Security
Designed so data stays where it belongs
Two guarantees underpin PACSinfra: tenant isolation, tested, and de-identification before storage. Everything else on this page supports them.
Tenant isolation, tested
Each organisation is a separate tenant. Users only ever see the studies, reports and projects that belong to their own organisation.
This is not just a design intention. It is verified by an automated isolation test suite that has to pass before every change is accepted, alongside linting and strict type checking.
One organisation, one view
Study lists, search, projects and reports are scoped to the user's organisation.
Editable roles per organisation
Each organisation defines its own roles from fine-grained permissions.
Tested on every change
The isolation suite runs with the rest of the test suites.
API-gated image access
The image server is never exposed. Every image passes through the PACSinfra API, which checks permissions and records an audit entry for each request.
Public
Browser
Your staff
The only way in
PACSinfra API
- Checks permissions
- Records audit entry
Private network
Orthanc
Image archive, not publicly reachable
De-identification before storage
Step 1
Upload
Single DICOM files or a ZIP archive, through the API.
Step 2
Validate
Files are checked before any processing.
Step 3
De-identify
Patient identifiers are removed from the DICOM metadata.
Step 4
Store
Only the de-identified study reaches the Orthanc image archive.
What's removed
- Patient identifiers in DICOM metadata
- Identifiers in free-text fields, where they are easy to miss
- Identifiers inside nested sequences, not just top-level attributes
The full list of handled attributes is in the de-identification docs.
Two ways to work
- Clinics
- Keep real identities in a separate application database, apart from the image archive.
- Research teams
- Run on pseudonyms only. No real identities are stored.
Limitation: De-identification covers DICOM metadata, not text burned into image pixels.
Some modalities, such as ultrasound or scanned documents, can include patient details drawn into the image itself. Review these studies before sharing them outside your organisation.
Break-the-glass access
Some studies need tighter control. Mark them as restricted and only users with access can open them as usual. When it is genuinely needed, a user can still "break the glass": access is allowed, but it is always recorded with the reason they give.
- 1. User opens a restricted study.
- 2. PACSinfra asks for a reason.
- 3. Access is granted and recorded in the audit trail with the reason.
Tamper-evident audit trail
Every action in PACSinfra is recorded in an append-only audit trail: logins, uploads, image requests, report changes, sharing and break-the-glass access. Entries are added, never edited or removed, and the trail is tamper-evident, so changes to past entries can be detected.
- Append-only: entries are never edited or deleted
- Tamper-evident: changes to past entries can be detected
- Covers every action, including each image request
Want to go through the details?
Read the docs, or book a call and we'll walk through the isolation model and de-identification pipeline with you.