ISO 27001
Fully certified for information security management. Your data is protected by internationally recognized standards for risk assessment, access control, and continuous improvement.

Everything in Mena is designed to keep your care safe, secure and private.
Because your moments of care are nobody else’s business.

Mena is built on a non-negotiable principle: protecting the security and confidentiality of our customers' and patients' data. We've designed our platform from the ground up to safeguard the most sensitive information.
Audio can be deleted immediately after processing, so recordings never need to remain stored.
You remain in control of your data, with clear storage boundaries and configurable policies.
All data is encrypted in transit and at rest. Patient data is protected at every stage, from the moment it leaves your device to when it's stored on our servers.
Retention periods can be configured to reflect your organization's operational and regulatory needs.
Your patient data is never used to train our AI models.
Role-based access, auditability, and administrative controls support enterprise deployments.
Our security program is aligned with the requirements healthcare organizations rely on.
Independent experts regularly assess our infrastructure and applications.
Fully certified for information security management. Your data is protected by internationally recognized standards for risk assessment, access control, and continuous improvement.

Actively aligning with international standards for medical device quality management and responsible AI governance.


Fully compliant with European, US, and Swiss data protection regulations. Covered by data processing agreements.

Regular penetration testing conducted in partnership with Cognisys. Independent verification of our security posture across infrastructure and application layers.

Common questions about privacy, security and compliance
Yes. Mena uses enterprise-grade controls, encryption, independent testing, and a security program designed for sensitive healthcare data.
Data residency is configured for the region and agreement applicable to your organization.
Access is restricted to authorized people and systems and governed by role-based controls.
Retention is minimized by default and can be configured to meet your organization’s requirements.
No. We do not train our AI models on your patient data.
Yes. Contact us and we will provide the materials appropriate for your deployment.
Talk to us.