Peer-reviewed research — Ophthalytics DR detection, validated on real-world fundus images Read the study

Trust at Ophthalytics

Ophthalytics develops and operates NSight360, cloud-hosted Software as a Medical Device for earlier retinal disease detection. This page sets out how we protect patients and their data across quality, security and privacy.

Request Documents
Quality System
ISO 13485:2016
Device Type
Software as a Medical Device
Data Classification
PHI, Restricted
Cloud Provider
Amazon Web Services
Last Assessed
Q2 2026

Compliance Posture at a Glance

The current status of our core quality, security and assurance activities. Items still in progress are labelled clearly. We do not claim certifications we have not earned.

ISO 13485:2016 QMS
Established
HIPAA-Aligned Practices
In Place
Independent Penetration Testing
Completed
SOC 2 Type II
In Progress

Compliance

Frameworks and assurance activities governing the NSight360 platform.

HIPAA

Administrative, physical, and technical safeguards are implemented in line with the HIPAA Security Rule. A Business Associate Agreement is executed with our cloud infrastructure provider.

SOC 2 Type II In Progress

A SOC 2 Type II readiness programme is underway, covering the Security trust services criteria. Controls are being implemented and evidenced ahead of an independent audit. The report will be published here on completion.

Independent Penetration Testing

The platform and its screening modules have undergone independent penetration testing covering authentication, authorisation, API security, and access control. Findings are tracked to closure through a formal remediation process, with re-testing to verify fixes.

Have any further questions?

Feel free to reach out to us — our security team reads every message, and we would rather answer a question twice than leave it unanswered once.