Trust at Ophthalytics
Ophthalytics develops and operates NSight360, cloud-hosted Software as a Medical Device for earlier retinal disease detection. This page sets out how we protect patients and their data across quality, security and privacy.
- Quality System
- ISO 13485:2016
- Device Type
- Software as a Medical Device
- Data Classification
- PHI, Restricted
- Cloud Provider
- Amazon Web Services
- Last Assessed
- Q2 2026
Compliance Posture at a Glance
The current status of our core quality, security and assurance activities. Items still in progress are labelled clearly. We do not claim certifications we have not earned.
Compliance
Frameworks and assurance activities governing the NSight360 platform.
Administrative, physical, and technical safeguards are implemented in line with the HIPAA Security Rule. A Business Associate Agreement is executed with our cloud infrastructure provider.
A SOC 2 Type II readiness programme is underway, covering the Security trust services criteria. Controls are being implemented and evidenced ahead of an independent audit. The report will be published here on completion.
The platform and its screening modules have undergone independent penetration testing covering authentication, authorisation, API security, and access control. Findings are tracked to closure through a formal remediation process, with re-testing to verify fixes.
Have any further questions?
Feel free to reach out to us — our security team reads every message, and we would rather answer a question twice than leave it unanswered once.