Trust centre

Security & Privacy at Lazomis QI

This page is maintained by Lazomis to answer common security and privacy questions about Lazomis QI. It describes controls that are currently in place in the application. It is not an independent certification or audit attestation.

Shared responsibility

Lazomis QI is built on managed cloud infrastructure. Platform-level controls (network, hosting, managed Postgres, managed authentication) are provided by our infrastructure partner. Application-level controls (tenant isolation, role-based access, data handling, approvals) are owned by Lazomis. Customer organisations remain responsible for managing their own users, role assignments, and the accuracy of data they submit.

Authentication & access

  • Email and password sign-in with managed authentication.
  • Email verification is required before a user can request organisation access.
  • Organisation membership is granted only after manual approval by a Lazomis platform administrator. Users cannot self-assign to an organisation.
  • Organisation administrator and platform administrator roles cannot be self-assigned and require manual approval.

Tenant isolation

Each organisation is isolated. Database row-level security policies and column-level privileges restrict access so that users can only read or modify records belonging to organisations they have been approved for. Approval and status fields on a user profile cannot be modified by the user themselves.

Data handling

  • Submissions, dashboards, reports, exports and uploaded files are organisation-scoped.
  • Demo data is kept separate from live organisation data and labelled.
  • Exports are filtered to the requesting user's authorised organisation and project scope.
  • CSV exports are hardened against spreadsheet formula injection before download.

Mailing list & interest contacts

Interest registrations and mailing-list contacts are stored separately from authenticated user accounts and are not visible to organisation administrators. Recipients can unsubscribe at any time using the link included in every marketing email.

Secrets & service credentials

Service credentials and API keys are stored as server-side secrets and are never embedded in browser code. Privileged operations run only inside server-side functions that verify the caller's role.

Reporting a security issue

If you believe you have found a security or privacy issue affecting Lazomis QI, please contact us at support@lazomis.co.uk. Please include steps to reproduce and avoid accessing data that does not belong to you.

Compliance

Lazomis QI is designed to support UK healthcare improvement work and to be deployed under organisational information-governance arrangements. This page does not claim certification under any specific standard (for example ISO 27001, SOC 2, DSPT). Where you require formal assurance documentation, please contact us.