Highly sensitive patient data, HDS and GDPR requirements, legacy or no-code applications at their limit, and a constant tension between time-to-market and compliance.
Data that cannot afford mistakes
Patient records, imaging, results: the slightest leak compromises your liability and the trust of healthcare professionals. Security is not a luxury—it’s the foundation.
HDS and GDPR are non-negotiable
Certified health data hosting, access traceability, consent, right to erasure: the framework is strict, and it evolves. Better to build it in from the start.
Legacy systems that hinder care
Ageing business applications or no-code tools that can no longer handle the load or business rules: technical debt slows down teams and patients.
AI already in use, with no framework
Reports rewritten in a consumer tool, letters drafted from a personal account: AI has already entered the wards. Without a governed, available alternative, it is patient data that leaves.
02 — Two ways forward
Build a tool, or transform your teams.
Two distinct services that often combine, but rarely at the same time. Custom development when a tool is missing. AI transformation when a method, real usage and a framework are missing. Scoping exists precisely to settle that.
Compliance is not a checkbox. It’s the foundation.
For a healthcare organisation, the real question is not “does it work?” but “where does my data go, who decides, and can I leave?”. The answers are the same whether we build an application or equip your teams with AI. Here they are, plainly.
Hosting on HDS-certified infrastructure
Your health data is hosted in France, on HDS-certified infrastructure (OVH, Scaleway). Depending on your needs: managed mode, or self-hosting under your institution’s direct control.
No data outside the EU, models included
No dependency on a non-European cloud, neither for the application nor for the AI: Mistral or local / self-hosted models. Your patient data and the documents submitted to the models stay in France.
GDPR by design
Data minimisation, traceable consent, right to erasure, processing register, anonymisation or pseudonymisation depending on use: GDPR is built in from design, never bolted on afterwards.
RLS on all tables
Row-Level Security at the database level: every access is filtered by role and institution. Data separation isn’t just application-level—it’s embedded in the engine.
AI prepares, the clinician decides
No procedure, diagnosis or patient pathway decided by a machine. AI drafts, retrieves a protocol, cites its source; a professional validates. It is a design principle, not an option.
Guaranteed reversibility
The code is yours, the data is exportable, the hosting is transferable. You’re never locked in with Scroll.
04 — Proof
Healthcare and pharma projects already in production.
From an international laboratory to hospital systems and medical imaging. Custom-built applications: the same foundation we reuse to deploy AI in a constrained environment.
International pharmaceutical laboratoryPharma · Over €3bn revenue · France & Spain
AI assistantAI ActGDPRMulti-country
An AI assistant embedded in the field teams’ sales enablement platform.
In production in France and Spain. The assistant is embedded in the existing business platform, with no redirect and no re-authentication — field adoption determined everything else. Deliberately sober architecture: a custom application proxy rather than an off-the-shelf orchestrator, so the in-house team can take over. Compliance handled with the DPO from the scoping stage, not as a final sign-off: transparency about the nature of the system, auditable logging, pseudonymisation, and a functional scope that excludes personal and health data by construction.
AP-HPPublic health · Hospital
Smart pre-consultation for AP-HP
An anonymous patient journey that turns waiting room responses into a structured medical report, accessible to the doctor via QR code.
ProtectUsHealthcare · No-code to code migration
Hospital RFID system rewritten for a dozen facilities.
Migration from Bubble to Next.js 15 + Supabase, self-hosted with OVH. Reversible switch, cabinet by cabinet, with no disruption to care services.
dPEI Pocket — endometriosis scoring for radiologists.
Web and mobile medical application (iOS/Android) with offline mode and PDF generation. Deep pelvic endometriosis scoring; anonymised data processed by region.
WebiOS / AndroidOfflinePDF
05 — Stack & Method
A stack built to last and to be audited.
Modern, maintainable, hireable. Traceable end to end: every access is logged, every deployment is tested. And AI that stays in its place — sovereign, supporting, never deciding.
HDS (Health Data Hosting) is a mandatory French certification for hosting personal health data. It enforces strict security, confidentiality, and traceability guarantees. In practice: any application storing patient data must rely on HDS-certified infrastructure. We host your applications on HDS-certified infrastructure in France (OVH, Scaleway).
In France, on HDS-certified infrastructure. No data leaves the European Union. Depending on your needs, in managed mode or via self-hosting under your establishment’s direct control.
Yes, by design: data minimisation, traceable consent, right to erasure, processing register, Row-Level Security at the database level. GDPR compliance is built in from the outset, not added later.
Yes, under three conditions we systematically enforce. Models run in France: Mistral, or locally/self-hosted on HDS-certified infrastructure—nothing is sent to public services. Usage is limited to preparation (drafting, retrieving protocols, summarising files), never clinical decision-making. Every response cites its sources for verifiability. This is precisely what replaces the unregulated AI already used in services.
Yes. We audit the existing solution (legacy, no-code, or AI-generated code), secure the data, then migrate it to a maintainable, compliant foundation in stages—without service disruption.
Data encryption, Row-Level Security on all tables, access logging, anonymization based on use case, and systematic code reviews. Security isn’t a final step—it’s built into the architecture.
Let’s discuss
A healthcare application to build, or teams to train on AI? Start with the free 48-hour pre-scoping: you will know where to begin before committing.