Skip to content

Security

Designed so data stays where it belongs

Two guarantees underpin PACSinfra: tenant isolation, tested, and de-identification before storage. Everything else on this page supports them.

Tenant isolation, tested

Each organisation is a separate tenant. Users only ever see the studies, reports and projects that belong to their own organisation.

This is not just a design intention. It is verified by an automated isolation test suite that has to pass before every change is accepted, alongside linting and strict type checking.

  • One organisation, one view

    Study lists, search, projects and reports are scoped to the user's organisation.

  • Editable roles per organisation

    Each organisation defines its own roles from fine-grained permissions.

  • Tested on every change

    The isolation suite runs with the rest of the test suites.

API-gated image access

The image server is never exposed. Every image passes through the PACSinfra API, which checks permissions and records an audit entry for each request.

Public

Browser

Your staff

The only way in

PACSinfra API

  • Checks permissions
  • Records audit entry

Private network

Orthanc

Image archive, not publicly reachable

Every image request goes through the API. Orthanc is never exposed to the internet.

De-identification before storage

  1. Step 1

    Upload

    Single DICOM files or a ZIP archive, through the API.

  2. Step 2

    Validate

    Files are checked before any processing.

  3. Step 3

    De-identify

    Patient identifiers are removed from the DICOM metadata.

  4. Step 4

    Store

    Only the de-identified study reaches the Orthanc image archive.

What's removed

  • Patient identifiers in DICOM metadata
  • Identifiers in free-text fields, where they are easy to miss
  • Identifiers inside nested sequences, not just top-level attributes

The full list of handled attributes is in the de-identification docs.

Two ways to work

Clinics
Keep real identities in a separate application database, apart from the image archive.
Research teams
Run on pseudonyms only. No real identities are stored.

Limitation: De-identification covers DICOM metadata, not text burned into image pixels.

Some modalities, such as ultrasound or scanned documents, can include patient details drawn into the image itself. Review these studies before sharing them outside your organisation.

Break-the-glass access

Some studies need tighter control. Mark them as restricted and only users with access can open them as usual. When it is genuinely needed, a user can still "break the glass": access is allowed, but it is always recorded with the reason they give.

  1. 1. User opens a restricted study.
  2. 2. PACSinfra asks for a reason.
  3. 3. Access is granted and recorded in the audit trail with the reason.

Tamper-evident audit trail

Every action in PACSinfra is recorded in an append-only audit trail: logins, uploads, image requests, report changes, sharing and break-the-glass access. Entries are added, never edited or removed, and the trail is tamper-evident, so changes to past entries can be detected.

  • Append-only: entries are never edited or deleted
  • Tamper-evident: changes to past entries can be detected
  • Covers every action, including each image request

Want to go through the details?

Read the docs, or book a call and we'll walk through the isolation model and de-identification pipeline with you.