Highly encrypted cloud storage with data centers and headquarters in Germany #nobackdoor

The German Act to Speed up Digitalization in Healthcare (DigiG) places significant demands on companies in the healthcare sector.
Securely managing sensitive health information requires a robust IT infrastructure.
SecureCloud gives you secure cloud storage, fully encrypted data management solutions, and collaborative online workspaces.
With our data centers and headquarters in Germany, we guarantee you an independent IT infrastructure without legal backdoors.
14 days free of charge and without obligation!
Anyone who works with patient data, sensitive health information or medical data of any kind needs maximum security.
SecureCloud is highly encrypted on all channels and is also always encrypted. You determine precisely who can see the data and for how long.
With SecureCloud, you choose peace of mind. Because nothing feels better than knowing valuable data in the most secure environment.






You're careful, SecureCloud is safe. But what if a laptop is stolen, the hardware falls into the wrong hands, or is infected with malware?
With Remote Wipe, you can reliably delete all data, even if the device is no longer physically present.
An absolute must for corporate security and an integral part of SecureCloud.
Who has access to which data is at your discretion. Thanks to SecureCloud, you can granularly restrict specific users or departments using many options.
Time-limited accesses, whitelists or blacklists (blacklists and whitelists), password restrictions, and more.
You can remove, change or issue restrictions at any time and thus meet important compliance requirements.


Bullet-proof and compliant documentation is essential for the medical and health sector. With the Audit Log function, no one can manipulate files unnoticed and every change remains traceable.
SecureCloud logs every exchange of data with external parties with clear proof of download or upload.
In the log, you can see the email addresses of people who have made changes at a glance.
14 days free of charge and without obligation!
SecureCloud meets the requirements of the German Digital Healthcare Act (DigiG, Gesetz zur Beschleunigung der Digitalisierung im Gesundheitswesen) and the General Data Protection Regulation (GDPR) for the processing of patient data. Hospitals, medical practices and care facilities store medical data in German data centers operated by noris network AG in Nürnberg; SecureCloud GmbH has no US parent, so no access under the US CLOUD Act is possible. SecureCloud is annually ISO 27001 certified by TÜV, BSI C5 attested, and Trusted Cloud certified (an initiative of the German Federal Ministry for Economic Affairs and Climate Action). All data is encrypted in transit and at rest.
SecureCloud encrypts all patient data with AES-256, an encryption considered resistant to quantum-computer attacks by today's standards. Granular permission management allows access to individual records, lab reports or imaging files to be strictly separated by function (medical, nursing, administrative), a prerequisite for GDPR Art. 9 (special categories of personal data, including health data). Pseudonymized datasets can be stored in separate data rooms with their own permission structure. The full audit log records every access for audit-readiness. SecureCloud is GDPR-compliant, BSI C5 attested and ISO 27001 certified.
SecureCloud complements KIM (Kommunikation im Medizinwesen) and the electronic patient record (ePA) for transmissions that take place outside the gematik telematics infrastructure, for example to patients directly, to attorneys, insurers or external medical experts. Recipients without a SecureCloud account receive the documents through encrypted SecureLinks; access can be password-protected, time-limited and restricted to specific files. SecureShare logs every download in the audit log. Permissions can be adjusted or fully revoked even after the link has been sent. Transmission is end-to-end encrypted from German data centers operated by noris network AG in Nürnberg.
SecureCloud meets the security requirements typical of funding projects under the German Hospital Future Act (KHZG, Krankenhauszukunftsgesetz): BSI C5 attestation, ISO 27001 certification (annually by TÜV), GDPR compliance and exclusive storage in German data centers operated by noris network AG in Nürnberg. SecureCloud GmbH is Trusted Cloud certified (an initiative of the German Federal Ministry for Economic Affairs and Climate Action) and CIS-compliant. Hospital-internal workflows (patient records, administration, research, external expert opinions) can be modeled in separate data rooms with granular permission management. Data never leaves Germany and is not subject to the US CLOUD Act.
SecureCloud supports hospitals classified as critical infrastructure (KRITIS) in the health sector through BSI C5 attestation, ISO 27001 certification and Trusted Cloud certification (an initiative of the German Federal Ministry for Economic Affairs and Climate Action). SecureCloud GmbH operates its own hardware at noris network AG in Nürnberg in German data centers with no US parent. A full audit log, snapshot recovery and granular permission management support the typical technical and organizational requirements of the BSI Act and the KRITIS Regulation. For specific KRITIS suitability, a case-by-case review by the hospital's IT security officers is recommended.
SecureCloud supports outpatient care services with encrypted synchronization on iOS, Android, Windows and macOS devices. Care staff capture patient documentation on the move; synchronization is encrypted with AES-256. When staff change or a device is lost, administrators can revoke access immediately and remove files from the device via remote wipe. Granular permission management separates access by care group, shift or client. The audit log records every change to patient documentation for audit-readiness. SecureCloud is GDPR-compliant, BSI C5 attested and ISO 27001 certified.
SecureCloud supports the long retention periods for patient records — 10 years under §630f German Civil Code (BGB) and the code of conduct of the German Medical Association (Bundesärztekammer, BÄK), and up to 30 years for radiology and radiation therapy cases — through audit-ready snapshots across several years and a full audit log. Every change to a patient record is recorded with user identification and timestamp; older states of a record remain available for the full retention period. Storage takes place in German data centers operated by noris network AG in Nürnberg. SecureCloud is GDPR-compliant, BSI C5 attested and ISO 27001 certified.
SecureCloud supports a GDPR-compliant response to data protection incidents under Art. 33 of the General Data Protection Regulation (GDPR) through immediate access revocation, remote wipe of lost or stolen devices and the full audit log. In the event of an incident, data protection officers can fully reconstruct the time, scope and patient data affected, a prerequisite for the 72-hour notification to the supervisory authority. Permissions can be revoked per user, device or document. SecureCloud GmbH stores all data exclusively in German data centers operated by noris network AG in Nürnberg and is BSI C5 attested.
Data centers and company headquarters in Germany
Our promise: #nobackdoor