Security Policy
Last updated: June 2026
This Security Policy is published by Techpharma Solutions Limited (company number 13867466), trading as MedMocean (referred to in this policy as we, us or our). References to the platform or MedMocean in this policy refer to the MedMocean software platform operated by Techpharma Solutions Limited.
Security is a core part of how MedMocean is designed, built, and operated. This page summarises the public security posture of the platform for customers, procurement teams, and information governance reviewers.
We intentionally avoid publishing sensitive implementation details that could weaken platform security. Further assurance information may be shared with eligible organisations through the appropriate commercial or governance process.
Independent Assurance
- The platform has undergone a CREST-accredited penetration test, including assessment against common web application risks aligned with the OWASP Top 10.
- Cyber Essentials certification supports our baseline approach to secure configuration, access control, malware protection, and vulnerability management.
- Security controls are reviewed as the platform evolves, with risk-based improvements prioritised throughout the product lifecycle.
1. Security Assurance
The platform is developed and operated with a security-led approach suitable for healthcare and enterprise environments. We use independent assurance, internal review, and operational monitoring to reduce risk and protect customer data.
The platform has undergone a CREST-accredited penetration test, including assessment against common web application risks aligned with the OWASP Top 10. Findings from independent assessment are reviewed and remediated according to risk, with lessons incorporated into future development and operational processes.
2. Cyber Essentials
We maintain Cyber Essentials certification. This reflects a practical set of controls across secure configuration, boundary protections, access control, malware protection, and vulnerability management.
Certification is treated as a baseline rather than a ceiling. We continue to review security measures as threats, platform features, and customer requirements evolve.
3. Data Protection and Encryption
Data is protected using layered encryption controls across both the application layer and the infrastructure layer.
In transit: Traffic between users and the platform is encrypted using TLS (HTTPS).
At rest: Stored data and backups are encrypted using industry-standard encryption such as AES-256 (or equivalent) as part of a defence-in-depth approach.
Infrastructure layer: The platform runs on AWS and uses AWS-supported encryption controls for underlying storage and managed infrastructure components. This is complemented by application-layer encryption where appropriate, providing layered protection even in the event of an infrastructure-level control failure.
Encryption keys are managed with access controls appropriate to their sensitivity, and are handled in line with operational security practices.
Sensitive operational details, including internal implementation specifics, are intentionally not published on this page. This helps preserve the effectiveness of the security controls that protect the platform.
Backups and supporting data stores are handled with security and recoverability in mind, including encryption and access restrictions appropriate to the sensitivity of the data.
4. Access Control
Access to the platform and supporting administrative systems is governed by least-privilege principles. Users and personnel are granted only the access needed for their role and responsibilities.
Administrative access is restricted to authorised personnel and protected with strong authentication controls. Access is reviewed when responsibilities change or access is no longer required.
Credentials are not stored in plaintext, and users are expected to keep account access confidential within their authorised organisation.
5. Secure Development
Security is considered throughout design, development, testing, and release. Changes are reviewed with attention to data protection, user access, error handling, and safe defaults.
We use dependency review, vulnerability management, and secure coding practices to reduce the likelihood of preventable issues entering production.
Where external services are used, they are selected with consideration for reliability, security posture, contractual safeguards, and data protection responsibilities.
6. Monitoring and Incident Response
The platform is monitored for reliability, availability, and security-relevant events. Alerts and logs are used to support investigation and response while avoiding unnecessary exposure of sensitive information.
If a security incident is suspected, we investigate promptly, take containment and remediation action, and notify affected customers or authorities where required by law or good practice.
Post-incident reviews are used to strengthen controls, improve processes, and reduce the likelihood of recurrence.
7. Healthcare Best Practice Alignment
The platform is designed with healthcare data protection, information governance, and clinical safety expectations in mind. The platform supports administrative and monitoring workflows and does not replace professional clinical judgement.
We align our approach with recognised NHS digital health, clinical safety, privacy, and information governance best practices where relevant to the service, including considering DTAC (Digital Technology Assessment Criteria) guidance where applicable.
8. Shared Responsibility
Security also depends on safe customer use. Organisations using the platform should manage internal access carefully, avoid shared credentials, keep user details up to date, and report suspected account compromise promptly.
Customers remain responsible for ensuring that data entered into or exported from the platform is handled according to their own governance, professional, and legal obligations.
9. Responsible Disclosure
We welcome responsible reports from customers, researchers, and partners who believe they have identified a security issue.
Please avoid public disclosure, data access, service disruption, or testing beyond what is necessary to demonstrate the issue. Reports can be sent to admin@medmocean.co.uk.
10. Contact
For security-related questions, assurance requests, or responsible disclosure reports, please contact:
- Techpharma Solutions Limited
- Email: admin@medmocean.co.uk
- Address: 124 City Road, London, England, EC1V 2NX
This policy was last updated in June 2026 and may be updated periodically to reflect changes in our public security posture, assurance status, or governance approach. The current version of this policy is always available on the Site.