Data security & compliance

Security built to the strictest healthcare standards

Gosta is built from the ground up to medical-device standards for data security, transparency and patient safety.

Data Protection & Security

Certified, audited, and kept that way

Certified systems and ongoing oversight, not a one-off assessment.

EU MDR Class I Medical Device

Patient data is processed only for the visit, then permanently erased.

ISO 27001

A certified ISMS: information security is systematically managed and audited.

GDPR

Patient data handled under EU privacy law and a signed processing agreement.

National requirements met

We work through each customer’s own security review and meet the national requirements that apply to their organisation.

Gosta listens
Speech is captured during the consultation and processed as it happens, inside the EU.
No recordings stored
Drafts the authorisation request from the record, attaches the evidence the payer asks for, and tracks each case until it is approved.
Professional is responsible
The note, codes and letters stay drafts until a clinician has reviewed and approved them.
Transferred, then erased
The approved output moves into the record system, and the working data is permanently erased.
No data for AI training
Gosta doesn’t use any of your data to train its AI models.
Tagline

How the best teams use Gosta

Security is shared between the tool and the team using it. Three habits that keep it that way.

Ask for consent

Tell the patient the consultation is being documented with Gosta. A reminder can be shown at the start of every session.

Read before you sign

Check the note and the proposed codes, add anything missing, and only then transfer them into the record.

Keep access personal

Accounts are individual and access is logged, so it stays clear who saw what and when. Do not share credentials.

Frequently asked questions

Where is the data stored and processed?

Exclusively on European infrastructure, under a data processing agreement signed with your organisation. Nothing is processed outside the EU.

Is Gosta a medical device?

---

Are audio recordings kept?

---

Is our data used to train AI models?

---

Who is responsible for the documentation?

---

How do you handle model errors and hallucinations?

---

Can we run our own security review?

---

Bring us  your security review

We will work through your organisation's requirements with you.