with the Protection of Personal Information Act (POPIA). Your practice stays responsible for its patients’ information and we process it as your operator, under the written Operator Agreement that section 21(2) of the Act requires. It is kept on managed servers in Europe, encrypted while it is stored and while it moves, and each practice’s records are kept apart from every other practice’s.

Information Regulator registration number 2026-068017

Independent certification

These are the two standards independent auditors use to check that a software company handles data properly. Both are under way, and each will appear here as it completes.

SOC 2In progress
ISO 27001In progress

Until they are finished we would rather tell you where we are than show a badge we have not earned.

Happy to answer more

If your practice or group needs a data processing agreement, a security review, or answers to a supplier questionnaire, two of those are already written down and you do not have to ask for them: the Operator Agreement is the written contract POPIA requires between your practice and us, and the security overview is the technical detail a procurement reviewer usually wants. For anything they do not cover, just ask. We would rather do that work up front than leave you wondering.

Run your whole practice from one core

Stop stitching tools together. Patients, diary, clinical records, communication, billing and reporting - connected, and configured for your discipline.

No card. 14 days. Cancel anytime.