Immune — Self Heal, an iStudio Technologies product

Trust & Security

Ransomware protection you can verify, not just take on faith

A platform that protects hospitals must hold itself to the highest standard. This is how Immune protects your data, resists being turned against you, and gives you the evidence to prove it — all built in, not bolted on.

Immune protects data with encryption everywhere, keeps protected health information out of its logs, records an immutable audit trail, runs fully on-premises when required, and gates every care-impacting action behind human approval.

Our security principles

When a hospital lets a security platform watch its network, verify its access, and act during an attack, it is extending an extraordinary degree of trust. We take that seriously. Immune is engineered so that it strengthens a hospital's security posture without ever becoming a new risk of its own — not a fresh place for patient data to leak, not a tool an attacker could hijack, and never a system that could override clinical judgment. The controls below are the concrete expression of that commitment.

Encryption everywhere

Data is protected in transit and at rest using strong, modern encryption.

PHI redaction

Protected health information is stripped from telemetry and logs, so the platform never becomes a new exposure.

Immutable audit log

Every detection, decision, and recovery step is recorded in a tamper-evident, append-only log.

Least-privilege access

Role-based access with multi-factor authentication for all operators; actions run with the minimum permissions required.

On-premises / air-gapped

Full sovereign deployment so no patient data leaves your environment.

Tamper resistance

Self-protecting components and an out-of-band control plane, so the defense survives an attack that targets it.

Patient-safety gating

Any action that could affect live care requires human approval; devices are quarantined, never shut down.

Validated recovery

Backups are verified clean and pre-attack, and recovery objectives are reported for every event.

Protecting the protector

Why Immune can't be turned against you

A recurring fear about powerful security automation is that it becomes a single point of catastrophic failure — that if an attacker compromised it, they could use its reach to do enormous damage. Immune is designed specifically to prevent this. Its components resist tampering and treat any attempt to disable them as an attack in itself. Its control plane runs out of band from the systems it protects, so compromising a hospital host does not hand an attacker control of the platform. Its audit log and its recovery points are immutable, unable to be altered even by the platform's own components, so an attacker cannot quietly erase their tracks or destroy the means of recovery. And because every care-impacting action requires human approval, there is no way to weaponize the platform into silently shutting down clinical systems.

These are not incidental features; they are foundational design decisions, made because a platform trusted with a hospital's most critical moments has to be worthy of that trust by construction. We would rather show you exactly how these protections work than ask you to take them on faith, which is part of what a technical evaluation with our team covers.

Common questions

Trust and security, answered

+Does Immune send our data to the cloud?

Only if you choose a hosted or hybrid model. Immune can run entirely on-premises or air-gapped, including its analysis engine, so protected health information never leaves your environment.

+How does Immune protect its own audit trail?

Every action is written to an append-only, tamper-evident audit log that cannot be altered or deleted by any host credential or by Immune's own components — so the record of what happened remains trustworthy even during an attack.

+Can Immune itself be used to cause harm if compromised?

Immune is designed to resist tampering, runs its control plane out of band from the systems it protects, and gates any patient-care-impacting action behind human approval — so it cannot be turned into a single point of catastrophic failure.

+What certifications does Immune support?

Immune's controls are designed to support HIPAA and HITECH obligations and to map to recognized security frameworks. Formal certifications are pursued in line with customer and market requirements; contact us for current status.

Evaluate Immune against your standards

Book a technical review and we'll walk through our security architecture, controls, and deployment options in detail.

Talk to us

See Immune protect your organization

Tell us about your environment and our team will show you exactly how Immune detects, contains, and self-heals through a ransomware attack — including the connected devices your current tools can't reach. We respond within one business day.

  • A working demo on a realistic scenario
  • Agentless coverage for medical and connected devices
  • On-premises and data-sovereignty deployment options
  • A frank look at where Immune fits alongside your stack

Request your demo

Tell us a little about your organization and we'll be in touch.

By submitting, you agree to be contacted about Immune. We respect your privacy and never share your details. See our privacy policy.