Skip to content

Self-hosted medical imaging

Your imaging platform, on your own server.

PACSinfra is a self-hosted medical imaging platform built on Orthanc and OHIF. Upload DICOM studies, review them, and write reports, all on your own server, with patient data that never leaves your control.

Security

Built on two guarantees

Tenant isolation, tested.

Each organisation sees only its own studies, verified by an automated isolation test suite. The image server is never exposed: every image passes through an API that checks permissions and records an audit entry for each request.

How it works →

De-identification before storage.

Patient identifiers are removed from DICOM metadata, including free-text fields and nested sequences, before anything reaches the image archive. Clinics can keep real identities in a separate application database. Research teams can run on pseudonyms only.

Limitation: De-identification covers DICOM metadata, not text burned into image pixels.

How it works →

What's included

Everything you need to store, review and report

  • Organisations, roles and permissions

    Login, editable per-organisation roles and fine-grained permissions.

  • DICOM upload and ingest

    Upload single files or ZIP archives, with validation and automatic ingest.

  • Study browsing

    Study lists with search and filters, series and instance browsing, and previews.

  • Radiology reports

    Draft, finalise, version and export reports to PDF.

  • Private projects

    Share selected studies with named colleagues.

  • Break-the-glass access

    Restricted studies can still be opened when needed, but access is always recorded with a reason.

  • Tamper-evident audit trail

    An append-only record of every action.

  • REST API

    A full REST API with Swagger docs, for developers and integrations.

  • One-command deployment

    Deploy with a single Docker Compose command.

Architecture

The image server is never exposed

Your browser talks to the PACSinfra API. The API checks permissions, records an audit entry, then fetches images from Orthanc on a private network.

Public

Browser

Your staff

The only way in

PACSinfra API

  • Checks permissions
  • Records audit entry

Private network

Orthanc

Image archive, not publicly reachable

Every image request goes through the API. Orthanc is never exposed to the internet.

Product

A look inside

Screenshot placeholder
Study list with search and filters
Screenshot placeholder
Series and instance browsing
Screenshot placeholder
Report editor with PDF export

Technology

Built from proven open-source parts

PACSinfra is built from a small set of proven, open-source parts. There's no ORM, no task-queue framework and no policy engine, so a developer can read and own the whole codebase.

  • API

    Go

  • DICOM worker

    Python

  • Frontend

    React + TypeScript

  • Orthanc

    The open-source DICOM server, used as the image archive

  • PostgreSQL 17

    Application data and the Orthanc index

  • Garage

    S3-compatible object storage for upload staging

See the full tech stack →

Pricing

Buy once, run it yourself

One organisation per licence. You may modify the code. You may not resell or redistribute it.

Founding customers: the first 3 organisations get 50% off in exchange for a case study.
  • Self-Hosted

    $2,500one-time

    Source code you run yourself.

  • Deployed

    Most popular

    $6,000one-time

    We deploy it on your server, end to end.

Compare plans and read the pricing FAQ →

FAQ

Common questions

Where does patient data live?

On your own server. PACSinfra is self-hosted: studies, reports and the audit trail stay on infrastructure you control.

What does de-identification cover?

Patient identifiers are removed from DICOM metadata, including free-text fields and nested sequences, before anything reaches the image archive. De-identification covers DICOM metadata, not text burned into image pixels.

Can clinics still see real patient identities?

Yes. Clinics can keep real identities in a separate application database, apart from the image archive. Research teams can run on pseudonyms only.

How do you know one organisation cannot see another’s studies?

Tenant isolation is verified by an automated isolation test suite, and every image request passes through an API that checks permissions and records an audit entry.

What do we need to run it?

A single server that can run Docker Compose. PACSinfra deploys with one command, with nginx as the only public entry point.

Can we integrate it with our own systems?

Yes. PACSinfra has a full REST API with Swagger docs.

Questions about buying? See the pricing FAQ.

See it on your own data.

Try the demo, compare plans, or talk to us about deploying PACSinfra on your server.