Built to be trusted with the most sensitive data there is.

Every layer of Atum Health — storage, sharing, and analysis — is designed so no one but you ever holds the keys to your record.

End-to-end encryption

AES-256 with asymmetric keys, applied client-side before any data leaves your device.

Zero-knowledge AI analysis

TIWA runs predictive inference against encrypted data — it never sees a raw record.

Immutable audit logs

Every access, grant, and revocation is anchored to the chain and cannot be altered after the fact.

Role- and attribute-based access

Permissions are scoped precisely to who someone is and what they were granted — nothing implicit.

UK GDPR & DPA 2018 aligned

Storage, sharing, and research participation workflows are built around UK GDPR and the Data Protection Act 2018 from the ground up.

Smart-contract-backed consent

Access grants are enforced on-chain, so permission changes take effect the instant you make them.

Caldicott Principles

Data-sharing decisions follow the NHS Caldicott Principles — data is used only where there is a clear justification and a defined need to know.

A clinician reviewing patient records securely on multiple monitors

Access moves through a state machine — never a silent grant.

Every institution request passes through the same lifecycle: requested, granted, active, and eventually expired or revoked. Disputed access is escalated for review against the immutable consent log. The one exception is break-glass emergency access for acute, life-threatening care — even then, the patient is notified before or immediately after, and the event is logged for compliance review.

Requested Granted Active Expired / Revoked Disputed