Built for compliance from the ground up

At Lyrebird Health, clinical safety, privacy, and security aren’t afterthoughts, they’re baked into everything we design.
Trust Centre

Medical Device Registration

Lyrebird is registered with the MHRA as a Class I medical device under the UK Medical Devices Regulations 2002

Cyber Essentials & Cyber Essentials Plus Certified

Fully Cyber Essentials & Cyber Essentials Plus Certified, Lyrebird maintains the highest standard of cybersecurity controls as independently verified. Certificates of assurance available on request.

DSPT Toolkit Compliant

Lyrebird is fully compliant with the DSPT Toolkit, published submission available on NHS portal

DTAC Compliant

Comprehensive internal DTAC assessment aligned to NHS expectations. Certificate of assurance available to partner NHS organisations.

CREST Penetration Testing

Annual penetration tests performed by CREST-accredited providers to ensure continuous robust protection. Latest report available on request

Encryption & Data Protection

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Lyrebird processes personal data in accordance with UK GDPR and the Data Protection Act 2018, as Data Processor to the deploying organisation.

NHS Wide Clinical Integration System

Lyrebird's OpenAPI built for interoperability by design with HL7 and FHIR compliance, is compatible with all NHS EPR systems

Clinician-In-The-Loop

Lyrebird designed from the ground up with the clinician in the loop at all times and required for every consult.

Audio never retained

Spoken words during the consultation are converted to text then deleted. Used offline, audio is held on your device until connection is restored, then transcribed and deleted.

Processing & storage

Data is stored in the United Kingdom. Model inference runs transiently in the EU after anonymisation and minimisation, with no patient data stored there.

Bank level encryption

All data in transit is secured with TLS 1.3 and at rest with 256-bit encryption, the same standard used by banks.

Your data is your data

Your data, nor your patients data will ever be sold to third parties.

No AI model training

All data is yours alone — it will never be used to train an AI model.
Questions about compliance?